Carhartt Hit by ShinyHunters Extortion Campaign, 12.9M Email Addresses Leaked
Earlier this month, workwear retailer Carhartt fell victim to an extortion campaign by the cybercriminal group ShinyHunters. The attackers allegedly exfiltrated and later published data containing 12.9 million unique email addresses tied to the company.
Analysis revealed that 83% of the exposed emails were already publicly available on LinkedIn or other third-party platforms, suggesting the breach may have leveraged existing data rather than a direct compromise of Carhartt’s systems. The incident highlights the risks of data aggregation by threat actors, who often combine stolen information with publicly accessible records to amplify the impact of breaches.
No further details on the attack vector or additional compromised data have been disclosed. The breach underscores the growing trend of extortion-based cybercrime, where attackers pressure organizations by threatening to release stolen data unless demands are met.
Source: https://www.linkedin.com/feed/update/urn:li:activity:7498135652006285313
Carhartt cybersecurity rating report: https://www.rankiteo.com/company/carhartt
"id": "CAR1787696780",
"linkid": "carhartt",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '12.9 million email addresses '
'exposed',
'industry': 'Workwear/Apparel',
'name': 'Carhartt',
'type': 'Retailer'}],
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '12.9 million',
'personally_identifiable_information': 'Email addresses',
'sensitivity_of_data': 'Low (83% already public)',
'type_of_data_compromised': 'Email addresses'},
'description': 'Earlier this month, workwear retailer Carhartt fell victim to '
'an extortion campaign by the cybercriminal group '
'ShinyHunters. The attackers allegedly exfiltrated and later '
'published data containing 12.9 million unique email addresses '
'tied to the company. Analysis revealed that 83% of the '
'exposed emails were already publicly available on LinkedIn or '
'other third-party platforms, suggesting the breach may have '
'leveraged existing data rather than a direct compromise of '
'Carhartt’s systems. The incident highlights the risks of data '
'aggregation by threat actors, who often combine stolen '
'information with publicly accessible records to amplify the '
'impact of breaches. No further details on the attack vector '
'or additional compromised data have been disclosed.',
'impact': {'brand_reputation_impact': 'Potential impact due to data leak',
'data_compromised': '12.9 million unique email addresses'},
'lessons_learned': 'Highlights risks of data aggregation by threat actors, '
'who combine stolen information with publicly accessible '
'records to amplify breach impact.',
'motivation': 'Extortion',
'references': [{'source': 'Cyber Incident Description'}],
'threat_actor': 'ShinyHunters',
'title': 'Carhartt Hit by ShinyHunters Extortion Campaign, 12.9M Email '
'Addresses Leaked',
'type': 'Extortion'}