← Terug naar overzicht

The ShinyHunters extortion group has published sensitive data stolen from clothing retailer Carhartt, exposing information from nearly 12.9 million accounts. The breach was reported by data breach notification service Have I Been Pwned. The data was stolen earlier in the month before being publicly released. Carhartt is a major clothing retailer, making this a significant consumer data breach. The ShinyHunters group is a known threat actor responsible for multiple high-profile data breaches. The scale of the breach, affecting nearly 13 million accounts, makes this a high-impact incident for affected customers.

Technical details

The ShinyHunters extortion group claimed responsibility for breaching Carhartt on August 13, allegedly stealing more than 50GB of data. The breach was linked by Have I Been Pwned founder Troy Hunt to the compromise of Carhartt's Databricks analytics platform, a cloud-based data platform combining business reporting and data storage. The stolen data affected 12.9 million accounts and included unique email addresses, names, phone numbers, physical addresses, customer metadata (loyalty/royalty information), employee data (over 15,000 employees with @carhartt.com email addresses), and other internal corporate data. The archive also contained millions of synthetic records not related to real individuals, which were excluded from the breach count. ShinyHunters demanded a $3.3 million ransom, which Carhartt declined to pay, after which the group released the full 50GB archive on their dark web leak site.

Mitigation steps

1. Carhartt customers and employees should monitor their accounts for suspicious activity and consider changing passwords, especially if the same credentials are reused elsewhere. 2. Check Have I Been Pwned (haveibeenpwned.com/Breach/Carhartt) to determine if your account was included in the breach. 3. Be vigilant against phishing attempts leveraging exposed PII such as names, email addresses, phone numbers, and physical addresses. 4. Organizations using Databricks or similar cloud analytics platforms should audit access controls, review authentication logs, and ensure multi-factor authentication is enforced. 5. Monitor for unauthorized use of exposed @carhartt.com employee credentials. 6. Review and harden security configurations on cloud-based data platforms to prevent unauthorized access. 7. Implement data minimization practices to reduce the exposure footprint in the event of future breaches.

Affected products

  • Databricks analytics platform (Carhartt's cloud-based data platform)

Related threat actors

  • ShinyHunters

IOC's

ShinyHunters dark web leak site (Carhartt entry), @carhartt.com email addresses (15,000+ employee accounts exposed)

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Database & Storage

Related links