ShinyHunters claims it stole 50GB of data from workwear company Carhartt, including records linked to millions of customers and employees. The group alleges that Carhartt ended extortion talks after receiving a $3.3 million ransom demand.
ShinyHunters lists Carhartt on leak site
The hacking group added Carhartt to its dark web leak site and posted a download link to the alleged stolen data.
ShinyHunters did not provide sample files to support its claims. As a result, the reported Carhartt data breach and the scale of the alleged theft remain unverified.
The group claims it obtained 50GB of corporate information. It says the data includes customer and employee personally identifiable information, customer loyalty data and internal company records.
Carhartt has not publicly confirmed the alleged incident at the time of reporting.
Hackers claim $3.3 million ransom talks failed
ShinyHunters says it demanded $3.3 million from Carhartt and that the company initially made contact. According to the group, the negotiations ended before a deal was reached.
The hackers accused Carhartt’s representatives of handling the talks poorly. They also claimed the company could have paid less if it had continued to negotiate.
Extortion groups commonly use leak sites and public statements to increase pressure on alleged victims. Their claims should be treated cautiously because attackers can exaggerate the amount, sensitivity or legitimacy of stolen data.
It is not yet clear when the alleged breach occurred or how the attackers may have accessed Carhartt’s systems.
Customer and employee data may be at risk
If the claimed Carhartt data breach is genuine, the affected information could create risks for customers and employees.
ShinyHunters says the stolen material includes personal data belonging to millions of customers. It also claims to hold employee information and internal corporate records.
Exposed personal data can support targeted phishing, identity theft and other follow-up fraud. Criminals may use details such as names, contact information and purchase-related data to create convincing scam messages.
Customers should remain cautious of unexpected emails, SMS messages or phone calls claiming to come from Carhartt. They should avoid opening links or sharing personal details through unsolicited communications.
Carhartt operates worldwide retail network
Carhartt is a privately owned workwear and apparel company headquartered in Dearborn, Michigan. The company operates retail stores in the United States and maintains an international presence through its Carhartt WIP brand.
The company employs more than 3,000 people worldwide and sells through retail locations, wholesale partners and online channels.
Until Carhartt confirms or denies the claims, the alleged breach remains an unverified extortion-group report. Organisations facing similar claims often need time to investigate whether stolen data is authentic, identify affected systems and assess whether customers or employees require notification.


0 responses to “ShinyHunters claims millions of Carhartt customers exposed in 50GB data breach”