Carhartt Hit by ShinyHunters: 13 Million Accounts Exposed After Ransom Refusal
Workwear giant **Carhartt** has reportedly suffered a significant data breach, with the notorious **ShinyHunters** extortion group leaking sensitive data from nearly 13 million accounts. The breach follows **Carhartt**'s refusal to pay a $3.3 million ransom demand, leading to the public release of customer, employee, and corporate information.

The **ShinyHunters** extortion group has published sensitive data from nearly 13 million accounts, allegedly stolen from clothing retailer **Carhartt** earlier this month. The exposure was confirmed by data breach notification service **Have I Been Pwned**.
**Carhartt**, an American apparel company founded in 1889, has yet to officially confirm the breach or issue a statement. However, **ShinyHunters** claimed on August 13 to have exfiltrated over 50GB of documents containing a wide range of customer, employee, and corporate data.
"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the cybercrime gang stated.
### Ransom Refusal Leads to Data Leak
The decision to publish the stolen records on their dark web site came after **Carhartt** reportedly declined to pay a $3.3 million ransom. According to **ShinyHunters**, a company negotiator informed the group: "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions."

*Carhartt entry on ShinyHunters leak site (BleepingComputer)*
### Databricks Platform Identified as Entry Point
**Troy Hunt**, founder of **Have I Been Pwned**, analyzed the 50GB archive released by **ShinyHunters**. His investigation linked the data breach to a compromise of **Carhartt**'s **Databricks** analytics platform, a cloud-based data solution combining business reporting and data storage.
Hunt confirmed that the breach impacts over 12.9 million **Carhartt** accounts. The exposed information includes unique email addresses, names, phone numbers, and physical addresses. Notably, "millions of synthetic records that did not relate to real individuals" were excluded from the breach count.
Additionally, over 15,000 employees with `@carhartt.com` email addresses were found within the leaked database.
A **Carhartt** spokesperson has not yet provided a comment regarding the incident.
### ShinyHunters' Persistent Campaign
**ShinyHunters** has been highly active over the past year, linked to numerous high-profile security breaches. Their targets have included over a dozen **Snowflake** customers, various third-party integration providers, and hundreds of **Salesforce** customers. The group claimed to have stolen more than 1.5 billion records in **Salesforce Aura** and **Salesloft Drift** campaigns.
Most recently, **ShinyHunters** took responsibility for breaches at over 100 organizations, exploiting an **Oracle PeopleSoft** zero-day flaw in data-theft attacks.
Past victims claimed by **ShinyHunters** include the **European Commission**, **Google**, **Cisco**, online dating giant **Match Group**, **PornHub**, video service **Vimeo**, **Rockstar Games**, edtech giant **McGraw Hill**, convenience store chain **7-Eleven**, cruise line operator **Carnival**, online training company **Udemy**, and medical device maker **Medtronic**.