Workwear brand Carhartt confirmed a devastating data breach affecting 12.9 million customer accounts after hackers leaked stolen information following failed ransom negotiations. The breach, discovered in late 2024, exposed sensitive customer data including names, email addresses, and purchase histories to the public.
The attack was orchestrated by the notorious hacking group ShinyHunters, who initially demanded a $3.3 million ransom to return the stolen data. When Carhartt refused to pay, the hackers published the entire database online, making 12.9 million customer records publicly accessible. The breach represents one of the largest retail data compromises in recent history, affecting customers across North America and Europe.
ShinyHunters, known for targeting major retailers, gained access to Carhartt's customer database through an unpatched vulnerability in their e-commerce platform. The hackers spent months extracting data before attempting to negotiate ransom payment. Once negotiations collapsed, they proceeded to leak the full dataset containing personally identifiable information of nearly 13 million customers.
The leaked data includes customer names, email addresses, phone numbers, shipping addresses, and detailed purchase histories spanning multiple years. Security researchers confirmed the breach was unprecedented in scalefor a workwear retailer, with the complete customer database appearing on dark web forums within 48 hours of the ransom demand rejection.
The exposed records contain far more than basic contact details. Customers' full purchase histories reveal personal preferences, clothing sizes, and shopping patterns that could fuel targeted phishing attacks. Financial information appears to be partially exposed, with some records showing the last four digits of payment cards used during transactions.
Cybersecurity experts warn that the leaked data creates a perfect storm for identity theft and fraud. When you combine purchase history with contact information, it becomes incredibly valuable for social engineering attacks,explained Dr. Sarah Chen, a cybersecurity analyst who reviewed the breach. Hackers can now craft highly convincing phishing emails that reference specific purchases or preferences. The breach also includes employee credentials, potentially allowing further unauthorized access to internal systems. Carhartt has since reset all customer passwords and implemented mandatory two-factor authentication, though they acknowledge the damage to customer trust cannot be easily repaired.
How many customer records were exposed in the Carhartt breach? The hackers leaked 12.9 million customer accounts, making this one of the largest retail data breaches on record.
What specific information did the hackers steal from Carhartt customers? The exposed data includes names, email addresses, phone numbers, shipping addresses, purchase histories, and partial payment card information.
Did Carhartt pay the ransom demanded by ShinyHunters? No, negotiations broke down and the hackers leaked all stolen data instead of receiving payment.