The ShinyHunters extortion group released sensitive data from approximately 12.9 million Carhartt accounts. This action occurred after Carhartt declined to pay a $3.3 million ransom demanded by the group. ShinyHunters initially claimed the attack on August 13, stating they had stolen over 50GB of customer, employee, and corporate data.
Analysis by Have I Been Pwned founder Troy Hunt confirmed that the leaked data includes unique email addresses, names, phone numbers, and physical addresses. The breach also affected over 15,000 employees with @carhartt.com email addresses. The cybercrime group stated that millions of customer records and extensive sensitive information, including personally identifiable information (PII) for employees and customers, were compromised.
The data breach has been linked to a compromise of Carhartt's Databricks analytics platform. Databricks is a cloud-based data platform that integrates business reporting and data storage. Carhartt has not yet issued a public statement or confirmed the claims made by ShinyHunters regarding the breach.
ShinyHunters has been associated with multiple security incidents over the past year. The group has been linked to breaches affecting over a dozen Snowflake customers and numerous third-party integration providers. They have also claimed responsibility for breaches impacting hundreds of Salesforce customers, asserting the theft of more than 1.5 billion records in total.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The ShinyHunters extortion group published sensitive data from nearly 13 million Carhartt accounts after the company refused to pay a $3.3 million ransom. The breach, linked to Carhartt's Databricks analytics platform, exposed email addresses, names, phone numbers, and physical addresses of customers and employees. This incident highlights the ongoing threat of data extortion and the importance of securing cloud-based data platforms.