INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Carhartt Exposes 12.9 Million Accounts
| 2026-08-27 11:10 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 13, the ShinyHunters extortion group claimed to have stolen more than 50GB of documents containing sensitive data from Carhartt, a US-based apparel company with over 3,000 employees in the United States and Europe. The attack allegedly compromised millions of customer records, as well as employee, customer metadata, and internal corporate data, affecting approximately 12.9 million accounts. ShinyHunters published the stolen data on its dark web site after failing to pressure Carhartt into paying a $3.3 million ransom demand; however, Carhartt decided not to negotiate further. The breach is believed to have originated from the compromise of Carhartt's Databricks analytics platform, which was linked by Have I Been Pwned founder Troy Hunt.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ca•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
manufacturingmanufacturing
retailretail
Incident Timeline
2026/08/27
Threat actors, ShinyHunters, published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month.
Click on any entity below to view its context and source!
victims
3,000 employees
Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.
threat_actor
ShinyHunters
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach,
ShinyHunters claimed the attack
on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, empl…
"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator told the extortion gang, according to ShinyHunters.
Carhartt entry on ShinyHunters leak site (BleepingComputer)
After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Da…
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
Over the past year, ShinyHunters has also been linked to security breaches at
over a dozen Snowflake customers
, as well as many
third-party integration providers
, and claimed breaches at
hundreds of Salesforce customers
, saying they've stolen…
Most recently, ShinyHunters claimed responsibility for a series of breaches at
more than 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
Among the breaches claimed by ShinyHunters are the
European Commission
,
Google
,
Cisco
,
online dating giant Match Group
,
PornHub
,
video service Vimeo
,
Rockstar Games
,
edtech giant McGraw Hill
,
convenience store chain 7-Eleven
, crui…
infrastructure
3.3
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
financial
$3.3 ransom demand
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
data_breach
1.5 records
Over the past year, ShinyHunters has also been linked to security breaches at
over a dozen Snowflake customers
, as well as many
third-party integration providers
, and claimed breaches at
hundreds of Salesforce customers
, saying they've stolen…
victims
100 organizations
Most recently, ShinyHunters claimed responsibility for a series of breaches at
more than 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
data_breach
50 GB
While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach,
ShinyHunters claimed the attack
on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, emplo…
Carhartt entry on ShinyHunters leak site (BleepingComputer)
After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Dat…
victims
15,000 employees
"
The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database.
Tactical Metrics
Metrics
victims
3,000
Employees
Click for context!
Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.
Metrics
data_breach
50
Gb
While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach,
ShinyHunters claimed the attack
on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, emplo…
Carhartt entry on ShinyHunters leak site (BleepingComputer)
After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Dat…
Metrics
infrastructure
3.3
Software Version
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
Metrics
financial
3,300,000
Ransom Demand
ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.
Metrics
victims
15,000
Employees
"
The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database.
Metrics
data_breach
1,500,000,000
Records
Over the past year, ShinyHunters has also been linked to security breaches at
over a dozen Snowflake customers
, as well as many
third-party integration providers
, and claimed breaches at
hundreds of Salesforce customers
, saying they've stolen…
Metrics
victims
100
Organizations
Most recently, ShinyHunters claimed responsibility for a series of breaches at
more than 100 organizations
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
Intelligence Sources
BleepingComputer
2026-08-27
Carhartt data breach exposes information of 12.9 million accounts
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Carhartt
entity
2x
target region
Target Country
United States
country
2x
victims
Employees
3,000
employees
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
general metric
Accounts
12,900,000
accounts
Contextual Telemetry
Context Block
12 METRICS
industry
Targeted Sector
Manufacturing
sector
target region
Target Region
EUROPE
region
threat actor
APT Group
ShinyHunters
actor
timeline
Temporal Reference
August 13
date
data breach
Gb
50
gb
infrastructure
Software Version
3.3
version
financial
Ransom Demand
3,300,000
ransom demand
data breach
Records
1,500,000,000
records
victims
Organizations
100
organizations
general metric
Eleven
7
eleven
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.