GoFirm
Back to Blog
Case Studies·3 min read

Carhartt refused to pay $3.3 million. It still owes an answer on how ShinyHunters got in.

By GoFirm

Carhartt, the American workwear and streetwear manufacturer founded in 1889 and now employing more than 3,000 people across the United States and Europe, has not disclosed a breach of its own systems. It has not needed to. On 13 August 2026 the extortion group ShinyHunters claimed to have stolen customer, employee and corporate data from the company's Databricks environment, the cloud analytics platform Carhartt uses to run its customer data warehouse. The claim arrived with a number attached and a deadline for payment.

ShinyHunters has spent 2026 running a consistent playbook against dozens of organisations: obtain a foothold through a vished credential reset, a hijacked OAuth token, or a compromised third-party integration, then use that trusted access to pull bulk data out of whatever platform sits behind it. The group's confirmed 2026 campaigns have used this method against Salesforce, Snowflake and Gainsight-connected environments at targets including Google, Cisco, the European Commission and Match Group. Carhartt has not confirmed its own entry point, but security researcher Troy Hunt's forensic review of the leaked archive traced the data specifically to Carhartt's Databricks instance, and the group's pattern elsewhere makes an approved credential reset or token grant, rather than a technical exploit, the far more likely starting point.

The negotiation collapsed quickly. According to chat logs ShinyHunters shared publicly, Carhartt's negotiator refused to move past the group's opening position, and the group described the negotiator as "unskilled and incompetent" before dumping the archive on 13 August rather than continue talking. Hunt then spent days separating fact from padding: the raw dataset contained roughly 25 million email addresses, but a large share used implausible domains and demographic patterns consistent with synthetic filler data designed to inflate the claimed scale. After removing it, Hunt confirmed 12,933,413 real accounts, containing names, email addresses, phone numbers and physical addresses, with the large majority already present in earlier breaches.

The number that matters here is not the $3.3 million Carhartt declined to pay. It is the fact that ShinyHunters has run this same model, credential or token compromise followed by a bulk export, against well over a hundred organisations in 2026 through its Salesforce, Salesloft Drift and Oracle PeopleSoft campaigns alone. The entry point changes each time. The mechanism does not: someone, or something, with legitimate access approves a request it should not have, and a platform that was never built to ask twice complies.

Carhartt is not a company that skimped on security. A retailer with thousands of employees and a dedicated analytics warehouse for customer data typically runs enterprise identity and access management as a baseline. What it did not have, and what none of ShinyHunters' 2026 victims have had, is a control that stops a bulk export of tens of millions of records the moment it is requested and asks the one question that actually matters: is the person requesting this really who they claim to be, on their own device, right now.

A bulk export from a data warehouse holding millions of customer records is a high-impact action, regardless of whether it is triggered by a stolen OAuth token, a vished credential reset, or a compromised admin session. GoFirm treats it as one. Before that export can execute, a confirmation request goes to the named authority Carhartt designates over that Databricks environment, sent to their registered device out of band from whatever channel the request came through, requiring a biometric confirmation before the export runs.

A ShinyHunters operator, however convincing on the phone and however valid the credential or token in hand, cannot produce that confirmation on someone else's registered device. The execution boundary holds regardless of how the access in front of it was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References


1. Gatlan, S. 2026. Carhartt data breach exposes information of 12.9 million accounts. BleepingComputer, 27 August 2026.
2. Jones, C. 2026. Carhartt data breach affects 12.9M, half of what ShinyHunters claimed. The Register, 26 August 2026.
3. Hunt, T. 2026. A cautionary tale about data breach claims, verification and Carhartt. Troy Hunt, 26 August 2026.

Share this article