Carhartt hackers claim millions of customers exposed in 50GB data breach
ShinyHunters is now blaming Carhartt’s “incompetent” negotiator for failed extortion talks.

Image by Ken Wolter | Shutterstock
- ShinyHunters claims it stole 50GB of Carhartt data containing millions of customer records.
- The hackers say Carhartt rejected further negotiations after receiving a $3.3 million demand.
- The alleged haul includes customer and employee PII, loyalty data, and internal corporate information.
ShinyHunters says failed negotiations with its latest victim – Carhartt – forced the extortion gang to publish millions of stolen records from the workwear giant, including customer and employee data.
The prolific hacker group posted Carhartt on its dark leak site Thursday, along with a download link to an alleged 50GB of stolen data.
Notably, the gang did not attach any proof samples to the Carhartt entry to show off its handiwork.
$3.3 million demand goes nowhere
It's not clear exactly when the purported breach took place, but ShinyHunters is claiming Carhartt prematurely walked away from the negotiating table, after refusing to pay a $3.3 million ransom.
What’s more, the ransomware operators say they would have accepted the ransom deal at a lower price point if Carhartt’s negotiating team hadn’t been so "incompetent."
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Our demand for this Company was $3.3 million. The Company reached out. However, The Company did not try to negotiate,” ShinyHunters wrote, adding that Carhartt could have “ended up saving a good chunk of money” had it played ball.
“The Company hired a very unskilled and incompetent negotiator. If The Company hired competency to negotiate for them, this post would've never been published,”ShinyHunters claims.
ShinyHunters posted an excerpt of the final message it claims to have had recieved from the nearly 140-year-old clothing company.
"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions. We appreciate your patience throughout this process,” Carhartt’s alleged response stated, effectively ending the ransom negotiations.
Customer and employee data allegedly stolen
Of course, whether ShinyHunters is just talking smack remains to be seen, but if the stolen 50GB claim is legitimate, data belonging to millions of Carhartt customers is now at risk.
Headquartered in Dearborn, Michigan, the private, family-owned workwear clothing and apparel brand generates close to $1 billion in annual revenue across retail stores, wholesale distribution, and online sales.
According to its website, Carhartt owns and operates 70 U.S.-based brick-and-mortar stores, as well as another 100 retail locations in major cities across Europe, Asia, and North America under its lifestyle and streetwear spin-off, Carhartt WIP.
The company says it employs more than 3,000 associates worldwide.
ShinyHunters describes the contents of the massive cache as millions of records of customer and employee personally identifiable information (PII) and sensitive data.
The group also says it has customer metadata (royalty information) and other internal corporate data, leaving out specific details about what that data may be.
There are “millions of customers' data involved here. As we always say, these companies don't care," ShinyHunters posted.
Once stolen by hackers, exposed personal data could lead to future targeted phishing scams and identity theft.
Cybernews has reached out to Carhartt and is waiting for a response at the time of this report.
Check if your data has been leaked