Carhartt
Incident posture
Timeline
Summary
Carhartt had sensitive data from nearly 13 million accounts exposed after the ShinyHunters extortion group claimed to have stolen over 50 gigabytes of customer, employee and corporate information from its systems. The group released the data on the dark web after a ransom demand of $3.3 million was refused, and analysis linked the breach to a compromise of the company's Databricks analytics platform, revealing email addresses, names, phone numbers and physical addresses, including over 15,000 employee accounts. ShinyHunters has also claimed responsibility for numerous other breaches across various industries in recent months.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 13, the ShinyHunters extortion group claimed to have compromised Carhartt's systems and exfiltrated more than 50 gigabytes of data containing customer, employee, and corporate information. After attempting to extort a $3.3 million ransom from the company, the group released the stolen archive on its dark web site when Carhartt's negotiator informed them that the organization would not proceed with negotiations or further discussion. Carhartt has not publicly confirmed the breach or issued an official statement regarding the incident. Analysis by Troy Hunt of Have I Been Pwned linked the exposed data to a compromise of Carhartt's Databricks analytics platform. The leaked dataset includes unique email addresses, full names, phone numbers, and physical addresses for affected individuals.
Hunt reported that the breach affects more than 12.9 million Carhartt accounts, noting that millions of synthetic records unrelated to real individuals were identified and excluded from the breach count. The leaked database also contains over 15,000 email addresses using the @carhartt.com domain, indicating employee exposure. ShinyHunters published the archive after failing to secure payment, asserting that the stolen material encompasses a wide range of personal and internal data. Over the past year, the same group has been associated with breaches at numerous Snowflake customers and third‑party integration providers, and has claimed responsibility for compromises affecting hundreds of Salesforce customers, alleging the theft of more than 1.5 billion records from Salesforce Aura and Salesloft Drift campaigns. Most recently, ShinyHunters claimed to have conducted a series of data‑theft attacks against over 100 organizations by exploiting an Oracle PeopleSoft zero‑day vulnerability, citing victims such as the European Commission, Google, Cisco, Match Group, PornHub, Vimeo, Rockstar Games, McGraw Hill, 7‑Eleven, Carnival, Udemy, and Medtronic.
The exposed information includes email addresses, names, phone numbers, and physical addresses for the affected accounts. Carhartt's lack of a public response left affected parties without official guidance from the company regarding the breach. Have I Been Pwned made the breach searchable through its service, allowing users to check whether their email addresses appeared in the disclosed data. The release of the archive on the dark web enables further dissemination of the compromised information by other malicious actors. No details about containment, remediation, or regulatory notification have been provided in the available sources.
Sources
Sources available to members: 1 source.