ShinyHunters Claims It Will Leak 50GB of Carhartt...

ShinyHunters allegedly breached Carhartt and threatened to leak 50GB of employee, customer, and loyalty data, though Carhartt has not confirmed it.

Event Overview

The hacker group ShinyHunters claimed last week that it had breached the U.S. apparel brand Carhartt and obtained about 50GB of compressed data, including customer and employee information, customer loyalty program data, and other internal company materials. Reports said the group had initially demanded US$3.3 million, later lowered the price, but negotiations still failed; it then posted a download link on the dark web and threatened to release the files. Carhartt has not confirmed the claim yet.Source

From data-breach collection websites, this incident appears to involve more than 4 million lines of records; if the leaked material is genuine, the impact would not be limited to a single table, but could instead involve a composite dataset exported across departments and systems. Because the original description mentions personal data, loyalty program data, and company information, this suggests the attacker may have obtained not just a static list, but also related information that could be used later for impersonation, phishing, and social engineering.Source

Technical Analysis

What makes this type of incident notable is not just the data volume, but the mix of data types. When customer data, employee data, loyalty program data, and internal information are all included in the same leaked set, attackers can cross-reference fields from different sources and improve the success rate of identity theft and targeted phishing. For defenders, this means that if databases, CRM systems, HR systems, and membership systems lack least-privilege access and clear segmentation, the risk will be amplified after an incident.Source

The 50GB compressed file claimed by ShinyHunters also suggests the leaked data may have been packaged and centrally organized for easier distribution on the dark web or for resale. This is often not just about “showing results,” but may also be used to pressure the victim into accepting the threat of public release after negotiations collapse. From a defense perspective, the real risk is not only the initial breach; once data has been fully exfiltrated, its further spread, resale, and reuse are almost impossible to reverse.Source

It is worth noting that Carhartt has not confirmed the incident, so the claim should currently be treated as unverified intelligence. For security teams, unverified does not mean harmless, because dark web disclosure pages, download links, and extortion narratives can still trigger customer concern, internal reviews, and external regulatory attention; at the same time, attackers may use such “leak claims” to launch follow-up phishing scams.Source

Impact Scope

If the leaked material is real, the most directly affected parties are customers and employees. Customers may face personal data exposure, phishing emails, account takeover, and fake customer-support scams; employees may see their HR, contact, and internal identity information exposed, increasing the success rate of targeted attacks. If loyalty program data is also included, attackers could further exploit membership status, transaction patterns, or reward information to create more credible fraud scenarios.Source

For the company itself, the impact is not limited to data-protection obligations; it also includes brand trust, customer complaint pressure, compliance investigations, and operational continuity. Carhartt is a privately held U.S. apparel company founded in 1889, with global revenue of about US$1 billion; if large volumes of customer and employee data are publicly exposed, notification, forensic work, remediation, and communication costs will inevitably rise. Even if the authenticity of the data remains unverified, the victim should still assume that sensitive information may have leaked and manage the risk accordingly.Source

Protection Recommendations

First, immediately inventory high-risk data domains similar to Carhartt’s, especially data flows between CRM, HR, membership, and loyalty systems, and confirm whether overly centralized exports or shared credentials exist. Second, strengthen external contact and customer-service workflows to prevent attackers from using leaked data for impersonation notices, refund scams, or fake event messages. Third, enable multi-factor authentication for all accounts that can access sensitive data, and check for abnormal logins, batch exports, and large-scale query behavior.Source

Fourth, establish a verification process for breach intelligence by cross-checking dark web claims, download links, and external reports to avoid over-disclosure or misclassification before confirmation. Fifth, if employee and membership data are truly stored together internally, prioritize data classification, field masking, segmented storage, and export approvals to reduce lateral spread from a single intrusion event.Source

5-Step Remediation Checklist

  1. Conduct a full inventory of data flows across customer, employee, loyalty program, and internal systems to identify points where sensitive data is centrally exported.
  2. Immediately review accounts with data access, force multi-factor authentication, and remove unnecessary permissions.
  3. Audit large queries, batch exports, abnormal downloads, and cross-system access logs, and preserve forensic evidence.
  4. Prepare external notification and customer-service response scripts to prevent leaked data from being used in phishing, impersonation, and social engineering.
  5. Implement data classification, least privilege, field masking, and export approvals to reduce the risk of future leaks.

References

  • iThome: ShinyHunters Claims It Will Leak 50GB of Carhartt Employee and Customer Data

More cybersecurity news