Desk live·
ForensicPost
Breaches/Verification/File 26-0826

Carhartt Leak Verifies at 12.9 Million — Half the Claim, Padded With Synthetic Records

ShinyHunters dumped 50GB after a $3.3 million demand failed, claiming roughly twice the accounts Have I Been Pwned could verify. The rest was fabricated filler injected into real data — a new problem for anyone counting.

Constructed geometry · not a chart of case data
JurisdictionUSADearbornthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCarhartt
ActorShinyHunters
S. Rosler11 min readConfidence: high3 sources reviewed

On 13 August 2026 ShinyHunters published what it described as 50GB of Carhartt customer data, after the clothing company declined to meet a $3.3 million demand. On 26 August, Have I Been Pwned added the breach at 12.9 million unique accounts — email addresses, names, phone numbers and physical addresses — roughly half what the group had claimed. Troy Hunt’s analysis found the published set injected with millions of lines of synthetic data, padding the apparent total, and linked the underlying theft to the compromise of Carhartt’s Databricks analytics environment.

Padding Is New, And It Changes The Verification Job

The corpus has recorded inflated claims throughout — reach counted as theft, rows counted as people, 26-0425’s ten million against five and a half. Fabricating records and mixing them into genuine data is a different act. A claim can be discounted; a poisoned dataset has to be cleaned before it can even be counted, and every downstream consumer — notification lists, class definitions, breach databases — inherits the problem.

It also cuts against the attacker’s own interest in a way worth noting: a leak that fails verification once makes that group’s every future claim cheaper to doubt. Reputation is the asset these operations trade on, and this spends it.

The Analytics Platform, Again

The reported source is the company’s Databricks environment — customer data pooled for analysis, outside the transactional systems that usually get the security attention. The 2025 SaaS-platform wave filed at 25-0810 ran on the same structure: the copy of the data that exists for querying is the copy that leaves.

What 12.9 Million Contact Records Amount To

No payment data, no credentials, no identifiers that unlock accounts — by field list, among the mildest categories filed here. The realistic harm is phishing that quotes a real purchase to a real address, at a scale where even a small hit rate pays. The company’s customers absorb that; the negotiation that failed was never about them.

How we reported this

Compiled from Have I Been Pwned’s verification, Troy Hunt’s published analysis and contemporaneous reporting, listed below. The 12.9 million figure is the verified count; the larger figure and the 50GB volume are the attackers’ claims. The Databricks link is Hunt’s finding as reported. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Carhartt data breach affects 12.9M, half of what ShinyHunters claimedThe Register
  2. Carhartt data breach exposes information of 12.9 million accountsBleepingComputer
  3. Carhartt Data BreachHave I Been Pwned
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary