← All articles

ShinyHunters leaks Carhartt data, but half the records were synthetic test data

The extortion group ShinyHunters published data stolen from workwear maker Carhartt after the company refused a 3.3 million dollar ransom, but analysis showed the leak was smaller than it first appeared. The raw dump held nearly 25 million email addresses, yet breach-tracking service Have I Been Pwned found millions were synthetic records that matched no real people, leaving about 12.9 million genuine addresses along with names, phone numbers, and physical addresses. A researcher traced the data to Carhartt's customer analytics warehouse, contaminated with a standard retail benchmarking dataset used for testing. The detailed contact and identity profiles still create real risk of targeted phishing for those affected.

Check
Affected Carhartt customers should be alert to targeted phishing and scam calls using their real name, address, and phone number, and treat unexpected messages referencing recent orders with suspicion.
Affected
About 12.9 million Carhartt customers whose emails, names, phone numbers, and physical addresses were leaked; the detailed profiles support convincing phishing, even though millions of the leaked records were synthetic.
Fix
For defenders, verify breach claims before reacting since raw dumps can be inflated with synthetic data, and keep test and benchmark datasets out of production stores that hold real records.