Troy Hunt, the Australian security researcher who runs the Have I Been Pwned (HIBP) breach-notification service, has reduced the estimated scope of the Carhartt data breach by nearly half, concluding that 12.9 million of the 24.8 million claimed records belong to real individuals.
ShinyHunters, a well-known cybercriminal group, leaked what it said was 50GB of Carhartt's data on August 13 after the workwear retailer refused to pay a $3.3 million extortion demand. The hackers publicly mocked Carhartt for hiring what they called "a very unskilled and incompetent negotiator."
In a detailed analysis published this week, Hunt said the leaked dataset contained millions of artificially generated records, likely using TPC-DS, a standard synthetic data generator used in database benchmarking. Suspicious patterns included an unusually high number of .edu and .org email domains, random-string domains such as lkvb06fkzsjv.org, fabricated names like michael.ware@c.edu, and customers registered in countries far outside Carhartt's main markets. The AI-assisted analysis also found more purported customers in Montenegro than in the United States, where Carhartt is headquartered, and an implausible number of account holders with birth dates in the early 1900s.
"You're not going to believe this, but turns out you can't always take criminals at their word," Hunt said, explaining that he used HIBP's open-source email extractor and the OpenClaw AI tool to sift through the data. After removing clear synthetic entries, duplicate Microsoft 365 addresses, and other anomalies, he arrived at 12,933,413 genuine accounts. HIBP's platform notes that 83 percent of those email addresses had already appeared in previous breaches.
Carhartt has not publicly commented on the breach or Hunt's findings. The company did not respond to a request for comment from The Register. The real leaked data reportedly includes names, email addresses, phone numbers, and physical addresses, leaving affected customers at risk of phishing and identity fraud despite the smaller-than-claimed scale.
Security experts say the incident underscores the importance of independent verification. "Take headline numbers with a grain of salt unless you're confident in the processes of those making the claims," Hunt advised. The final HIBP count gives affected consumers a more accurate picture, but it also raises questions about how much of ShinyHunters' data was genuine and what Carhartt knew about the breach.