Carhartt
Incident posture
Timeline
Summary
The workwear retailer suffered a ransomware attack in which the extortion group ShinyHunters publicly leaked approximately 50 GB of personal data after the company declined to pay an initial $3.3 million ransom demand. The exposed information primarily included customer contact details such as names, phone numbers, email addresses, and physical addresses, with analysis by Have I Been Pwned confirming data tied to roughly 12.9 million real individuals alongside millions of synthetic records. Employees potentially faced greater data risk, though the full scope of compromised information remained pending the company's internal investigation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Carhartt, the well-known workwear retailer, became the subject of a ransomware-related data exposure when the extortion group ShinyHunters announced on Thursday, August 13, 2026 that it had published data stolen from the company. According to the group's own post on a dark web site it operates, the release consisted of approximately 50 gigabytes of personal information relating to Carhartt customers and employees. ShinyHunters stated that the data set included names, phone numbers, email addresses, and physical addresses of individuals harvested from compromised Carhartt databases. The group also claimed that Carhartt had been contacted with an initial ransom demand of $3.3 million, but that the company declined to pay, with the gang accusing Carhartt of being "incompetent" in its negotiations and missing the chance to settle for a lower amount. The post also included what ShinyHunters said was an excerpt from a final message from Carhartt ending negotiations, which read, "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process."
Following the publication of the data, Cybernews reported that ShinyHunters did not initially provide any online proof connecting the released files to actual individuals or to a real cyberattack against Carhartt. To evaluate the validity of the claim, the cybersecurity notification service Have I Been Pwned analyzed the leaked data and determined that it contained information tied to roughly 12.9 million real individuals, alongside millions of additional synthetic records that did not correspond to any actual people. This analysis was the principal independent corroboration that the leaked files corresponded to genuine Carhartt-related personal data. Carhartt itself had not responded to a request for comment from Cybernews as of August 31, 2026, leaving many details about the company's own review of the event officially unconfirmed in the public record at that time.
In commentary provided by email to Chain Store Age, Paul Bischoff, consumer privacy advocate at tech research firm Comparitech, noted that ShinyHunters' claims are generally considered credible and advised that anyone potentially affected should treat the situation seriously. According to Bischoff, the breached data examined by Have I Been Pwned was largely limited to contact information, which he stated did not by itself pose a direct threat to customers' bank accounts or identities, but which could be used as a basis for targeted phishing attempts. He added that employees could face greater exposure to more sensitive data, but that the precise categories of compromised employee information would likely remain unclear for several weeks until Carhartt concluded its internal investigation. As of the August 31, 2026 publication of the article, no detailed breakdown of which categories of employee data were affected had been released by the company.
The broader context surrounding the Carhartt incident involved a surge in ransomware activity during the first half of 2026. A Comparitech study reported that global ransomware attacks reached a new high during that six-month period, with the Comparitech daily ransomware tracker logging 4,217 incidents between January and June 2026. This figure represented an 11 percent increase over the 3,809 attacks recorded in the second half of 2025, translating to an average of 23 ransomware attacks per day worldwide. Retailers specifically saw a 28 percent rise in reported attacks, with 326 total incidents logged in the first half of 2026, 28 of which were confirmed, compared with 254 incidents in the preceding half-year period. The Carhartt disclosure occurred against this backdrop of rising activity targeting the retail sector, though the specific method by which ShinyHunters obtained access to the company's systems, the date the intrusion began, and the timeline of detection were not detailed in the available reporting.
Sources
Sources available to members: 1 source.