Carhartt Data Breach Exposes Information of 12.9 Million Accounts
ShinyHunters publishes stolen data from clothing retailer, impacting millions of customers.

Key Takeaways
- ShinyHunters published data from 12.9 million Carhartt accounts.
- The breach was confirmed by Have I Been Pwned.
- Stolen data includes personal information, posing risks of phishing and identity theft.
- Carhartt has not yet publicly commented on the breach.
Quick answers
- What happened?
- The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt, according to Have I Been Pwned. The breach, which occurred earlier this month, exposes customer information and underscores the ongoing threat of data extortion.
- What should defenders do?
- Affected individuals should monitor their accounts for suspicious activity, be cautious of phishing emails, and consider changing passwords and enabling multi-factor authentication. Organizations should review their security measures and ensure they have robust incident response plans.
Carhartt, a major clothing retailer, has suffered a significant data breach after the extortion group ShinyHunters published sensitive data from approximately 12.9 million customer accounts. The breach was disclosed by data breach notification service Have I Been Pwned, which confirmed the authenticity of the leaked data.
The stolen data includes personal information such as names, email addresses, and other account-related details. The exact scope of the data and the method of the breach have not been fully disclosed, but the incident highlights the persistent risk posed by cybercriminal groups targeting retail companies.
ShinyHunters, known for previous large-scale data breaches, has a history of selling or leaking stolen data. The publication of this data puts affected customers at risk of phishing, identity theft, and other malicious activities.
Carhartt has not yet issued a public statement regarding the breach, and it is unclear if they have notified affected individuals. The company is expected to launch an investigation and may offer credit monitoring or other protective measures to impacted customers.
This incident serves as a reminder for organizations to strengthen their security posture and for individuals to monitor their accounts for suspicious activity.
Security Details
The breach involved the unauthorized access and exfiltration of customer data from Carhartt's systems. The data, now public, includes personal information such as names and email addresses. The exact attack vector is not yet known, but the involvement of ShinyHunters suggests a targeted extortion attempt.
Mitigation
Affected individuals should monitor their accounts for suspicious activity, be cautious of phishing emails, and consider changing passwords and enabling multi-factor authentication. Organizations should review their security measures and ensure they have robust incident response plans.
Sources
BleepingComputer
Carhartt data breach exposes information of 12.9 million accounts
Aug 27, 2026 · 11:10
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

FBI Warns ShinyHunters Members Following Dutch Police Arrest of Alleged Leader
The FBI has issued warnings to members of the ShinyHunters extortion group, urging them to turn themselves in following the arrest of an alleged leader by Dutch police. The operation marks a coordinated law enforcement effort to disrupt the group's activities.



