ShellCodeX
Tools โ€ข Events โ€ข News โ€ข Insights
LiveThreat
Radar
ShellCodeX Breach Report

Carhartt Data Breach

carhartt.com
Major exposure
Verified breach
Accounts exposed 12,933,413
Breach date 13 Aug 2026
Added to tracker 25 Aug 2026
Data classes 4

What happened

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.

ShellCodeX exposure analysis

Moderate ยท 40/100. Moderate residual exposure based on 12,933,413 affected accounts and 4 reported data types.

  • Email exposure makes targeted phishing against affected users more credible.

Exposed data

Email addresses Names Phone numbers Physical addresses

Recommended actions

  • Watch for targeted phishing emails referencing Carhartt โ€” attackers weaponise breach data quickly.
  • Stay alert for smishing (SMS phishing) and SIM-swap attempts using your phone number.
  • Exposed identity data raises identity-theft risk โ€” consider credit monitoring or a credit freeze.
  • Check whether your email address appears in this breach on haveibeenpwned.com.
Am I affected? Check whether your email address appears in this breach.
Check on HIBP