The ShinyHunters extortion group has published a trove of data allegedly stolen from Carhartt, the American clothing manufacturer known for its rugged workwear. The leaked data includes information on approximately 12.9 million accounts, according to Have I Been Pwned (HIBP), a service that tracks data breaches and notifies users when their credentials are compromised.
Carhartt has not yet publicly commented on the breach. The company operates a substantial e-commerce and retail presence, serving both individual consumers and industrial clients. The compromised data is believed to include account email addresses, names, and possibly hashed passwords, though the exact scope and sensitivity of the exposed fields have not been confirmed by the company.
The ShinyHunters group is a known cybercriminal gang that has previously claimed responsibility for major breaches at companies such as Microsoft (a limited source code leak), AT&T, and Pixlr. The group often sells or publicly releases stolen databases as a means of extortion or reputation damage. In this case, the data was made available for free on underground forums, increasing the risk of misuse.
Have I Been Pwned founder Troy Hunt confirmed that the records have been ingested into the service, allowing affected users to check if their email addresses are part of the breach. Hunt noted that while the dataset appears legitimate, independent verification is ongoing.
For Carhartt customers, the immediate risks include phishing emails crafted using the exposed information, as well as credential stuffing attacks—where cybercriminals attempt to use the same email-password combination on other online services. Users are advised to change their Carhartt account password immediately, enable multi-factor authentication if available, and remain vigilant for suspicious communications.
This incident underscores the persistent threat that data breaches pose to major retailers, which hold vast amounts of customer information. Carhartt joins a growing list of companies that have been targeted by groups like ShinyHunters, highlighting the need for robust data security practices and rapid incident response.