Skip to content
Tech News
← Back to articles

Carhartt data breach exposes information of 12.9 million accounts

read original more articles
Why This Matters

The Carhartt data breach exposing nearly 13 million accounts highlights the growing threat of cyberattacks targeting large corporations, emphasizing the importance of robust cybersecurity measures. This incident underscores the risks consumers and companies face regarding sensitive personal and corporate data being compromised and potentially exploited. It serves as a reminder for organizations to strengthen their data security protocols to protect stakeholder information.

Key Takeaways

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe.

While Carhartt has yet to confirm the extortion group's claims or issue a statement about the breach, ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data.

"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the cybercrime gang said.

ShinyHunters also released an archive of the allegedly stolen records on its dark web after failing to pressure the apparel giant into paying a $3.3 million ransom demand.

"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator told the extortion gang, according to ShinyHunters.

Carhartt entry on ShinyHunters leak site (BleepingComputer)

​After analyzing the 50GB archive released by ShinyHunters on their dark web site, Have I Been Pwned founder Troy Hunt linked the resulting data breach to the compromise of Carhartt's Databricks analytics platform (a cloud-based data platform that combines standard business reporting and data storage into a unified architecture).

Hunt added that the data breach affects more than 12.9 million Carhartt accounts, with the exposed information including unique email addresses, names, phone numbers, and physical addresses, as well as "millions of synthetic records that did not relate to real individuals and were excluded from the breach."

The Have I Been Pwned founder also found over 15,000 employees with @carhartt.com email addresses in the leaked database.

... continue reading