Carhartt customer data was exposed in a breach, and a review of the leaked files found about 12.9 million real records rather than the much larger total claimed by ShinyHunters. Troy Hunt said the August 13 leak had been padded with synthetic records, but the genuine data still includes names, email addresses, phone numbers, and physical addresses. Carhartt has not publicly commented on the breach.
Why it matters: Millions of Carhartt customers may face phishing, scam, or identity-fraud risks even though the criminals exaggerated the breach size. Affected users should watch for targeted messages and consider extra caution around unsolicited texts, calls, and emails using their personal details.
SecurityWeek News
2026.08.28
97% relevant
This roundup adds Troy Hunt's analysis that about half of the 24.8 million email addresses in the alleged Carhartt breach dataset were synthetic TPC-DS benchmark records, reinforcing that the original leak claim overstated the number of real exposed customer records.
Sergiu Gatlan
2026.08.27
98% relevant
This article directly updates the same Carhartt breach by reporting Have I Been Pwned's analysis of the leaked archive, tying the incident to Carhartt's Databricks analytics platform and clarifying that the exposed data includes about 12.9 million real accounts plus synthetic records excluded from the final count.
2026.08.26
100% relevant
This article establishes a trackable breach event by providing a concrete victim, estimated affected count, exposed data types, and the link to a specific ShinyHunters leak posted on August 13.
← Back to all stories