In August 2026, the ShinyHunters extortion group stole and later published data from roughly 12.9 million Carhartt accounts, reportedly through the company’s Databricks analytics platform. Exposed information includes names, email addresses, phone numbers, and physical addresses for customers and over 15,000 employees. Affected individuals should monitor credit reports and stay alert for phishing attempts referencing Carhartt.
| Company | Carhartt |
|---|---|
| Industry | Retail |
| Data Types Exposed | Full Names, Email Addresses, Phone Numbers, Physical Addresses, Customer Loyalty Metadata, Employee Corporate Email Addresses |
| People Affected | 12.9 million accounts |
| Attack Method | Extortion/Data Theft |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the Carhartt Data Breach?
The Carhartt data breach involves the theft and public release of records tied to nearly 13 million customer and employee accounts. An extortion group known as ShinyHunters claimed responsibility for the attack. According to the group, unauthorized access to Carhartt’s network occurred in August 2026.
ShinyHunters said it pulled more than 50GB of files containing a broad mix of customer, employee, and internal corporate records. The group has since tied the intrusion to Carhartt’s Databricks analytics environment, a cloud platform used to store and process large volumes of business data. After Carhartt reportedly declined to pay a $3.3 million ransom demand, the attackers published the stolen archive on a dark web leak site.
A well-known breach notification service analyzed the leaked archive and confirmed it affects real Carhartt accounts. However, the researcher also found that millions of additional records in the file were synthetic and did not belong to actual people. As a result, those fake entries were excluded from the final breach count. Carhartt has not yet issued a public statement confirming the incident or detailing its own forensic findings.
Who was affected?
Because the exposed data touched customer, employee, and corporate systems, the Carhartt data breach likely affects several distinct groups of people. Customers who created accounts or made purchases through Carhartt’s platforms appear to make up the bulk of the exposed records. In addition, researchers identified more than 15,000 unique email addresses belonging to current or former Carhartt employees within the leaked files.
The confirmed scope of the breach stands at more than 12.9 million accounts. This figure reflects real individuals only, after synthetic and fabricated entries were filtered out. Given Carhartt’s presence across the United States and Europe, the affected population likely spans multiple countries.
It also remains unclear whether minors are among the affected individuals. Because Carhartt sells apparel to a wide consumer base, some accounts may belong to younger customers or family members. Anyone who has ever placed an order or created a loyalty account with Carhartt should consider themselves potentially affected until the company issues formal notifications.
What Information Was Potentially Exposed?
The data released by ShinyHunters reportedly includes a mix of personal and corporate information. Based on the analysis conducted after the leak, the following categories of data were confirmed as exposed for real individuals:
- Full names
- Email addresses
- Phone numbers
- Physical mailing addresses
- Customer metadata, including loyalty program details
- Employee corporate email addresses
Although this breach does not appear to include Social Security numbers or payment card data, the exposed information still carries real risk. For example, criminals often combine names, phone numbers, and addresses to build convincing phishing or smishing campaigns. Because the data includes both customer and employee details, scammers could impersonate Carhartt itself when targeting victims.
Furthermore, exposed contact information can fuel targeted social engineering attacks. Fraudsters may use loyalty program details to appear legitimate when contacting victims by phone or email. This increases the likelihood that a victim mistakenly shares additional sensitive information, such as login credentials or financial details, believing they are speaking with a trusted retailer.
What is the company doing?
As of this writing, Carhartt has not publicly confirmed the extortion group’s claims. The company also has not issued a detailed statement addressing the scope of the incident. However, the breach notification service that verified the leaked archive has made its findings public, which effectively confirms that real customer and employee data was exposed.
Companies facing this type of extortion attempt typically launch an internal investigation, engage outside forensic experts, and review access to affected systems, including third-party cloud platforms. Given the reported link to a Databricks environment, Carhartt will likely need to review how that platform was accessed and secured. Additionally, affected individuals should watch for official notification letters, which would outline any credit monitoring or identity protection services offered.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Because your name, address, and phone number were exposed, you should start monitoring your credit reports right away. Regularly checking your reports helps you catch new accounts or inquiries you did not authorize. You can request free reports from all three major credit bureaus through AnnualCreditReport.com.
In addition, consider spacing out your requests throughout the year so you have ongoing visibility. This way, you are not left without monitoring for long stretches. If you notice unfamiliar accounts or hard inquiries, dispute them with the bureau immediately.
Stay Alert for Phishing and Impersonation Attempts
Because scammers now have your contact details, you should expect an increase in suspicious emails, texts, and phone calls. Be especially cautious of messages that claim to come from Carhartt or reference your loyalty account. Never click links or share personal information unless you can verify the sender independently.
Instead, contact Carhartt directly through its official website or customer service line if you receive a suspicious message. This lets you confirm whether the communication is legitimate. As a general rule, legitimate companies rarely ask for sensitive details through unsolicited emails or texts.
Consider a Fraud Alert if You Notice Suspicious Activity
Although this breach does not appear to include Social Security numbers, exposed contact information can still be used to attempt account takeovers. Therefore, if you notice unusual account activity tied to your name, phone number, or email, consider placing a fraud alert with the credit bureaus. This makes it harder for someone to open new credit in your name.
A fraud alert typically lasts one year and can be renewed. Setting one up is free and only takes a few minutes online or by phone. This step adds an extra layer of protection while you monitor for further signs of misuse.
Update Passwords and Enable Extra Account Security
Because your email address was part of the leak, you should update passwords on any accounts linked to that address. This is especially important if you reused the same password across multiple sites. Choose strong, unique passwords for each account going forward.
Additionally, enable multi-factor authentication wherever it is available. This adds a second layer of verification beyond just a password. As a result, even if criminals obtain your login details, they will face an added barrier to accessing your accounts.
