Carhartt Data Breach: 12.9M Accounts Leaked (2026)
Data Breach · Investigation HOT

Carhartt Data Breach: 12.9 Million Accounts Leaked, but the Company Has Not Confirmed It

Published September 1, 2026

About 12.9 million people whose details sat in Carhartt customer records had their names, email addresses, phone numbers and postal addresses published online in August 2026 after the extortion group ShinyHunters leaked the data. Carhartt has not publicly confirmed the incident, no class action has been filed, and there is nothing to claim.

Carhartt customer data breach leaked by the ShinyHunters extortion group
Have I Been Pwned verified 12,933,413 Carhartt accounts on August 26, 2026, after removing millions of records identified as synthetic test data.
Not Confirmed by Carhartt · No Suit Filed · Nothing to Claim

This page describes a threat actor's public data leak and the independent analysis of it. Carhartt has not publicly confirmed the incident, so the scale figures and data-element lists below are attributed to the leaked archive and to security research, not to a company disclosure. No class action has been filed, there is no settlement, and there is nothing to claim. This page is informational and is not legal advice.

What Is This About?

The extortion group ShinyHunters published an archive of Carhartt data on August 13, 2026, saying it held more than 50 gigabytes of customer, employee and internal corporate records. The group said it had demanded $3.3 million and released the archive after the workwear company declined to pay.

Security researcher Troy Hunt, who runs the breach-notification service Have I Been Pwned, reviewed the archive and loaded 12,933,413 accounts into the service on August 26, 2026. The verified records contain email addresses, names, phone numbers and physical addresses. Hunt concluded the data most likely came from a customer analytics warehouse Carhartt ran on the Databricks platform.

Carhartt has not publicly confirmed the incident. The company has issued no statement, and reporters at several outlets said it did not respond to requests for comment. No class action had been filed over the breach as of September 1, 2026, and there is no settlement, no fund and no claim form. Several consumer law firms have announced that they are investigating potential claims, which is an early step and not a filed case.

Status Data leaked and verified · Not confirmed by Carhartt Attorney investigations announced · no complaint on file as of September 1, 2026
Scale 12,933,413 accounts The count Have I Been Pwned loaded after removing millions of synthetic records from the leaked archive
Reportedly Involved Names, email addresses, phone numbers, physical addresses From the leaked archive and security analysis, not a Carhartt disclosure · no Social Security or payment card numbers reported
Can I Claim? No — nothing to claim yet No lawsuit, no settlement, no claim form, no deadline

What the Leaked Data Contains

The records Have I Been Pwned verified carry four fields: email address, full name, phone number and a physical delivery or billing address. That combination is enough to write a convincing scam message, which is the practical risk here, but it is not the set of fields that leads directly to a drained bank account.

The archive also reached inside the company. Hunt found more than 15,000 addresses on the carhartt.com domain, meaning employee accounts were swept up alongside shoppers. ShinyHunters separately described taking customer metadata including loyalty information and internal corporate documents, though those claims come from the group and have not been independently confirmed.

No reporting has described Social Security numbers or payment card numbers in the leaked data. That absence matters for what comes next: data-breach cases involving financial identifiers tend to move faster and settle for more than cases built on contact details alone. For background on how these cases are structured, see our explainer on the data breach class action.

Why the Victim Count Fell From 24.9 Million to 12.9 Million

The headline number moved twice, and the reason is a useful warning about taking a hacker's arithmetic at face value.

Running the raw ShinyHunters dump through an extraction tool produced 24,876,077 unique email addresses. Hunt's review found the file had been padded with a large volume of records that did not describe real people, and the estimate of genuine individuals dropped to roughly 13.6 million. Removing duplicate Microsoft 365 addresses and accounts flagged for deactivation brought the final figure to the 12,933,413 that went into Have I Been Pwned.

The tell was demographic. Birth years in the questionable records ran from 1924 to 1992 in a perfectly flat line, roughly 1,050 to 1,194 people in every single year with no exceptions. Real customer bases do not look like that; they cluster, and they do not stop dead at two arbitrary years. A flat band inside fixed bounds is the signature of a random number generator. Other markers pointed the same way: email addresses pairing .edu and .org domains with randomized strings, and more supposed customers registered in Montenegro than in the United States, where Carhartt is headquartered and sells the overwhelming majority of its products.

Hunt attributed the padding to TPC-DS, a standard benchmark dataset the industry uses to simulate retail analytics at scale. Synthetic test data sitting in the same analytics environment as live customer records is ordinary practice, and whoever assembled the dump appears to have taken both. Whether the inflation was deliberate or a byproduct of grabbing everything in reach, the effect was the same: the initial claim described roughly twice as many victims as the data supports.

Carhartt Has Not Confirmed the Breach

A company founded in 1889 and still owned by the founder's descendants, Carhartt is private, based in Dearborn, Michigan, and reported around $1.8 billion in annual revenue. It has said nothing publicly about the incident.

That silence is the single most consequential fact for anyone trying to work out whether they are affected. Without a company disclosure there is no official count of affected people, no field-by-field list of what was taken, no stated date range, and no notification letters. Everything on this page traces back to the attacker's archive and to independent analysis of it.

Silence at this stage is not itself unusual. Forensic work on an intrusion of this size routinely takes weeks, and state breach-notification statutes generally start the clock on a company's determination of what happened rather than on a hacker's post. What the silence does mean is that customers should not wait for a letter before taking the ordinary precautions described below.

Who ShinyHunters Are

ShinyHunters is among the most active extortion crews operating today, and it has moved away from the encryption model people associate with ransomware. The group steals data and threatens to publish it, skipping the step of locking up a victim's systems.

Its access method is social engineering rather than software exploits. Operators call employees, impersonate internal help desks, and walk targets into handing over credentials or authorizing a malicious application, then pull data from whatever corporate platform those credentials unlock. Campaigns tied to the group have run through Salesforce, Snowflake and similar analytics and cloud services, which is why so many of its victims share a pattern: the customer data was concentrated in one platform, and one compromised account reached all of it.

OCA has covered several matters connected to the same crew and the same campaign pattern, including the DentaQuest data breach, the Canvas and Instructure data breach, and the Salesforce-linked breaches affecting Louis Vuitton and TransUnion.

Has a Lawsuit Been Filed?

No. As of September 1, 2026, no class action complaint over the Carhartt breach had appeared on the federal dockets, and no court has been asked to decide anything about the incident.

Several consumer law firms have published notices saying they are investigating potential data privacy claims. An investigation notice is a firm gathering potential plaintiffs and evaluating whether a case exists. It is not a filed complaint, it does not create a class, and it does not put money anywhere. Signing up with a firm is a decision for the reader; it is not a claim form and it produces no payment.

If a complaint is filed, the usual sequence follows: consolidation of overlapping cases, a motion to dismiss, and a fight over whether people whose contact details were exposed have suffered the kind of concrete injury federal courts require. That last question is where breaches without financial identifiers most often stall. Cases that clear it typically take years to reach a settlement, and settlements in contact-data breaches tend toward credit monitoring and modest cash tiers rather than large per-person payments.

The Website-Tracking Claims Are a Separate Matter

Notices circulating about Carhartt.com and online tracking technology describe a different legal theory and should not be confused with this breach. Those inquiries concern whether tracking tools embedded in the retailer's website captured and shared visitors' browsing activity without adequate consent, under federal and state wiretapping and privacy statutes. Carhartt has previously faced privacy litigation of that kind.

The distinction is practical, not technical. A tracking case turns on how a company's own website was configured and who it shared data with; a breach case turns on an outside intruder taking data the company held. They involve different conduct, different statutes, different proof and different classes. Someone who shopped on the site without ever creating an account might fall inside a tracking class and outside the breach class, and someone whose record sat in the analytics warehouse might be the reverse. Neither matter has produced a settlement, a fund or a claim form.

What Carhartt Customers Should Do Now

Start by finding out whether an address of yours is in the dataset. The Have I Been Pwned entry linked in the Sources below accepts an email address and reports whether it appears in this breach.

Treat unexpected messages that reference Carhartt with suspicion, whether they arrive by email, text or phone. The leaked combination of name, email, phone number and home address is precisely what makes a scam message look legitimate, and the crew behind this leak is known for using stolen contact data to run follow-on phone scams. A message that already knows your address is not thereby trustworthy. Do not click links in these messages; navigate to the retailer's site directly.

Beyond that, the standard steps apply. Monitor financial statements and credit reports for activity you do not recognize. A fraud alert or a credit freeze at the major credit bureaus is free to place and free to lift, and a freeze is the stronger of the two. If a Carhartt account shares a password with anything else, change it there and everywhere it was reused. Keep any notice you eventually receive, since a notification letter often becomes the proof of class membership if a claims process is ever created.

There is nothing to file for this incident right now, and any site inviting you to submit a claim for a Carhartt settlement today is not describing something that exists.

What Happens Next

Three things would change the picture. A Carhartt disclosure would replace the attacker-derived figures with an official count, a data-element list and a date range, and would usually arrive with notification letters and an offer of credit monitoring. A filed complaint would move this from investigation to litigation. A state attorney general filing would put the incident on a public breach registry with the company's own numbers attached.

None of those had happened as of September 1, 2026. This page will be updated as the record develops. For other active matters, see our data breach settlements and investigations hub.

This page is informational and is not legal advice.

Frequently Asked Questions

Is there a Carhartt data breach settlement or class action?

No. As of September 1, 2026, no class action had been filed over the breach, and there is no settlement, no fund and no claim form. Consumer law firms have announced investigations, which is an early step that does not create anything to file.

How many Carhartt accounts were exposed?

Have I Been Pwned loaded 12,933,413 accounts on August 26, 2026. The raw leaked archive initially yielded about 24.9 million unique email addresses; the lower figure is what remained after records identified as synthetic test data, duplicates and deactivated accounts were removed.

What information was in the leaked Carhartt data?

Email addresses, names, phone numbers and physical addresses. The archive also held more than 15,000 carhartt.com employee email addresses. No reporting has described Social Security numbers or payment card numbers.

Has Carhartt confirmed the data breach?

No. The company had issued no public statement as of September 1, 2026, and reporters at several outlets said it did not respond to requests for comment. Every figure on this page is attributed to the leaked archive and independent analysis rather than to a company disclosure.

Am I at risk of identity theft?

The verified fields are contact details rather than financial identifiers, so the immediate risk is targeted phishing and phone scams rather than direct account takeover. Monitoring statements and credit reports, and placing a free fraud alert or credit freeze, are reasonable precautions.

Sources

Have I Been Pwned — Carhartt breach entry (12,933,413 accounts)
Troy Hunt — "A Cautionary Tale About Data Breach Claims, Verification and Carhartt"
BleepingComputer — "Carhartt data breach exposes information of 12.9 million accounts"
The Register — "Carhartt data breach affects 12.9M, half of what ShinyHunters claimed"
TechRadar Pro — "Carhartt data breach exposed information from 12.9 million user accounts"
SC Media — "Carhartt data breach claims inflated by synthetic data, analysis finds"
Security Magazine — "12.9M Exposed by Carhartt Data Breach"


For more class actions keep scrolling below.
Status Data leaked and independently verified — not confirmed by Carhartt
Company Carhartt, Inc. (Dearborn, Michigan)
Date Leaked August 13, 2026
Verified Scale 12,933,413 accounts (Have I Been Pwned, August 26, 2026)
Attributed Source Carhartt customer analytics warehouse on Databricks (researcher assessment)
Claimed By ShinyHunters extortion group · $3.3M demand the group said Carhartt declined
Litigation None on file — attorney investigations announced only
Settlement None — nothing to claim

More on Retail & Platform Data Breaches