Data Leak
Carhartt public leak after ShinyHunters extortion and Databricks linkage
Updated 27.08.2026 14:10
Case score 89
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 89
- Main story score
- 89
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Data Leak Primary incident and public leak affecting Carhartt, including the extortion claim, archive release, Databricks linkage, and exposed-account scale. main
Members 1
First seen 27.08.2026 14:10
Latest activity 27.08.2026 14:10
Overview
ShinyHunters has moved the **Carhartt** incident from an extortion claim to a public data-leak event by releasing an allegedly stolen archive on a dark web site after a **$3.3 million ransom** went unpaid. The archive was described as more than **50GB** of customer, employee, and corporate data, and subsequent analysis tied the exposure to Carhartt's **Databricks analytics platform**.
Have I Been Pwned said the leak affects **more than 12.9 million Carhartt accounts** and includes names, email addresses, phone numbers, and physical addresses, with **over 15,000** employee **@carhartt.com** addresses also present. Carhartt had not publicly confirmed the extortion claim or disclosed remediation details in the available material.
Latest development Open development history ShinyHunters claims Carhartt data theft On August 13, ShinyHunters said it had stolen more than 50GB of documents from Carhartt, including customer, employee, and corporate data, while Carhartt had not confirmed the extortion group's claims or issued a statement about the breach.
-
Have I Been Pwned links leaked Carhartt archive to Databricks compromise
By August 27, Have I Been Pwned had analyzed the 50GB archive released on the dark web after ShinyHunters failed to extract a $3.3 million ransom, and Troy Hunt linked the breach to Carhartt's Databricks analytics platform. The exposed data was said to affect more than 12.9 million Carhartt accounts and included unique email addresses, names, phone numbers, and physical addresses, with over 15,000 employees using @carhartt.com addresses appearing in the leaked database.
ShinyHunters has published an archive of allegedly stolen **Carhartt** data on a dark web site after failing to secure a **$3.3 million ransom**. The exposed material was described as more than **50GB** of customer, employee, and corporate data. Available material did not include public confirmation from Carhartt at the time covered here.
Analysis of the leaked archive tied the breach to Carhartt's **Databricks analytics platform**, and Have I Been Pwned said the exposure affects **more than 12.9 million Carhartt accounts**. The leaked data includes unique email addresses, names, phone numbers, and physical addresses. The same analysis found **over 15,000 employees** with **@carhartt.com** email addresses in the leaked database.
The sequence points to a data-theft extortion event that escalated into public leak exposure once ransom pressure failed. That public release changes the risk profile from a private extortion claim to broad follow-on fraud, phishing, and social engineering risk for customers and employees whose contact details appear in the archive. Available evidence does not establish the full intrusion path beyond the Databricks linkage or what additional data elements, if any, were exposed outside the published archive.
Signals
Impact signals
Affected impact
CVEs/products
Geographic context
Threat context
Data exposure
Threat actor context
1 listedMember happenings
Data Leak
Carhartt data leak after ShinyHunters dark web publication
Data Type
Corporate Secrets
Data Type
Customer Records
Data Status
Fully Leaked
Data Leak
Carhartt data leak after ShinyHunters dark web publication
Data Type
Corporate Secrets
Data Type
Customer Records
Data Status
Fully Leaked