The extortion group ShinyHunters has leaked sensitive data from nearly 13 million Carhartt accounts after the apparel giant refused to pay a $3.3 million ransom.
- ShinyHunters leaked data from 12.9 million Carhartt accounts on the dark web.
- The breach involves names, emails, phone numbers, and physical addresses.
- Carhartt refused to pay a $3.3 million ransom demand.
- The breach is linked to the compromise of the Databricks analytics platform.
The renowned American apparel giant Carhartt is facing a massive cybersecurity crisis. The notorious extortion group ShinyHunters has published sensitive information belonging to nearly 13 million accounts, following a failed ransom attempt. The group allegedly stole over 50GB of documents containing a vast array of customer, employee, and corporate data.
The Ransom Refusal
According to reports, the cybercriminals demanded a $3.3 million ransom to prevent the release of the stolen data. However, Carhartt's leadership decided not to engage in negotiations, a move that prompted the attackers to leak the archive on the dark web. This highlights the difficult dilemma companies face when dealing with high-profile extortion groups.
Why This Matters
BozokMedia analysis shows that this breach underscores a critical vulnerability in cloud-based data architectures. As organizations migrate sensitive business intelligence to platforms like Databricks, these centralized hubs become high-value targets for sophisticated threat actors like ShinyHunters.
Once attackers bypass initial defenses using valid credentials, traditional prevention mechanisms often fail to stop the exfiltration of massive data volumes.
Analysis by Troy Hunt, founder of Have I Been Pwned, suggests the breach originated from the compromise of Carhartt's Databricks analytics platform. The leaked data includes unique email addresses, names, phone numbers, and physical addresses. Furthermore, the breach also impacts internal operations, with over 15,000 @carhartt.com employee email addresses appearing in the leaked database.
Historical Background
Founded in 1889, Carhartt has grown from a small workwear manufacturer into a global powerhouse in both workwear and streetwear, employing over 3,000 people across the United States and Europe.
Frequently Asked Questions
1. What kind of data was stolen in the Carhartt breach?
The breach included customer names, emails, phone numbers, physical addresses, and employee credentials.
2. How can I protect myself if my data was leaked?
Change your passwords immediately, enable multi-factor authentication (MFA), and monitor your financial statements for suspicious activity.