Hacker working on a laptop showing data breach

Data Breach at American Clothing Giant Carhartt Exposes Nearly 13 Million People

ShinyHunters was recently linked to a data breach affecting American clothing giant Carhartt, which leaked customer, employee, and corporate data from 12.9 million accounts.

Dearborn, Michigan-based Carhartt employs about 3,000 people across 70 stores across the United States and reports annual revenue of nearly $1 billion.

The data breach surfaced on August 13, 2026, after the prolific threat actor claimed responsibility for the leak, listing the apparel giant on its data leak site following apparently failed ransom negotiations. Carhartt data breach impacts 12.9 million accounts.

According to the data breach tracking website Have I Been Pwned (HIBP), the leaked details included names, email addresses, phone numbers, and physical addresses. Affected individuals are at risk of phishing attacks in which the threat actor attempts to lure them into disclosing sensitive information, such as credit card details.

“Millions of records of customer data and vast amounts of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised,” ShinyHunters wrote.

Carhartt has yet to confirm the data breach or attribute it to any hacking group at the time of publication. The ransomware gang demanded $3.3 million in ransom, which the company failed to pay.

However, paying a ransom does not usually guarantee that the cybercrime group would not attempt to sell the stolen information to other threat actors. The cybercrime gang also accused the company of not caring for its customers and hiring an unskilled negotiator.

“After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions,” the company stated.

Meanwhile, HIBP founder Troy Hunt linked the data breach to the compromise of Carhartt’s Databricks cloud analytics platform. He also noted that the leaked information included synthetic information that does not relate to real individuals. His analysis also suggested that at least 15,000 employees using the “carhatt.com” email addresses were affected.

According to Hunt, some of the generated records “did not relate to real individuals and were excluded from the breach.” Nearly 12 million records were auto-generated. Nevertheless, ShinyHunters’ claims are usually credible.

Hacking group ShinyHunters implicated

ShinyHunters has been linked to various data breaches affecting various cloud platforms and business applications. The cybercrime group was linked to the Snowflake cloud platform data breach and to hacking campaigns targeting Salesforce Aura and Salesforce Drift. Instead of targeting individual companies, the ransomware group targets popular business applications used by thousands of organizations to steal massive troves of personal information.

Recently, the group claimed responsibility for the Oracle PeopleSoft data breach that affected over 100 organizations. ShinyHunters’ previous victims include Google, Cisco, RockStar Games, the European Commission, PornHub, Carnival, Medtronic, 7-Eleven, McGraw Hill, and Match Group.

ShinyHunters gained prominence around 2020 by deploying ransomware before it ditched encryption and focused on purely extortion attacks. At the time, the group was linked to the popular data breaches at AT&T, Microsoft, Santander, and Ticketmaster.

More recently, it was linked to attacks on Google, Cisco, Qantas, Adidas, Allianz, Pandora, and luxury LVMH brands. Other brands breached by ShinyHunters include TransUnion and Workday. ShinyHunters also collaborated with other hacking groups, Scattered Spider and Lapsus$.

While the group employs advanced tactics, it also leverages low-level attacks, including voice phishing (vishing), which exploits human weakness, the weakest link in any cybersecurity program. Such attacks include luring individuals to log into spoofed pages to harvest their credentials.