Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 28, 2026 · 7 min read

Carhartt Breach Exposes 12.9 Million Customer Accounts

ShinyHunters listed the workwear brand on 13 August 2026, demanded $3.3 million, and dumped a 50GB archive when Carhartt refused. Troy Hunt then proved roughly half the file was fake, and the surviving 12,933,413 records entirely real.

Carhartt's negotiator sent one line and ended the conversation: "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions." That is the correct answer to an extortion demand. It is also why 12.9 million customers now have their name, email address, phone number and home address sitting in a free download on the open internet.

Key Takeaways

  • ShinyHunters published a 50GB Carhartt archive on 13 August 2026 after the retailer declined a $3.3 million ransom.
  • Troy Hunt verified 12,933,413 genuine accounts and loaded them into Have I Been Pwned on 25 August 2026, with email addresses, names, phone numbers and physical addresses as the exposed data classes.
  • Nearly half the dump was synthetic: ShinyHunters had scooped up TPC-DS retail benchmark data sitting in the same Databricks tables as the real customer records, inflating the original claim of over 24.8 million addresses.
  • No passwords were exposed, because the login field in the stolen customer table was empty across the dataset.
  • 83% of the 12.9 million addresses were already in Have I Been Pwned from earlier breaches, which leaves roughly 2.2 million people entering a public breach corpus for the first time.

What Was Actually Exposed in the Carhartt Breach?

The verified Carhartt records contain identity and shopping history, not credentials. Have I Been Pwned lists four compromised data classes: email addresses, names, phone numbers and physical addresses. Hunt's teardown found more inside the customer tables: dates of birth, demographic and household keys, first purchase and shipment dates, and loyalty or preferred customer flags.

What is not there matters just as much. The customer login column was empty across the dataset, so no passwords or hashes were published, and no payment card data appears. Anyone telling you to reset your Carhartt password because it leaked is guessing.

The corporate side took a hit too. BleepingComputer counted more than 15,000 @carhartt.com addresses in the archive alongside internal business data, which hands anyone building a business email compromise campaign a ready made org chart.

Why Was the Original Count Nearly Twice as High?

Because ShinyHunters stole a test dataset and a customer dataset in the same grab, then counted both. Hunt's writeup traced the archive to tables formatted as tpcds_sf1000 — the schema of TPC-DS, the Transaction Processing Performance Council's standard retail analytics benchmark. Real Carhartt customers were sitting in the same schema as machine generated benchmark rows.

The tells were statistical. Hunt found 97.6% of email domains appearing exactly once, birth years spread evenly across 1924 to 1992 at around 1,100 per year, birth countries distributed uniformly across all 211 ISO country codes, and addresses like Marina.Tucker@xgpgHqAu.com. Humans do not distribute that neatly. Random number generators do. At one point the dataset implied more Carhartt customers in Montenegro than in the United States.

Hunt's verdict on the exercise was blunt: "You're not going to believe this, but turns out you can't always take criminals at their word." Four days earlier, writing about the 7.1 million Salesforce records ShinyHunters claimed from Baxter International, we argued that leak site counts are upper bounds written by someone with an incentive to make them large. Carhartt puts a number on that incentive. The inflation ran to 47%.

Unopened cardboard shipping parcels on a doorstep in early morning light with one shipping label blurred, illustrating retail order data exposed in the Carhartt breach

How Did the Data Get Out?

The evidence points to Carhartt's Databricks analytics platform, but nobody has confirmed the entry method. Hunt linked the archive to a Databricks data lakehouse based on the table structure and benchmark contamination, and BleepingComputer reported the same conclusion. What remains unestablished is how ShinyHunters reached that platform: stolen credentials, a compromised integration, or the voice phishing route the crew has leaned on all year.

Most of the group's 2026 campaign ran through Salesforce tenants reached by calling employees into authorizing a malicious connected app. This one landed elsewhere, and an analytics warehouse is a fatter target than a CRM: it is where a retailer joins customer, order and loyalty tables for reporting.

The implication runs past Carhartt. Every retailer that copies its ecommerce tables into an analytics environment for BI carries the same exposure, and those environments usually sit outside the access review, logging and export monitoring the primary application gets. NIST SP 800-207 is the reference to cite when arguing that the warehouse deserves the same zero trust treatment as the storefront.

How Busy Have ShinyHunters Been This Month?

ShinyHunters is a data extortion crew that steals from cloud and SaaS platforms, names the victim on a dark web leak site, sets a deadline, and publishes when payment does not arrive. No encryption, no ransomware payload. The leverage is the threat of publication alone, which is why refusing to pay produces exactly what Carhartt got.

August 2026 alone gave the group four listings we have covered: 218,000 business email addresses from eye care maker Alcon on 11 August, 1.6 million RingCentral accounts on 16 August, 7.1 million Baxter records on 23 August, and now Carhartt. Add them up and the month's claimed total is about 21.9 million records in seventeen days. Five days after Carhartt the group made all four look small, claiming 284 million patient records from drug distributor McKesson — again unverified, and again reached through a vished login.

Only one of those four numbers has been independently verified, and it is the one that shrank. The headline fight is over 24.8 million versus 12.9 million, but the durable lesson is that a leak site record count is a marketing figure until a researcher opens the file. The same gap opened days later when FulcrumSec claimed 86 GB from the Manchester Airports Group breach affecting 8.7 million customers while the operator confirmed a narrower set of fields. Carhartt also breaks from earlier victims like Canada Life, breached through a single employee Salesforce account, where the vector was known within days.

What This Means for Your Inbox

A verified email address attached to a real shipping address, phone number and first purchase date is a phishing kit with the research already done. The attacker does not have to guess whether you shop at Carhartt. They know, and they know where the package goes. That converts the weakest lure in the business, the generic "there was a problem with your delivery" email, into a message that matches something true about you.

Expect three shapes over the next few months. Shipping notifications for an order you did not place, designed to get a click on a tracking link. Refund and returns lures referencing a purchase, aiming at your card details. And loyalty messages exploiting the preferred customer flags in the leaked tables. Order confirmation styling is trivial to clone, and a message carrying your correct home address clears most people's suspicion in about two seconds. The fake cloud storage payment emails flooding inboxes earlier this year worked on far less personal detail than this.

The 83% overlap cuts both ways. For most people the address was already circulating and now simply carries a retail purchase history attached to it. For the roughly 2.2 million new to the corpus, this is the entry point into list based spam, sextortion attempts and credential stuffing.

What Should Carhartt Customers Do Right Now?

Start by finding out whether you are in it. Search your address at Have I Been Pwned, which loaded the verified Carhartt set on 25 August 2026. A hit means your name, phone number and home address are public. It does not mean your account was accessed.

  • Treat every unexpected order, shipping or refund email as hostile until you verify it out of band. Open carhartt.com yourself and check your order history rather than clicking anything in the message.
  • Turn on two factor authentication anywhere that email address is also a login, especially your email account itself. No passwords leaked here, but the address is now a confirmed live target.
  • Change any password you have reused across your Carhartt account and another site. Reuse is what turns an address only leak into an account takeover months later.
  • Expect calls and texts, not just email. Phone numbers were in this dump, and voice phishing is this crew's own preferred technique.
  • If your details show up in fraud attempts, the FTC's IdentityTheft.gov is the place to file and get a recovery plan.

One thing not to do: act on a breach notification email that arrives unprompted. Fake notifications follow real breaches within days, and they convert precisely because the recipient just read a news story.

What to Watch Next

Carhartt has not issued a public statement. As of 27 August 2026 it had not commented to BleepingComputer or other outlets, and no customer notification has been confirmed. Watch for a state attorney general filing, where the actual data elements get listed under oath rather than described by a journalist or a criminal.

The other thing to watch is whether anyone confirms the Databricks entry point. Until Carhartt says how the analytics platform was reached, every retailer running the same architecture is guessing at whether it shares the exposure. That silence costs everyone except the company keeping it.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.