mimile
Back to feed

Carhartt data breach exposes 12.9 million user records on dark web

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Carhartt data breach exposes 12.9 million user records on dark web

Carhartt customer data from 12.9 million accounts has been leaked onto the dark web by the ShinyHunters group. The stolen records include names, email addresses, postal addresses, and phone numbers. The breach likely originated from Carhartt's Databricks analytics platform, according to security researcher Troy Hunt.

Key Facts

  • ShinyHunters added Carhartt to its data leak site after negotiations broke down, uploading the entire stolen archive.
  • Security researcher Troy Hunt analyzed the leaked batch and concluded it most likely came from Carhartt's Databricks analytics platform.
  • The leaked data includes 12.9 million accounts with email addresses, names, phone numbers, and physical addresses.
  • Carhartt operates roughly 60 stores in the US, employs about 3,000 people, and generates an estimated $1.8 billion in annual revenue.

Breach Discovery

The ShinyHunters ransomware gang added Carhartt to its data leak site, stating that negotiations broke down and uploading the entire stolen archive. The group claimed that millions of records of customer data and sensitive information containing employee, customer, and internal corporate data were compromised. A company negotiator allegedly told the extortionists that after careful review and internal discussions, Carhartt decided not to move forward with negotiations.

Data Exposure

Security researcher Troy Hunt from HaveIBeenPwned analyzed the leaked batch and concluded it most likely came from Carhartt's Databricks analytics platform. Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains millions of synthetic records that did not relate to real individuals and were excluded from the breach.

Threat Actor Profile

ShinyHunters is currently one of the most active threat actors, having started as a typical ransomware group but abandoning encryption to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages. After gaining a foothold, they target SaaS solutions to steal valuable information, having claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.

1 source

Carhartt data breach exposes 12.9 million user records on dark web