Skip to content
Data breachUnknown

Carhartt data breach exposes 12.9 million customer accounts

American workwear maker Carhartt was hit by a ShinyHunters extortion campaign that exposed the personal information of 12.9 million customer accounts after the theft of data from its cloud analytics platform.

Victim
Carhartt, Inc.
records
12.9M

In late August 2026, American workwear and apparel maker Carhartt, Inc. was the target of a ShinyHunters "pay-or-leak" extortion campaign that exposed the personal information of millions of its customers. After the retailer reportedly rejected the group's roughly $3.3 million demand, ShinyHunters published data it claimed to have stolen and blamed the failed negotiations on Carhartt's response.

On 26 August 2026, the breach-notification service Have I Been Pwned completed its analysis of the leaked material, confirming 12.9 million unique email addresses belonging to real users โ€” roughly half the figure ShinyHunters had initially claimed. The exposed records also included customer names, phone numbers and physical addresses.

What happened

Security researchers, including Have I Been Pwned's Troy Hunt, linked the incident to the compromise of Carhartt's Databricks cloud analytics platform, where customer and business data had been aggregated. The breach followed the broader 2026 wave of ShinyHunters campaigns that targeted enterprise SaaS and data-warehouse environments to bulk-extract customer datasets before extortion.

Why it matters

The Carhartt breach is a reminder that consolidating customer data into cloud analytics and warehousing platforms concentrates risk: a single compromised environment can expose tens of millions of records at once. It also highlights the recurring gap between attackers' inflated victim claims and the verifiable exposure โ€” here, independent analysis put the real figure at roughly half of what the extortion group advertised.

Financial impact

Reported costs in USD

Ransom demanded
$3.3M
Ransom paid
Refused

    Timeline

    1. ShinyHunters lists Carhartt on its data-leak site after failed ransom negotiations.

    2. Have I Been Pwned confirms 12.9 million unique email addresses in the leaked data โ€” about half of what ShinyHunters had claimed.

    Sources

    1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
    2. theregister.comhttps://www.theregister.com/security/2026/08/26/carhartt-data-breach-affects-129m-half-of-what-shinyhunters-claimed/5292626
    3. cybernews.comhttps://cybernews.com/news/carhartt-data-breach-shinyhunters-millions-customer-records/
    4. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Carhartt

    Related incidents

    Data breachContained

    Florida DMV confirms breach of DAVID driver database via compromised law-enforcement account

    Florida's Department of Highway Safety and Motor Vehicles confirmed that attackers used a compromised law-enforcement account to breach its DAVID driver database, as the ShinyHunters extortion group claimed to have stolen more than 200,000 driver records.

    Victim
    Florida Department of Highway Safety and Motor Vehicles
    Records
    200.0K