Carhartt Data Breach Affects 12.9M Accounts in ShinyHunters Attack

Carhartt Data Breach Affects 12.9M Accounts in ShinyHunters Attack

A Carhartt data breach leaked information tied to 12.9 million accounts after hackers stole company data. Here’s what was taken, why it matters, and how you can protect yourself online.

What Happened?

According to BleepingComputer, Carhartt — an American workwear and streetwear company — is linked to a data breach affecting more than 12.9 million accounts.

The ShinyHunters hacker group claimed the attack on August 13. It said it stole more than 50GB of customer, employee, and company data.

The group later published the stolen files after Carhartt refused to pay a $3.3 million ransom demand.

Troy Hunt, founder of Have I Been Pwned, analyzed the files. He connected the breach to Carhartt’s Databricks platform.

Databricks is a cloud service companies can use to store and analyze business data.

Carhartt has not publicly confirmed the breach or released its own statement about the incident.

Personal details stolen in a breach can remain useful to criminals long after the original attack. They may use that information to make phishing messages or fake calls more believable.

Also, your information may already have appeared in another breach without you knowing.

If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

Have I Been Pwned found information connected to more than 12.9 million Carhartt accounts in the stolen files.

The confirmed leaked information included:

  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses

The database also included more than 15,000 Carhartt employee email addresses ending in @carhartt.com.

The archive contained millions of synthetic records as well. These records were not linked to real people, so they were excluded from the breach count.

The report did not say whether passwords, payment card details, or Social Security numbers were included.

How Hackers Reached Carhartt’s Databricks Platform

Troy Hunt linked the stolen information to Carhartt’s Databricks analytics platform.

However, Carhartt has not explained exactly how the hackers gained access.

That means the exact entry point and security weakness have not been publicly shared.

ShinyHunters is an extortion group. These criminal groups steal information and then demand money from companies to prevent the data from being published.

In this case, ShinyHunters said Carhartt refused to continue negotiations. The group then released the stolen files online.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

Why Carhartt Customers Should Pay Attention

Names, email addresses, phone numbers, and home addresses may seem like basic information. However, criminals can combine these details to create convincing scams.

For example, a message that knows your name or address may look more trustworthy than a random phishing email.

That means you should be careful with unexpected messages about orders, refunds, deliveries, passwords, or account problems.

The larger lesson also goes beyond Carhartt. Any retailer or service that stores your contact information can become a target.

Knowing what information criminals may already have can help you recognize suspicious messages before you respond.