A closer look at leaked Carhartt customer data shows cybercriminals padded the breach with millions of fabricated records to inflate its scale.

Workwear and fashion retailer Carhartt was hit by a data breach claimed by the hacking group ShinyHunters, which said it released 50 gigabytes of the company’s data on August 13. The group made the disclosure after what it described as a negotiation with Carhartt that followed an initial extortion demand of $3.3 million.
The leaked dataset included names, email addresses, phone numbers and physical addresses. Carhartt has not issued a public comment on the breach.
Security researcher Troy Hunt, who runs the breach-notification site Have I Been Pwned, later examined the leaked data before adding it to his platform and found that the incident was roughly half as extensive as ShinyHunters had claimed, affecting approximately 12.9 million individuals rather than the larger figure the group cited, according to information published by The Register.
Hunt’s review determined that the dataset had been padded with millions of lines of synthetic data, artificially inflating the apparent number of victims. He used an open-source email extraction tool that initially pulled nearly 25 million addresses from the dump, then applied an artificial intelligence tool, OpenClaw, to scan the material for irregularities.
The analysis flagged large numbers of email addresses using .edu and .org domains paired with randomized strings, a pattern consistent with synthetic data generation. It also found customer records tied to countries such as Benin and Montenegro that are not significant markets for the retailer, along with an unusually high concentration of birth dates from the early 1900s.
After removing the fabricated entries, the estimated number of genuine individuals fell from 24.8 million to 13.6 million. Hunt then eliminated additional questionable records, including duplicate Microsoft 365 addresses and accounts marked for deactivation, arriving at a final count of 12,933,413 accounts believed to be authentic. Have I Been Pwned’s platform notes that 83 percent of those accounts had already appeared in previous breaches.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543