CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5899

As cited

Copy frozen at (site build).

breaches incidents

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

Carhartt's data breach affected 12.9 million individuals, roughly half the 24.8 million ShinyHunters claimed when it leaked company data on August 13, 2026. Troy Hunt's analysis of the dump using email extraction and artificial intelligence tools identified millions of synthetically injected records, including fabricated email domains, implausible geographic distributions, and unlikely birth dates. The real data contained names, email addresses, phone numbers, and physical addresses, with 83 percent already present in prior breaches.

Why it matters: Carhartt customers with exposed personal information should monitor for phishing and identity theft, while security teams should verify breach claims independently rather than accepting criminal statements at face value, as inflated numbers can distort incident response priorities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

Carhartt's data breach affected 12.9 million individuals, roughly half the 24.8 million ShinyHunters claimed when it leaked company data on August 13, 2026. Troy Hunt's analysis of the dump using email extraction and artificial intelligence tools identified millions of synthetically injected records, including fabricated email domains, implausible geographic distributions, and unlikely birth dates. The real data contained names, email addresses, phone numbers, and physical addresses, with 83 percent already present in prior breaches.

Why it matters: Carhartt customers with exposed personal information should monitor for phishing and identity theft, while security teams should verify breach claims independently rather than accepting criminal statements at face value, as inflated numbers can distort incident response priorities.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary