The Carhartt data breach affects about 12.9 million people, roughly half of what the ShinyHunters group claimed, according to Troy Hunt’s analysis for Have I Been Pwned.
ShinyHunters dumped what it called 50GB of Carhartt data on August 13 after the retailer rejected a $3.3M extortion demand. Hunt’s email extractor pulled nearly 25 million addresses, but AI-assisted analysis flagged millions of them as synthetic.
The tell: improbable email domains such as .edu and .org addresses built from random strings, consistent with TPC-DS synthetic data generation. Fake accounts were scattered across countries like Benin and Montenegro, which recorded more “customers” than the US, where Carhartt is headquartered.
Hunt noted the padding does not mean the real records are safe. Genuine customer data is still in the dump, and affected individuals should check Have I Been Pwned and change passwords. The analysis also undercuts ShinyHunters’ claims about the scale of the haul, a pattern Hunt says is familiar from previous extortion cases.
Carhartt has not yet confirmed the breach publicly, and the retailer’s own negotiations with the group remain undisclosed.
