The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt, according to data breach notification service Have I Been Pwned. The stolen records affect more than 12.9 million Carhartt accounts, with exposed information including unique email addresses, names, phone numbers, and physical addresses. Have I Been Pwned founder Troy Hunt also found over 15,000 employees with @carhartt.com email addresses in the leaked database. Hunt excluded millions of synthetic records that did not relate to real individuals from the breach count.

Carhartt is an American apparel company founded in 1889, known for workwear and streetwear, with manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe. The company has yet to confirm the extortion group’s claims or issue a statement about the breach. A Carhartt spokesperson was not immediately available for comment when BleepingComputer reached out with questions. ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing customer, employee, and corporate data.

According to the cybercrime gang, the compromised data includes millions of records of customer data and a vast amount of sensitive information and personally identifiable information containing employee, customer, and customer metadata, as well as other internal corporate data. After failing to pressure Carhartt into paying a $3.3 million ransom demand, ShinyHunters released an archive of the allegedly stolen records on its dark web site. The group shared a company negotiator’s message that stated, according to ShinyHunters, that Carhartt leadership had decided not to move forward with negotiations or further discussions.

After analyzing the 50GB archive, Hunt linked the data breach to the compromise of Carhartt’s Databricks analytics platform, a cloud-based data platform combining standard business reporting and data storage into a unified architecture. This connection points to a specific technical vector for the incident affecting a major American consumer brand. The breach exposes personal information of US customers and employees, raising concerns for the retailer’s large domestic footprint.

Over the past year, ShinyHunters has been linked to security breaches at over a dozen Snowflake customers, as well as many third-party integration providers. The group has also claimed breaches at hundreds of Salesforce customers, saying they stole more than 1.5 billion records in Salesforce Aura and Salesloft Drift campaigns. Most recently, ShinyHunters claimed responsibility for a series of breaches at more than 100 organizations following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.

Among the breaches claimed by ShinyHunters are the European Commission, Google, Cisco, online dating giant Match Group, PornHub, video service Vimeo, Rockstar Games, edtech giant McGraw Hill, convenience store chain 7-Eleven, cruise line operator Carnival, online training company Udemy, and medical device maker Medtronic. The group’s pattern of targeting large enterprises and public institutions highlights a persistent threat to US companies and their customer data. Overall prevention scores can hide what happens after initial access, as once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

More cybersecurity news from TechManNews.