ShellCodeX Breach Report
Carhartt Data Breach
carhartt.com
Verified breach
Accounts exposed
12,933,413
Breach date
13 Aug 2026
Added to tracker
25 Aug 2026
Data classes
4
What happened
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.
ShellCodeX exposure analysis
Moderate ยท 40/100. Moderate residual exposure based on 12,933,413 affected accounts and 4 reported data types.
- Email exposure makes targeted phishing against affected users more credible.
Exposed data
Email addresses
Names
Phone numbers
Physical addresses
Recommended actions
- Watch for targeted phishing emails referencing Carhartt โ attackers weaponise breach data quickly.
- Stay alert for smishing (SMS phishing) and SIM-swap attempts using your phone number.
- Exposed identity data raises identity-theft risk โ consider credit monitoring or a credit freeze.
- Check whether your email address appears in this breach on haveibeenpwned.com.
Am I affected?
Check whether your email address appears in this breach.
Check on HIBP