According to Have I Been Pwned, the ShinyHunters extortion group has published sensitive information linked to approximately 13 million accounts allegedly stolen from clothing retailer Carhartt earlier this month.
Founded in 1889, Carhartt is an American apparel company known for its workwear and streetwear. The company operates manufacturing facilities in Kentucky and Tennessee and employs more than 3,000 people across the United States and Europe.
Carhartt has not confirmed ShinyHunters’ claims or issued a public statement about the alleged data breach. However, ShinyHunters claims to have attacked Carhartt and says it stole more than 50GB of documents containing customer, employee, and corporate data.
“Millions of customer data records and vast amounts of confidential information and PII were compromised, including employees, customers, customer metadata (loyalty information), and other internal corporate data,” the cybercrime group said.
ShinyHunters also published an archive of allegedly stolen Carhartt data on the dark web after reportedly failing to pressure the clothing company into paying a $3.3 million ransom.
According to ShinyHunters, Carhartt’s negotiators told the group that, “after careful consideration and internal discussions with management, we have decided not to proceed with negotiations or further discussions.”

After analyzing a 50GB archive published by ShinyHunters on a dark web site, Troy Hunt, the founder of Have I Been Pwned, linked the alleged Carhartt data breach to the company’s Databricks analytics platform. Databricks is a cloud-based data platform that combines business reporting, analytics, and data storage in a unified architecture.
Hunt reported that more than 12.9 million Carhartt accounts were affected. The exposed information reportedly included unique email addresses, names, phone numbers, and physical addresses, along with “millions of synthetic records unrelated to actual individuals.” These synthetic records were excluded from the breach count.
The Have I Been Pwned founder also identified more than 15,000 employees with @carhartt.com email addresses in the leaked database.
A Carhartt spokesperson did not immediately respond to BleepingComputer’s questions about the alleged cyberattack and data exposure.
Over the past year, ShinyHunters has also been linked to security breaches involving more than a dozen Snowflake customers and numerous third-party integration providers. The group has claimed breaches affecting hundreds of Salesforce customers and said it stole more than 1.5 billion records during Salesforce Aura and Salesloft Drift campaigns.
Most recently, ShinyHunters claimed responsibility for a series of breaches affecting more than 100 organizations after attackers allegedly exploited a zero-day vulnerability in Oracle PeopleSoft.
Other organizations allegedly targeted by ShinyHunters include the European Commission, Google, Cisco, online dating company Match Group, Pornhub, video platform Vimeo, Rockstar Games, education technology company McGraw Hill, convenience store chain 7-Eleven, cruise operator Carnival, online training platform Udemy, and medical device manufacturer Medtronic.
The overall prevention score can obscure what happens after an attacker gains initial access. When attackers use valid credentials, the effectiveness of your defenses can drop sharply.
Blue Report 2026 measures defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




