Carhartt Breach: Why the 24 Million "Stolen Records" Headline Was Half Fiction
ShinyHunters says it pulled 50 gigabytes of data from Carhartt and exposed nearly 24 million customer records. Troy Hunt says not so fast. When the founder of Have I Been Pwned finished cleaning the leak, the real number of affected people landed at 12.9 million — and the gap says as much about how breach statistics get reported as it does about the attack itself.
The clothing retailer confirmed nothing for two weeks. ShinyHunters first claimed the hit on August 13, saying it had grabbed more than 50GB of documents holding customer, employee, and corporate data. When Carhartt refused to pay the group's $3.3 million ransom demand, the extortion crew published the archive on its dark-web leak site. Have I Been Pwned then loaded the data, and the incident joined a long list of ShinyHunters victims that already includes Google, Cisco, Match Group, and McGraw Hill.
A 50GB dump and a $3.3 million demand
Carhartt is not a small target. The workwear brand was founded in 1889 and runs manufacturing facilities in Kentucky and Tennessee, with more than 3,000 employees across the United States and Europe. ShinyHunters described the stolen material as "millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data."
The gang's negotiator claims Carhartt walked away from talks. "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company representative told the extortionists, according to ShinyHunters. Carhartt has still not issued a public statement confirming the breach. BleepingComputer reported it reached out to the company and received no comment.
That silence is common, but it leaves customers guessing. The leaked database held names, email addresses, phone numbers, and physical addresses. Hunt also found more than 15,000 entries with @carhartt.com employee addresses, which points to an insider-level extraction rather than a scraped public list.
Where the Databricks trail leads
Hunt's analysis traced the source to Carhartt's Databricks environment — a cloud data platform that fuses analytics and storage into one architecture. That detail matters. A retailer's customer warehouse is a single, rich target: it can hold purchase history, demographics, and contact records in one place, which is exactly the kind of haul an extortion group wants.

ShinyHunters has leaned on this pattern all year. The group was tied to breaches at more than a dozen Snowflake customers, a string of third-party integration providers, and claimed hits at hundreds of Salesforce customers through the Salesforce Aura and Salesloft Drift campaigns. Most recently it took credit for intrusions at more than 100 organizations by exploiting an Oracle PeopleSoft zero-day flaw. The Carhartt leak fits a playbook built on cloud and SaaS data stores, not on breaking into a single laptop.
The 24 million that weren't there
Here is where the story gets interesting. Hunt's usual workflow is to run an open-source email extractor over a leaked corpus, count the unique addresses, and load them. His first pass on the Carhartt file returned 24,876,077 addresses. That is a big number, the kind that makes headlines. It was also wrong.
Drilling into the data, Hunt noticed something odd: an unusually high share of addresses used .edu and .org domains for a workwear retailer. Looking closer, he found the local parts looked real — Firstname.Lastname — but the domains were gibberish, strings like xgpgHqAu.com with no vowels. Those were not customers. They were synthetic records generated by a benchmarking tool.
The leak had scooped up Carhartt's own test data. The customer tables followed the TPC-DS benchmark schema, a standard retail analytics format used for performance testing. Real Carhartt records sat in the same schema as millions of auto-generated fake ones, and ShinyHunters — along with the aggregators that reposted the figures — grabbed everything without knowing the difference.
The tells piled up. Birth-country fields were spread almost evenly across all 211 ISO countries, with the United States appearing only 407 times. Birth years ran in a perfectly flat line from 1924 to 1992. A real customer base skews toward recent decades and a handful of markets; a random number generator does not. Domain analysis showed 97.6% of email domains appeared exactly once — a signature of generated data, not a living retailer's list.
Counting real people, not rows
After stripping the synthetic records, the count fell to about 13.3 million. Then Hunt kept refining. Microsoft 365 had created three address variants for many employees — carhartt.com, carhartt.onmicrosoft.com, and carhartt.mail.onmicrosoft.com — all the same person. Around 289,000 addresses began with "deactivate-", a soft-delete flag Carhartt used to retire accounts; 99% of those duplicated an active address. Test domains like wctest.com and carharttdonotship.com added tens of thousands more phantom rows.
The final, defensible figure: 12,933,413 unique email addresses, which Hunt rounded to 12.9 million in the public breach entry. Nearly half the original corpus never represented a real person.
The episode is a cautionary tale about taking criminals at their word. The underlying breach was real — 15,000 internal employee addresses and Carhartt-specific sub-address tags like +carhartt prove the data came from the company's own systems. But the headline scope was inflated by data the attackers never meant to steal and likely never noticed.
What customers should actually do
For the people whose addresses are real, the practical steps are unchanged. Carhartt has not reported passwords in the exposed tables — the customer schema Hunt reviewed showed login fields empty — but names, emails, phones, and home addresses are enough for targeted phishing. Expect messages that reference an order or an account to look more convincing than usual.
Turn on multi-factor authentication wherever it is offered, and treat any unexpected "reset your password" or "confirm your shipping" email as suspect until checked on the real site. Freezing credit with the major bureaus is worth considering given the volume of identity-linked data in the open. The breach notification at Have I Been Pwned lets affected users confirm whether their address appears in the cleaned, 12.9 million-record set rather than the inflated 24 million figure.
The bigger lesson for breach reporting
This case shows why raw leak sizes deserve skepticism. Extortion groups have no incentive to understate a haul, and the louder the number, the more pressure it puts on a victim.
![]()
News outlets that repeat the first figure without verification can double-count test data and duplicates, making a bad incident look twice as large as it is.
Hunt's point is not that Carhartt was fine — it was breached, and real customers are exposed. The point is that "the truth is in the data," and reaching it takes work most aggregators skip. As more retailers park customer histories in cloud warehouses like Databricks, the gap between a dramatic headline and a verified count will keep widening. The next 50GB dump will arrive with a big number attached. The responsible move is to read it carefully before repeating it.
For ongoing coverage of extortion-group activity and actively exploited flaws, see our Cybersecurity section, and for the wider pattern of cloud data-store intrusions, our Cloud & Edge Computing reporting tracks how warehouses like Databricks become breach targets.
Sources:
- BleepingComputer: Carhartt data breach exposes information of 12.9 million accounts
- Troy Hunt / Have I Been Pwned: A Cautionary Tale About Data Breach Claims, Verification and Carhartt
- Have I Been Pwned breach entry: Carhartt