ShinyHunters Dumps 12.9 Million Carhartt Accounts and Regular Shoppers Pay the Price

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt earlier this month. Breach notification service Have I Been Pwned put the count at 12.9 million accounts.

If you wear their jackets to the job site, this one is about you. Carhartt is not a Silicon Valley app. It is work clothes. The people in this dump are contractors, farmers, mill hands, and anybody who needed gear that would survive a Maine winter.

What Have I Been Pwned flagged in the Carhartt leak

Have I Been Pwned is the service regular people use to see if an email address showed up in a known breach. They are the ones confirming this dump and attaching the 12.9 million figure to it.

ShinyHunters is an extortion group. They steal large piles of customer records and publish them. That is what happened here. The data came from Carhartt, a major clothing retailer in the United States, and it is now out.

Public reporting calls it sensitive data tied to those 12.9 million accounts. That is already enough. A retailer account is a live list of real customers at a brand people trust.

Why a workwear brand this size is a problem

When 12.9 million shopper accounts go public, scammers get a fresh list. The next move is almost always the same. You get a fake Carhartt email about a password reset, a package problem, or a refund. They already know you shop there, so the bait looks right.

That is how regular people lose email and bank logins. Not because they are dumb. Because the company lost the list, and somebody used it to sound official.

It pisses me off every time. You paid for a coat. You did not sign up to have your account tossed on the internet because a crew named ShinyHunters wanted a payday.

What to do if you have a Carhartt account

Do the boring things that actually work. Do them this week, not after the phishing mail lands.

  • Check Have I Been Pwned with the email you use at Carhartt and any other address that might be on the account.
  • Change the password on your Carhartt account. Make it unique. If that password ever lived anywhere else, change those logins too.
  • Turn on two-factor authentication anywhere Carhartt or your email provider offers it.
  • Treat every Carhartt email, text, and order problem message as hostile until you log in by typing the real site yourself.
  • Watch for new account signups that use your email. Scammers love a known customer list.

You cannot pull this data back. You can stop the second hit, which is someone walking into your email or your bank with a story that sounds like it came from the store you already trust.

Do not wait on a company letter. The data is already published. Lock the doors on your own accounts before somebody else tries the handle.

Primary Source: https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.