ShinyHunters dumps 12.9 million Carhartt customer records after ransom refusal
The extortion crew says it grabbed 50GB from the workwear brand's cloud analytics platform. Carhartt walked away from a $3.3 million demand, and the data is now public.

Key points
- ShinyHunters published data on 12.9 million Carhartt accounts after the retailer refused a $3.3 million ransom demand made in August 2025.
- The stolen archive weighs about 50GB and includes names, email addresses, phone numbers and physical addresses.
- Have I Been Pwned founder Troy Hunt traced the theft to Carhartt's Databricks cloud analytics platform.
- More than 15,000 staff email addresses ending in @carhartt.com also appeared in the leak.
- ShinyHunters has been tied this year to breaches at Google, Cisco, Vimeo and dozens of Snowflake and Salesforce customers.
The extortion group ShinyHunters has dumped a huge cache of stolen data from the American workwear brand Carhartt, first reported by BleepingComputer. Around 12.9 million customer accounts are in the file.
Carhartt, which has made rugged clothing since 1889 and employs more than 3,000 people across the US and Europe, refused to pay. So the criminals published everything.
What was actually stolen?
Roughly 50GB of files, including names, email addresses, phone numbers and home addresses for nearly 13 million Carhartt customers. Employee records and internal corporate documents are in there too.
Troy Hunt, who runs the breach-notification site Have I Been Pwned, went through the archive and loaded 12.9 million affected accounts into his service. He also found more than 15,000 email addresses ending in @carhartt.com, suggesting most of the company's staff directory is in the dump.
Hunt noted the archive also contained "millions of synthetic records" (fake test data), which he stripped out before loading the real ones.
How did the attackers get in?
Hunt linked the theft to Carhartt's Databricks setup. Databricks is a cloud service where companies pile up their customer data for analytics and reporting, essentially one giant filing cabinet in the cloud.
If that filing cabinet is reachable with stolen or weak login details, an attacker can walk out with the lot in one go. This is not a novel AI-era attack. It is the same story we have seen at dozens of Snowflake customers over the past year: a cloud data warehouse, valid credentials, no extra checks, done.
Carhartt has not publicly confirmed the breach or explained how the account was accessed.
What happened with the ransom?
ShinyHunters claimed the attack on 13 August 2025 and demanded $3.3 million. Carhartt said no.
According to chat logs the group posted, a company negotiator told them: "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions." The data went up on the group's dark web leak site shortly after.
| Detail | Figure |
|---|---|
| Accounts exposed | 12.9 million |
| Staff emails in dump | 15,000+ |
| Archive size | ~50GB |
| Ransom demanded | $3.3 million |
| Attack claimed | 13 August 2025 |
Should Carhartt customers worry?
Yes, but the risk is mostly scams rather than direct financial theft. Payment card numbers have not been reported as part of the leak. Contact details have.
That means anyone who bought from Carhartt should expect a wave of phishing emails, which are fake messages designed to look like they come from the retailer, plus text-message scams and possible junk post. Two practical steps: treat any "Carhartt order problem" email with suspicion and go to the website directly, and change your Carhartt password if you reused it anywhere else.
You can check whether your email address is in this dump on Have I Been Pwned.
Who are ShinyHunters?
A data-theft and extortion crew that has had a very busy 2025. They have been tied to breaches at more than a dozen Snowflake customers, hundreds of Salesforce customer environments through the Salesforce Aura and Salesloft Drift campaigns, and most recently a wave of attacks using a zero-day flaw (a bug the vendor did not know about) in Oracle PeopleSoft.
Among organisations they have claimed to hit: Google, Cisco, the European Commission, Match Group, Vimeo, Rockstar Games, McGraw Hill, 7-Eleven, Carnival, Udemy and medical device maker Medtronic. The pattern is consistent. Find a cloud platform holding lots of customer data, get in with valid credentials, take everything, demand payment.



