Clothing retailer Carhartt had data on approximately 12.9 million customers exposed after the ShinyHunters group conducted an extortion campaign and published stolen records in August 2026.
Loading page…
Loading page…
Clothing retailer Carhartt had data on approximately 12.9 million customers exposed after the ShinyHunters group conducted an extortion campaign and published stolen records in August 2026.
According to Have I Been Pwned, in August 2026 the ShinyHunters hacking group targeted Carhartt with a "pay or leak" extortion campaign. When the company did not comply, the group published data they claimed to have obtained from Carhartt's systems. The breach was disclosed publicly on August 25, 2026.
The published dataset contained email addresses, names, phone numbers, and physical addresses. As reported by Have I Been Pwned, the corpus also included millions of synthetic records that did not correspond to real individuals; those records were excluded from the breach count.
Approximately 12.9 million unique email addresses were identified in the leaked data, suggesting a large portion of Carhartt's customer base may be affected. Only records tied to real individuals were counted.
If you have a Carhartt account, be alert for phishing emails or text messages that use your name or address to appear legitimate. Consider using a unique email alias for retail accounts going forward. Monitor for unsolicited calls or mail that may exploit your exposed contact details. No passwords or financial data were reported as part of this breach, so no immediate credential changes are required, but staying vigilant is advised.