TechNewsReel
Live

Carhartt Data Breach Exposes 12.9 Million Customer Records

The durable workwear giant faces a massive security failure after the cybercrime group ShinyHunters leaked millions of user accounts.

TechNewsReel Newsroom · August 27, 2026

Carhartt has suffered a massive data breach that exposed the personal information of approximately 12.9 million customers. The leak represents a significant security failure for the global apparel brand and puts millions of users at risk of targeted cyberattacks.

According to security reports, exactly 12,933,413 accounts were compromised in the incident. The breach has been linked to ShinyHunters, a notorious cybercrime group known for targeting high-profile corporate databases. The exposed data includes a wide array of personally identifiable information (PII), specifically customer names, email addresses, phone numbers, and physical addresses.

The Context of the Leak

Carhartt is globally recognized for its durable workwear, maintaining a massive customer base that spans industrial workers and fashion consumers alike. In the current cybersecurity landscape, the theft of PII is a primary objective for threat actors. By harvesting names, emails, and phone numbers, attackers can build highly convincing profiles of victims to facilitate subsequent crimes. This specific breach follows a pattern of large-scale retail leaks where database vulnerabilities are exploited to scrape millions of records in a single event.

Why This Matters

For the millions of affected users, the immediate risk is a surge in sophisticated phishing and smishing campaigns. Because the leaked data includes both email and phone numbers, attackers can coordinate multi-channel attacks, pretending to be Carhartt support or delivery services to trick users into revealing passwords or financial details.

From a corporate perspective, a breach of this magnitude threatens customer trust and brand loyalty. The scale of the exposure necessitates an extensive remediation effort, including widespread customer notifications and potential regulatory scrutiny over how the data was protected. For a brand built on the concept of "durability" and reliability, a failure in digital infrastructure creates a stark contrast to its physical product reputation.

What's Next

As the industry monitors the fallout, the primary focus remains on whether any more sensitive data, such as hashed passwords or payment information, was included in the ShinyHunters leak. While the confirmed data focuses on contact information, the full extent of the database's exposure is often revealed in stages as the stolen data is traded or leaked on dark web forums. Users are encouraged to remain vigilant against unsolicited communications and to update their security credentials across any platforms where they may have reused the same email or phone number.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.