Carhartt Said No to a $3.3M Ransom. Now 12.9 Million Shoppers' Data Is Online
ShinyHunters hackers leaked names, emails, and home addresses of 12.9M Carhartt customers after the brand refused to pay a $3.3M ransom. Here's what to do.
The Jacket Brand That Wouldn't Blink, And What It Cost You
Carhartt built its reputation on gear that doesn't quit. Turns out its security team has that same stubbornness. When hackers demanded $3.3 million to keep stolen customer data off the internet, Carhartt said no.
That decision is arguably the right one on principle. But 12.9 million customers are now living with the fallout.
How Did This Happen?
Carhartt hasn't said publicly how attackers got in. That's a frustrating non-answer, but it's a common one. What we know is this: sometime before August 2026, a hacker group called ShinyHunters made it inside Carhartt's systems and walked out with roughly 50 gigabytes of customer data.
ShinyHunters is not a mystery outfit. They're a prolific group with a long history of high-profile breaches, TicketMaster, Santander, AT&T. Their playbook is consistent: breach a company, steal data, negotiate a ransom, and if talks fail, post everything publicly.
The "negotiation" phase is worth understanding. Hackers like these don't always want a public scene. A payout is clean and quiet. When Carhartt's negotiator told the group they had "decided not to move forward," ShinyHunters did exactly what they threatened. On August 13, 2026, they posted the Carhartt dataset on their dark-web leak site for anyone to download.
What's Actually in the Leak?
ShinyHunters claimed 25 million records. Roughly half turned out to be synthetic, fake entries, likely padding designed to inflate the perceived value of the data during negotiations.
Have I Been Pwned, the breach notification service run by security researcher Troy Hunt, verified 12.9 million real accounts in the dump. That's still an enormous number.
Here's what was exposed:
- Email addresses
- Full names
- Phone numbers
- Home and mailing addresses
No passwords. No payment card numbers. No Social Security numbers confirmed in the leak.
That last paragraph shouldn't make you relax too much.
Your home address combined with your full name, phone number, and email is more than enough for a criminal to do serious damage. It's the raw material for targeted phishing, SIM swap attacks, package theft, and in worst cases, physical harm. Your address tells someone where you live. That's not abstract.
What Should You Do Right Now?
You can't un-expose your data. But you can make it significantly harder to exploit.
1. Check if your account was in the breach. Go to haveibeenpwned.com and enter your email address. It's free and takes ten seconds. If your address shows up in the Carhartt breach, treat the steps below as urgent, not optional.
2. Watch for phishing with unusual precision. Criminals who buy or download this data will use your name and address to craft convincing emails. A message that opens with your full name and references your street address feels legitimate. It isn't. No company will ask for your password or payment info via email. Slow down before clicking anything.
3. Lock down your phone number. Your carrier offers a free PIN or passphrase that blocks SIM swaps, the attack where someone calls your carrier, pretends to be you, and redirects your number to their phone. Call your carrier today and set one up. This is a five-minute task most people never do.
4. Use a password manager and turn on 2FA everywhere. Even though passwords weren't in this leak, people reuse passwords. If your email was exposed here and you use the same password elsewhere, change it now. A password manager makes unique passwords effortless. Two-factor authentication means that even if someone has your password, they still can't get in.
5. Consider a credit freeze. Home addresses and names are sometimes the starting point for identity theft and fraudulent account openings. A credit freeze at all three major bureaus, Equifax, Experian, TransUnion, blocks anyone from opening new credit in your name. It's free. It doesn't hurt your credit score. You can lift it temporarily when you need to apply for something.
6. Look into data removal services. Your home address is now more widely distributed than it was before. Data broker removal services like Optery, DeleteMe, or Privacy Bee can scrub your information from the public databases that aggregate and sell personal records. It doesn't fix the breach, but it reduces your overall exposure surface.
The Real Price of Holding the Line
Here's the uncomfortable truth about Carhartt's decision.
Refusing to pay ransoms is the right policy at a societal level. Paying ransoms funds the next attack and the one after that. It guarantees that breaching companies is profitable. Security experts, law enforcement agencies, and governments broadly agree: don't pay.
But that calculus is made by executives and boards. The cost lands on customers.
You didn't decide not to negotiate. You didn't know your data was being used as leverage. You just bought a jacket.
This isn't an argument for paying hackers. It's an argument for something harder to legislate: companies owe their customers honest communication fast, not boilerplate "we take security seriously" statements weeks later. They owe investment in security before an incident, not PR management after one. And they owe transparency about how the breach happened so other companies can learn from it.
Carhartt made a principled stand. Now 12.9 million people need to clean up a mess that wasn't theirs to make.
Do This Now
- Check haveibeenpwned.com for your email address
- Set a SIM swap PIN with your mobile carrier
- Turn on two-factor authentication for email and any shopping accounts
- Freeze your credit at all three bureaus (free at equifax.com, experian.com, transunion.com)
- Be suspicious of any email, call, or text that uses your full name and address together
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded