Carhartt Data Breach Exposes Sensitive Info of 12.9 Million Accounts
A massive data breach has struck clothing retailer Carhartt, exposing sensitive information from nearly 13 million accounts. The ShinyHunters extortion group claimed responsibility for the attack earlier this month and published the stolen data on its dark web site after failing to pressure Carhartt into paying a $3.3 million ransom demand.
The compromised data includes customer, employee, and corporate information, including unique email addresses, names, phone numbers, physical addresses, and other sensitive details. Have I Been Pwned founder Troy Hunt analyzed the leaked database and confirmed that it links back to the compromise of Carhartt’s Databricks analytics platform, a cloud-based data platform used for business reporting and storage.
The breach affects not only customers but also Carhartt employees, with over 15,000 staff members having their email addresses exposed. The compromised data is a treasure trove for cybercrime gangs like ShinyHunters, which has been linked to security breaches at numerous high-profile organizations in the past year. ShinyHunters claimed responsibility for breaching more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.
Carhartt, founded in 1889, is a well-established apparel company with manufacturing facilities in Kentucky and Tennessee and over 3,000 employees worldwide. While the company has yet to confirm the breach or issue a statement, the exposed data suggests a significant security lapse on their part. The breach highlights the importance of robust cybersecurity measures for companies handling sensitive customer and employee information.
The ShinyHunters extortion group’s actions demonstrate the growing trend of cybercrime gangs targeting large-scale organizations in pursuit of lucrative ransom demands. As these attacks become more sophisticated, it is essential for companies to invest in robust security protocols and incident response plans to mitigate the impact of such breaches.
For individuals affected by this breach, it is crucial to remain vigilant about potential phishing attempts or identity theft. Monitoring credit reports and taking steps to secure personal data can help minimize the risk of damage from this breach. As a precautionary measure, users are advised to change passwords and enable two-factor authentication for all sensitive online accounts.
In light of this breach and others like it, companies must prioritize cybersecurity and adopt proactive measures to prevent similar incidents in the future. By doing so, they can protect not only their customers’ data but also their own reputation and business continuity.
Source: Bleeping Computer — 2026-08-27