Carhartt Data Breach (August 2026)
The ShinyHunters extortion group published data taken from the workwear retailer, and Have I Been Pwned verified 12.9 million real customer records inside it after stripping out millions of synthetic ones.
- Organization
- Carhartt
- Sector
- Retail
- Country
- United States, MI
- Incident date
- August 13, 2026
- Disclosed
- August 25, 2026
- Records affected
- 12.9 million
- Attack type
- Undisclosed
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Names
- Phone numbers
- Physical addresses
- ShinyHunters claims to have compromised Carhartt, saying it took more than 50 GB of compressed data
- The group publishes the data. Have I Been Pwned's first pass finds 24.9 million email addresses
- After analysis shows roughly 45 percent of the corpus is synthetic benchmark data, Have I Been Pwned loads 12.9 million verified addresses
- Troy Hunt publishes the verification write-up
What Happened
On August 13, 2026, the ShinyHunters extortion group claimed it had compromised Carhartt, the Michigan workwear retailer, and taken more than 50 GB of compressed data covering customer records, employee information and loyalty data. Per Have I Been Pwned's entry, this was a "pay or leak" campaign: the group demanded payment and, when none came, published the data.
The verification is the interesting part of this one. In his write-up of the analysis, Troy Hunt describes running the published corpus through Have I Been Pwned's extraction tooling and getting 24,876,077 email addresses. Frequency analysis then showed that about 45 percent of those were synthetic: single-use gibberish domains, perfectly uniform birth countries across 211 ISO codes, a flat spread of birth years. The pattern matched the TPC-DS benchmark dataset, which appears to have been stored in the same Databricks environment as the real customer records. The synthetic rows were excluded and 12.9 million verified addresses were loaded, most of them at real domains including carhartt.com and its "do not ship" alias.
Carhartt had not published a statement confirming or describing the incident at the time the data was verified. How the group got in has not been disclosed by the company, so the attack type on this report is undisclosed rather than a guess.
What was Exposed
The verified records contain email addresses, names, phone numbers and physical addresses. No passwords or payment data appear in the Have I Been Pwned classes for this breach.
That combination is exactly what a targeted scam needs: a real name, a real address, and a real email or phone number, all tied to a brand the person has actually bought from. Expect messages that look like Carhartt order updates, delivery problems or loyalty account notices, and expect them for months. According to the analysis, 83 percent of the affected addresses were already in Have I Been Pwned from earlier breaches, so many of the people in this set have been through this before.
What to do if you are Affected
Nothing on the list above lets someone log into your account or your bank, so the work is watchfulness rather than emergency.
The full sequence, including what to do when a scam does arrive, is in what to do after a data breach. The tells to look for in the messages that will follow are in what phishing looks like.
What is not Known Yet
Whether Carhartt will confirm the incident publicly, how the group got in, and whether employee data was taken as claimed. The report will be updated when the company or a regulator filing adds to the record.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.