ShinyHunters has listed Carhartt on its dark web leak site, claiming it published approximately 50GB of information stolen from the US workwear company after negotiations over a $3.3 million ransom ended without an agreement. The group says the leaked material contains millions of records involving Carhartt customers and employees, although the scale and contents of the alleged breach have not been independently confirmed.
The extortion group added Carhartt to its leak site on Thursday and provided a download link for the purported stolen data. Unlike some of its other victim listings, ShinyHunters did not initially publish samples that could be used to independently verify that the files originated from Carhartt.
According to the hackers, Carhartt made contact after receiving the $3.3 million demand but ultimately declined to continue negotiations. ShinyHunters claimed it would have accepted a lower payment and blamed the breakdown in discussions on the company’s negotiator. Those statements represent the attackers’ account of events and have not been independently verified.
The group also published what it claimed was Carhartt’s final response to the extortion attempt. The purported message indicated that, following internal discussions, the company had decided not to proceed with further negotiations. The authenticity and context of the communication have not been independently established.
ShinyHunters claims the resulting leak contains personally identifiable information belonging to millions of customers, as well as employee information, customer loyalty data, and unspecified internal corporate records. However, the group did not provide a detailed description of individual data fields contained in the archive.
The claimed number of affected people also remains uncertain. Millions of records do not necessarily represent millions of unique individuals, and without an independent examination of the approximately 50GB archive, the actual number of Carhartt customers and employees whose information may have been exposed cannot be established.
Carhartt is a privately owned American clothing manufacturer best known for workwear. The company was established in Detroit in 1889 and has developed an international retail and distribution presence. Carhartt
ShinyHunters has previously been associated with large-scale corporate data theft and extortion operations. Rather than necessarily encrypting a victim’s systems, such attacks can center on stealing information and threatening to publish it unless the targeted organization pays.
In the Carhartt case, however, several important details remain unresolved. It is not publicly clear when the alleged intrusion occurred or how ShinyHunters gained access to the company’s environment. The group has also not disclosed sufficient public evidence to independently establish the full contents of the purported archive.
As a result, the $3.3 million ransom demand, 50GB data volume, millions of affected customer records and details of the negotiations currently depend primarily on ShinyHunters’ claims. The group’s decision to list Carhartt and provide a purported download does not by itself confirm the precise scale or contents of the alleged breach.
