Skip to content
Cyber Security Firms
ConfirmedRetail

Carhartt Data Breach (August 2026)

The ShinyHunters extortion group published data taken from the workwear retailer, and Have I Been Pwned verified 12.9 million real customer records inside it after stripping out millions of synthetic ones.

Disclosed Updated
Organization
Carhartt
Sector
Retail
Country
United States, MI
Incident date
August 13, 2026
Disclosed
August 25, 2026
Records affected
12.9 million
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses
Timeline
  1. ShinyHunters claims to have compromised Carhartt, saying it took more than 50 GB of compressed data
  2. The group publishes the data. Have I Been Pwned's first pass finds 24.9 million email addresses
  3. After analysis shows roughly 45 percent of the corpus is synthetic benchmark data, Have I Been Pwned loads 12.9 million verified addresses
  4. Troy Hunt publishes the verification write-up

What Happened

On August 13, 2026, the ShinyHunters extortion group claimed it had compromised Carhartt, the Michigan workwear retailer, and taken more than 50 GB of compressed data covering customer records, employee information and loyalty data. Per Have I Been Pwned's entry, this was a "pay or leak" campaign: the group demanded payment and, when none came, published the data.

The verification is the interesting part of this one. In his write-up of the analysis, Troy Hunt describes running the published corpus through Have I Been Pwned's extraction tooling and getting 24,876,077 email addresses. Frequency analysis then showed that about 45 percent of those were synthetic: single-use gibberish domains, perfectly uniform birth countries across 211 ISO codes, a flat spread of birth years. The pattern matched the TPC-DS benchmark dataset, which appears to have been stored in the same Databricks environment as the real customer records. The synthetic rows were excluded and 12.9 million verified addresses were loaded, most of them at real domains including carhartt.com and its "do not ship" alias.

Carhartt had not published a statement confirming or describing the incident at the time the data was verified. How the group got in has not been disclosed by the company, so the attack type on this report is undisclosed rather than a guess.

What was Exposed

The verified records contain email addresses, names, phone numbers and physical addresses. No passwords or payment data appear in the Have I Been Pwned classes for this breach.

That combination is exactly what a targeted scam needs: a real name, a real address, and a real email or phone number, all tied to a brand the person has actually bought from. Expect messages that look like Carhartt order updates, delivery problems or loyalty account notices, and expect them for months. According to the analysis, 83 percent of the affected addresses were already in Have I Been Pwned from earlier breaches, so many of the people in this set have been through this before.

What to do if you are Affected

Nothing on the list above lets someone log into your account or your bank, so the work is watchfulness rather than emergency.

The full sequence, including what to do when a scam does arrive, is in what to do after a data breach. The tells to look for in the messages that will follow are in what phishing looks like.

What is not Known Yet

Whether Carhartt will confirm the incident publicly, how the group got in, and whether employee data was taken as claimed. The report will be updated when the company or a regulator filing adds to the record.

Sources

  1. Have I Been Pwned: Carhartt
  2. Troy Hunt, A Cautionary Tale About Data Breach Claims, Verification and Carhartt, August 26, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →