BREACH2026-08-30T08:03:15.707324+00:005 min read

Carhartt Said No to a $3.3M Ransom. Now 12.9 Million Shoppers' Data Is Online

ShinyHunters hackers leaked names, emails, and home addresses of 12.9M Carhartt customers after the brand refused to pay a $3.3M ransom. Here's what to do.

Carhartt Said No to a $3.3M Ransom. Now 12.9 Million Shoppers' Data Is Online

The Jacket Brand That Wouldn't Blink, And What It Cost You

Carhartt built its reputation on gear that doesn't quit. Turns out its security team has that same stubbornness. When hackers demanded $3.3 million to keep stolen customer data off the internet, Carhartt said no.

That decision is arguably the right one on principle. But 12.9 million customers are now living with the fallout.


How Did This Happen?

Carhartt hasn't said publicly how attackers got in. That's a frustrating non-answer, but it's a common one. What we know is this: sometime before August 2026, a hacker group called ShinyHunters made it inside Carhartt's systems and walked out with roughly 50 gigabytes of customer data.

ShinyHunters is not a mystery outfit. They're a prolific group with a long history of high-profile breaches, TicketMaster, Santander, AT&T. Their playbook is consistent: breach a company, steal data, negotiate a ransom, and if talks fail, post everything publicly.

The "negotiation" phase is worth understanding. Hackers like these don't always want a public scene. A payout is clean and quiet. When Carhartt's negotiator told the group they had "decided not to move forward," ShinyHunters did exactly what they threatened. On August 13, 2026, they posted the Carhartt dataset on their dark-web leak site for anyone to download.


What's Actually in the Leak?

ShinyHunters claimed 25 million records. Roughly half turned out to be synthetic, fake entries, likely padding designed to inflate the perceived value of the data during negotiations.

Have I Been Pwned, the breach notification service run by security researcher Troy Hunt, verified 12.9 million real accounts in the dump. That's still an enormous number.

Here's what was exposed:

  • Email addresses
  • Full names
  • Phone numbers
  • Home and mailing addresses

No passwords. No payment card numbers. No Social Security numbers confirmed in the leak.

That last paragraph shouldn't make you relax too much.

Your home address combined with your full name, phone number, and email is more than enough for a criminal to do serious damage. It's the raw material for targeted phishing, SIM swap attacks, package theft, and in worst cases, physical harm. Your address tells someone where you live. That's not abstract.


What Should You Do Right Now?

You can't un-expose your data. But you can make it significantly harder to exploit.

1. Check if your account was in the breach. Go to haveibeenpwned.com and enter your email address. It's free and takes ten seconds. If your address shows up in the Carhartt breach, treat the steps below as urgent, not optional.

2. Watch for phishing with unusual precision. Criminals who buy or download this data will use your name and address to craft convincing emails. A message that opens with your full name and references your street address feels legitimate. It isn't. No company will ask for your password or payment info via email. Slow down before clicking anything.

3. Lock down your phone number. Your carrier offers a free PIN or passphrase that blocks SIM swaps, the attack where someone calls your carrier, pretends to be you, and redirects your number to their phone. Call your carrier today and set one up. This is a five-minute task most people never do.

4. Use a password manager and turn on 2FA everywhere. Even though passwords weren't in this leak, people reuse passwords. If your email was exposed here and you use the same password elsewhere, change it now. A password manager makes unique passwords effortless. Two-factor authentication means that even if someone has your password, they still can't get in.

5. Consider a credit freeze. Home addresses and names are sometimes the starting point for identity theft and fraudulent account openings. A credit freeze at all three major bureaus, Equifax, Experian, TransUnion, blocks anyone from opening new credit in your name. It's free. It doesn't hurt your credit score. You can lift it temporarily when you need to apply for something.

6. Look into data removal services. Your home address is now more widely distributed than it was before. Data broker removal services like Optery, DeleteMe, or Privacy Bee can scrub your information from the public databases that aggregate and sell personal records. It doesn't fix the breach, but it reduces your overall exposure surface.


The Real Price of Holding the Line

Here's the uncomfortable truth about Carhartt's decision.

Refusing to pay ransoms is the right policy at a societal level. Paying ransoms funds the next attack and the one after that. It guarantees that breaching companies is profitable. Security experts, law enforcement agencies, and governments broadly agree: don't pay.

But that calculus is made by executives and boards. The cost lands on customers.

You didn't decide not to negotiate. You didn't know your data was being used as leverage. You just bought a jacket.

This isn't an argument for paying hackers. It's an argument for something harder to legislate: companies owe their customers honest communication fast, not boilerplate "we take security seriously" statements weeks later. They owe investment in security before an incident, not PR management after one. And they owe transparency about how the breach happened so other companies can learn from it.

Carhartt made a principled stand. Now 12.9 million people need to clean up a mess that wasn't theirs to make.


Do This Now

  • Check haveibeenpwned.com for your email address
  • Set a SIM swap PIN with your mobile carrier
  • Turn on two-factor authentication for email and any shopping accounts
  • Freeze your credit at all three bureaus (free at equifax.com, experian.com, transunion.com)
  • Be suspicious of any email, call, or text that uses your full name and address together

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read

Stay invisible. Follow @hack_decoded