Carhartt data breach exposed information from 12.9 million user accounts
Names, emails, and more Carhartt data has been exposed by ShinyHunters.
The private information of 12.9 million Carhartt customers has been leaked online, putting their names, email addresses, phone numbers, and home addresses at risk. The data breach, orchestrated by the notorious ransomware gang ShinyHunters, resulted from unsuccessful $3.3 million ransom negotiations. The stolen data, obtained from Carhartt's Databricks analytics platform, also includes employee and customer metadata, such as royalty information.
Despite Carhartt's rejection of the ransom demand, the company decided not to engage in further discussions with the threat actors. Security analyst Troy Hunt identified the breach as originating from Carhartt's Databricks platform and noted that the archive contained both genuine and synthetic records. ShinyHunters, now focusing on data exfiltration through vishing and SaaS breaches, has already claimed responsibility for attacks on numerous Salesforce and Snowflake customers.
Carhartt operates around 60 stores in the US, employs approximately 3,000 employees, and generates an estimated $1.8 billion in annual revenue.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Hasbro Data Breach Exposed Employee Personal Information securityweek.com