Carhartt breach confirmed at 12.9M victims, far fewer than hacker group claimed

Have I Been Pwned analysis finds millions of synthetic records padded ShinyHunters' data dump

edit
By LineZotpaper
Published
Read Time3 min
Carhartt's data breach affected 12.9 million people, according to Have I Been Pwned founder Troy Hunt, roughly half the 24.8 million figure the cybercriminal group ShinyHunters claimed when it leaked 50GB of retailer data this month. Hunt's analysis found the dump was heavily padded with synthetic records, and the actual number of genuine victims is far below the hackers' headline number.

Troy Hunt, the Australian security researcher who runs the Have I Been Pwned (HIBP) breach-notification service, has reduced the estimated scope of the Carhartt data breach by nearly half, concluding that 12.9 million of the 24.8 million claimed records belong to real individuals.

ShinyHunters, a well-known cybercriminal group, leaked what it said was 50GB of Carhartt's data on August 13 after the workwear retailer refused to pay a $3.3 million extortion demand. The hackers publicly mocked Carhartt for hiring what they called "a very unskilled and incompetent negotiator."

In a detailed analysis published this week, Hunt said the leaked dataset contained millions of artificially generated records, likely using TPC-DS, a standard synthetic data generator used in database benchmarking. Suspicious patterns included an unusually high number of .edu and .org email domains, random-string domains such as lkvb06fkzsjv.org, fabricated names like michael.ware@c.edu, and customers registered in countries far outside Carhartt's main markets. The AI-assisted analysis also found more purported customers in Montenegro than in the United States, where Carhartt is headquartered, and an implausible number of account holders with birth dates in the early 1900s.

"You're not going to believe this, but turns out you can't always take criminals at their word," Hunt said, explaining that he used HIBP's open-source email extractor and the OpenClaw AI tool to sift through the data. After removing clear synthetic entries, duplicate Microsoft 365 addresses, and other anomalies, he arrived at 12,933,413 genuine accounts. HIBP's platform notes that 83 percent of those email addresses had already appeared in previous breaches.

Carhartt has not publicly commented on the breach or Hunt's findings. The company did not respond to a request for comment from The Register. The real leaked data reportedly includes names, email addresses, phone numbers, and physical addresses, leaving affected customers at risk of phishing and identity fraud despite the smaller-than-claimed scale.

Security experts say the incident underscores the importance of independent verification. "Take headline numbers with a grain of salt unless you're confident in the processes of those making the claims," Hunt advised. The final HIBP count gives affected consumers a more accurate picture, but it also raises questions about how much of ShinyHunters' data was genuine and what Carhartt knew about the breach.

§

Analysis

Why This Matters

  • Affected Carhartt customers need accurate information to assess their risk of phishing, identity theft, and fraud.
  • The case highlights how cybercriminals inflate breach figures, creating unnecessary panic and undermining trust in security reporting.
  • Carhartt's continued silence leaves customers without official guidance on protective steps, even as independent verification narrows the impact.

Background

ShinyHunters is a prolific hacking group known for selling and leaking stolen corporate data. The Carhartt breach surfaced publicly on August 13, 2026, when the group dumped what it claimed was a 50GB trove after failed ransom negotiations. The initial claim of nearly 25 million affected individuals was amplified by media coverage, but no independent verification occurred until Troy Hunt reviewed the dataset for Have I Been Pwned.

Hunt's methodology involved automated email extraction, AI-based anomaly detection, and manual review. The presence of TPC-DS synthetic data — a benchmark dataset used by database vendors — strongly suggested the hackers had intentionally padded the dump. This is not the first time ShinyHunters has been accused of exaggerating; the group has a history of recycling older leaked datasets alongside new material.

Carhartt, a privately held company founded in 1889, has not issued any public statement about the breach. Its lack of communication has been criticized, as it contrasts with standard practice where affected companies notify regulators and customers within a reasonable timeframe.

Key Perspectives

Troy Hunt / Security researchers: The HIBP analysis is the most reliable public assessment. Hunt argues that breach figures from criminals should be treated as unverified until independently examined. His work provides a defensible number for affected individuals. ShinyHunters: The group maintains it accessed and leaked genuine Carhartt data. Their own statements claimed the retailer's negotiator was inept, and they portrayed the breach as far more extensive than Hunt found. They have no incentive to correct the record. Carhartt: The company remains silent, possibly to limit liability or because it is still investigating. Its absence leaves customers uncertain, though Hunt's findings suggest the breach is real but less damaging than claimed. Affected customers: Those whose genuine data was leaked face real exposure. Even with 12.9 million people affected, the risk of targeted phishing campaigns is significant, especially given the inclusion of physical addresses and phone numbers.

What to Watch

  • Whether Carhartt finally issues an official statement or breach notification, and whether it confirms or disputes Hunt's 12.9 million figure.
  • The response of state attorneys general or data-protection regulators, who may open investigations into the breach and the company's handling of it.
  • Any further analysis of the dataset for specific high-risk records, such as payment data or government IDs, which Hunt has not detailed.
  • Whether ShinyHunters releases follow-up leaks or claims to detail synthetic data injection, potentially escalating the blame game.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.