CSIDB logo
Incident

Carhartt

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 20:36

Linked entities

Victim
Carhartt
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Carhartt had sensitive data from nearly 13 million accounts exposed after the ShinyHunters extortion group claimed to have stolen over 50 gigabytes of customer, employee and corporate information from its systems. The group released the data on the dark web after a ransom demand of $3.3 million was refused, and analysis linked the breach to a compromise of the company's Databricks analytics platform, revealing email addresses, names, phone numbers and physical addresses, including over 15,000 employee accounts. ShinyHunters has also claimed responsibility for numerous other breaches across various industries in recent months.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On August 13, the ShinyHunters extortion group claimed to have compromised Carhartt's systems and exfiltrated more than 50 gigabytes of data containing customer, employee, and corporate information. After attempting to extort a $3.3 million ransom from the company, the group released the stolen archive on its dark web site when Carhartt's negotiator informed them that the organization would not proceed with negotiations or further discussion. Carhartt has not publicly confirmed the breach or issued an official statement regarding the incident. Analysis by Troy Hunt of Have I Been Pwned linked the exposed data to a compromise of Carhartt's Databricks analytics platform. The leaked dataset includes unique email addresses, full names, phone numbers, and physical addresses for affected individuals.

Hunt reported that the breach affects more than 12.9 million Carhartt accounts, noting that millions of synthetic records unrelated to real individuals were identified and excluded from the breach count. The leaked database also contains over 15,000 email addresses using the @carhartt.com domain, indicating employee exposure. ShinyHunters published the archive after failing to secure payment, asserting that the stolen material encompasses a wide range of personal and internal data. Over the past year, the same group has been associated with breaches at numerous Snowflake customers and third‑party integration providers, and has claimed responsibility for compromises affecting hundreds of Salesforce customers, alleging the theft of more than 1.5 billion records from Salesforce Aura and Salesloft Drift campaigns. Most recently, ShinyHunters claimed to have conducted a series of data‑theft attacks against over 100 organizations by exploiting an Oracle PeopleSoft zero‑day vulnerability, citing victims such as the European Commission, Google, Cisco, Match Group, PornHub, Vimeo, Rockstar Games, McGraw Hill, 7‑Eleven, Carnival, Udemy, and Medtronic.

The exposed information includes email addresses, names, phone numbers, and physical addresses for the affected accounts. Carhartt's lack of a public response left affected parties without official guidance from the company regarding the breach. Have I Been Pwned made the breach searchable through its service, allowing users to check whether their email addresses appeared in the disclosed data. The release of the archive on the dark web enables further dissemination of the compromised information by other malicious actors. No details about containment, remediation, or regulatory notification have been provided in the available sources.

Sources

Sources available to members: 1 source.

CSIDB