ShinyHunters has published data allegedly stolen from American clothing company Carhartt, with an analysis of the leaked files indicating that nearly 13 million accounts were affected.

 

 

The extortion group claimed responsibility for the attack on August 13, saying it had obtained more than 50GB of data. ShinyHunters alleged that the stolen material included customer and employee information, customer metadata, and internal corporate records. Carhartt has not publicly confirmed the group’s claims or released details about the incident.

According to ShinyHunters, the attackers demanded $3.3 million from Carhartt. The group later published the stolen archive on its dark web leak site after the company reportedly declined to continue negotiations. ShinyHunters shared a message attributed to a Carhartt negotiator stating that the company had decided not to move forward with further discussions.

The release allowed researchers to examine the stolen material rather than relying exclusively on the attackers’ description of the breach. Have I Been Pwned founder Troy Hunt analyzed the roughly 50GB archive and linked the incident to Carhartt’s Databricks analytics environment.

Hunt determined that the breach affected more than 12.9 million Carhartt accounts. Information found in the dataset included email addresses, names, telephone numbers, and physical addresses. More than 15,000 email addresses using Carhartt’s corporate @carhartt.com domain were also identified.

The archive additionally contained millions of synthetic records that did not correspond to real people. Those entries were excluded when calculating the number of affected accounts, illustrating why raw database record counts do not necessarily represent the actual number of individuals involved in a breach.

Several important details remain unknown. Carhartt has not explained how the attackers gained access, when the intrusion occurred, or whether systems beyond the identified data environment were compromised. There is also no confirmation that passwords or payment-card information were exposed.

ShinyHunters has been connected to numerous data theft and extortion campaigns involving major cloud and enterprise platforms. During the past year, the group has been linked to breaches affecting Snowflake customers and third-party integration providers, while also claiming attacks against numerous organizations using Salesforce environments.

More recently, ShinyHunters claimed responsibility for breaches involving more than 100 organizations following attacks that exploited an Oracle PeopleSoft zero-day vulnerability.

For Carhartt customers, the publication of names, contact details, and physical addresses could increase exposure to targeted phishing and impersonation attempts. However, the confirmed scope remains limited to information identified through analysis of the leaked dataset. Further details about the intrusion and its overall impact remain unavailable until Carhartt provides additional information.

Leave a Reply