ShinyHunters targeted clothing retailer Carhartt in a “pay or leak” extortion campaign and published data allegedly taken from the company. The validated portion contains approximately 12.9 million unique email addresses, alongside names, telephone numbers, and physical addresses; internal and customer-origin indicators support that Carhartt was genuinely breached.
The initial claim of 24,876,077 email addresses was substantially overstated because the published dataset included millions of synthetic records from TPC-DS benchmark data in a Databricks environment. Researchers excluded those sample files, as well as duplicate, deactivated, and internal performance-test records, reducing the count to 12,933,413 addresses; the analysis found no evidence that ShinyHunters fabricated the remaining data.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Clothing retailer Carhartt was targeted in a ShinyHunters “pay or leak” extortion campaign.
Have I Been Pwned founder Troy Hunt analyzed ShinyHunters' 50 GB archive and linked the exposed data to a compromise of Carhartt's Databricks analytics platform. The archive included more than 15,000 employee records using @carhartt.com addresses, alongside customer and other records.
An analysis of the published dataset identified TPC-DS synthetic benchmark records in Databricks sample paths and removed them along with duplicate aliases, deactivated accounts, and internal test data. The resulting dataset contained 12,933,413 email addresses, with remaining internal and customer indicators supporting that Carhartt was genuinely breached.
ShinyHunters subsequently published data allegedly obtained from Carhartt, including names, phone numbers, physical addresses, and 12.9 million unique email addresses. The published corpus also included millions of synthetic records not associated with real individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcebleepingcomputer.com
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcecyberveille.ch
Open sourcetheregister.com
Open sourcetroyhunt.com
Open sourcehaveibeenpwned.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.