Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-28 ยท updated: 2026-08-28 ยท tags: [cyber, incident] ยท confidence: high ยท severity: high ยท affected_sectors: [retail] ยท au_impact: false

Carhartt Breach: ShinyHunters Releases Data of 12.9 Million Accounts

Summary

On 28 August 2026 details of a major customer data breach affecting US workwear retailer Carhartt came to wider attention. The extortion group ShinyHunters publicly released an archive of more than 12.9 million Carhartt accounts, which was subsequently analysed by the data-breach notification service Have I Been Pwned (HIBP). Troy Hunt linked the dataset back to a compromise of Carhartt's Databricks analytics platform.

Technical detail

The exposed data included unique email addresses, account names, phone numbers and physical addresses for the affected customers. The dataset also included more than 15,000 employee records with @carhartt.com email addresses. HIBP excluded "millions of synthetic records that did not to relate to real individuals". Carhartt has not yet confirmed the breach or issued a statement, so the incident type of probable breach applies. ShinyHunters first claimed the attack on 13 August, demanded a $3.3 million ransom, and published the roughly 50 GB archive offline after Carhartt declined to negotiate.

Significance

The Carhartt incident is a reminder that customer name, address and phone data โ€” even without financial details โ€” has real value to criminals, whether for identity theft, phishing or fraud. The involvement of ShinyHunters, a well-known extortion actor, shows the ongoing pressure organisations face from data extortion groups as well as from bare ransomware. The fact that the breach was likely driven from a cloud analytics platform (Databricks) is a further noteworthy pattern of data being breached in a business intelligence tool rather than through traditional e-commerce infrastructure.

AU/NZ relevance

Carhartt products are distributed in Australia and New Zealand and the affected online store could conceivably have served Australian and New Zealand customers. However, the exposure has not been specifically scoped to Australian customers. Australian and New Zealand consumers who shop with foreign retailers should remain alert for phishing or targeted fraud using the exposed data, and Australian and New Zealand retailers should take note of the lesson that analytics platforms holding customer data are a widening target for attackers.