Ransomware attack reportedly exposes Carhartt data
A well-known online extortion group reportedly published personal information of Carhartt employees and customers following a cyberattack.
The ransomware gang ShinyHunters posted a link on a site it operates on the dark web to what it said was 50 GB of personal data relating to customers and workers at Carhartt on Thursday, Aug. 13. The data included information such as names, phone numbers, email and physical addresses of individuals stored in compromised Carhartt databases.
According to Cybernews, ShinyHunters did not provide any online proof that the information it posted the link to was associated with real people or with an actual cyberattack on Carhartt. However, the cybersecurity blog Have I Been Pwned analyzed the data posted by ShinyHunters and determined it contained information connected to 12.9 million real individuals, as well as millions of additional synthetic records which did not correlate to any actual people.
On its dark web site, ShinyHunters said that although Carhartt rejected its initial demand for $3.3 million, it would have negotiated for a lower monetary amount but Carhartt was “incompetent” in its negotiations and missed the opportunity to save a “good chunk of money” on a potential ransom to retrieve the data and not have it publicly exposed.
ShinyHunters also posted an excerpt from a message it said Carhartt sent to terminate ransom negotiations.
"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," the alleged excerpt stated. "We appreciate your patience throughout this process.”
In an emailed statement to Chain Store Age, Paul Bischoff, consumer privacy advocate at tech research firm Comparitech, said ShinyHunters claims are “usually credible,” so anyone who potentially had information exposed should “take the risks seriously.”
“Based on what Have I Been Pwned found, the breached customer data was mostly limited to contact information,” said Bischoff in the statement. “That doesn't pose a direct threat to customer's bank accounts or identities, but it could be used to target them with phishing messages. Employees could have more sensitive data risk, but we'll probably have to wait a few weeks for Carhartt to finish its investigation before we learn exactly what data was compromised."
Carhartt has not responded to a Cybernews request for comment as of Aug. 31, 2026. Global ransomware events reached a new high in the first half of 2026, with retailers experiencing a significant increase, according to a recent study from Comparitech.
[READ MORE: Retailers see sharp uptick in ransomware attacks]
During the first half of 2026, an average of 23 ransomware attacks per day occurred around the world. In the first six months of 2026, the Comparitech daily ransomware tracker logged 4,217 ransomware attacks. This is an 11% increase on the second half of 2025 (3,809). This total included 326 attacks recorded against retailers (28 confirmed), up 28% from 254 in the second half of 2025.
