Summary
ShinyHunters published what it claims is 50 gigabytes of stolen Carhartt data on August 14, 2026 after the 138-year-old workwear manufacturer declined to pay a $3.3 million ransom demand and what the group described as an incompetent negotiation. Have I Been Pwned founder Troy Hunt analyzed the leaked dataset and identified 12,933,413 unique email addresses belonging to real individuals, approximately half of the 25 million ShinyHunters implied when it published the archive. The discrepancy reflects ShinyHunters' documented practice of padding leaked datasets with synthetic records to inflate apparent scope. Hunt's analysis excluded nearly 12 million addresses identified as synthetic, test, disposable, or non-human before arriving at the 12.9 million figure. HIBP now records the Carhartt breach as exposing names, email addresses, phone numbers, and physical addresses. Hunt noted that 83 percent of the affected email addresses were already in HIBP from previous breaches, meaning the majority of affected individuals are not new to breach exposure. Carhartt has not publicly confirmed the breach, acknowledged the ransom demand, or disclosed the number of affected individuals. ShinyHunters published a message it claims to have received from Carhartt during negotiations stating the company had decided not to move forward with discussions.
Timeline
| Date | Event |
|---|---|
| Aug 13, 2026 | ShinyHunters breaches Carhartt systems — 50GB data claimed exfiltrated |
| Aug 14, 2026 | ShinyHunters lists Carhartt on dark web leak site — publishes archive after ransom negotiations end |
| Aug 14, 2026 | ShinyHunters states demand was $3.3 million — criticizes Carhartt's negotiating competence |
| Aug 25, 2026 | Troy Hunt analyzes leaked dataset — 12,933,413 real accounts identified after synthetic padding removed |
| Aug 25, 2026 | Have I Been Pwned adds Carhartt breach — 83% of addresses already in previous breaches |
| Aug 27, 2026 | Carhartt has not publicly confirmed the breach or the number of affected individuals |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| carhartt.com | 56.82 | ✓ | ✓ | ✓ | Live |
Context
carhartt.com scores 56.82 — a low-trust range score reflecting live signals across the domain's reputation profile at the time of capture. For a nearly 140-year-old American workwear brand with a strong consumer identity, a score at this level is a meaningful signal. The breach follows ShinyHunters' documented 2026 campaign targeting major consumer brands and communications platforms: Aura in March, RingCentral in July, ReliaQuest in August. The Carhartt response — declining to pay, declining to publicly confirm, declining to disclose affected individual counts — is a defensible corporate position but one that leaves affected customers without actionable information. The 12.9 million individuals whose names, email addresses, phone numbers, and physical addresses are now in Have I Been Pwned did not receive that information from Carhartt. They received it from Troy Hunt.
The Trust Observatory · thetrustobservatory.com · August 27, 2026