Clothing retailer Carhartt has been hit by a data breach exposing customer and employee records following unsuccessful ransom negotiations with cybercriminals.
The ShinyHunters group claimed responsibility for the breach on August 13th, stating that attackers obtained more than 50GB of files containing customer, employee, and corporate information. The compromise affected approximately 12.9 million accounts, according to reports.
Carhartt declined to pay the extortion demand. "After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," the company stated.
The leaked data included names, email addresses, phone numbers, and physical addresses. Security researcher Troy Hunt identified more than 15,000 records associated with Carhartt employee email addresses in the leaked database. Hunt determined the records most likely originated from Carhartt's Databricks analytics platform.
ShinyHunters posted the data to their leak site after talks broke down over a $3.3 million ransom demand. The group stated that the breach included customer metadata and internal corporate data.
Carhartt has not publicly confirmed the breach or commented on the extortion claims. The company operates approximately 60 US stores and employs roughly 3,000 people.
ShinyHunters has recently shifted its tactics from encryption-based attacks to data exfiltration through vishing and software-as-a-service platform breaches.


