Carhartt Data Breach: 12.9 Million Real Accounts Exposed — But the Original Number Was Massively Inflated
- The Mess: The ShinyHunters leak involving Carhartt initially appeared to contain almost 25 million unique email addresses. A detailed analysis by Have I Been Pwned founder Troy Hunt found that millions of records were synthetic, duplicate or test data. After filtering, 12,933,413 accounts were considered genuine and were loaded into HIBP. The exposed information includes names, email addresses, phone numbers and physical addresses.
This breach has an unusual twist.
The headline originally suggested something close to 25 million victims.
That wasn’t true.
But that doesn’t mean the breach is small.
12.9 million genuine accounts is still enormous.
And the incident provides an excellent example of why raw numbers published by ransomware and extortion groups shouldn’t automatically be treated as fact.
ShinyHunters Claimed a 50 GB Dump
ShinyHunters claimed that it had stolen approximately 50 GB of Carhartt data and demanded around $3.3 million from the company.
After negotiations failed, the group published the data.
The alleged dataset contained customer and employee information along with other corporate data.
At first glance, the numbers looked enormous.
HIBP’s initial extraction process found almost 25 million unique email addresses.
That would have made this one of the largest recent retail breaches.
But something didn’t look right.
The Data Was Full of Fake Customers
Troy Hunt and his team began examining the dataset.
The first major clue was the unusual distribution of email domains.
There were huge numbers of addresses associated with domains that didn’t make much sense for Carhartt’s customer base.
There were also suspicious geographic patterns.
For example, the dataset contained unexpectedly large numbers of supposed customers from countries that aren’t major Carhartt markets.
And then there were the birthdays.
A suspicious number of supposed customers had birth dates dating back to the early 1900s.
That isn’t impossible.
But when millions of records start looking statistically strange, investigators need to ask why.
Then They Found TPC-DS
This is where the story becomes really interesting.
Researchers identified data consistent with TPC-DS, a synthetic dataset used for benchmarking and testing retail analytics systems.
In other words:
some of the supposedly stolen customer records weren’t real customers at all.
They were synthetic test data.
That explains why the original dump was so large.
Someone had apparently mixed legitimate information with huge amounts of artificial data.
And that made the breach look considerably worse than it actually was.
24.8 Million Became 12.9 Million
The numbers changed dramatically during the investigation.
The initial extraction found approximately:
24.9 million unique addresses.
After filtering obvious synthetic and non-human records, the number dropped substantially.
Further analysis removed:
- duplicate Microsoft 365 addresses;
- test addresses;
- disposable addresses;
- deactivated addresses;
- synthetic records;
- other obvious artifacts.
The final number submitted to Have I Been Pwned was:
12,933,413 genuine accounts.
That’s roughly half the original headline figure.
And this is exactly why breach statistics need independent verification.
What Was Actually Exposed?
The confirmed dataset contains personal information including:
names.
email addresses.
phone numbers.
physical addresses.
That information can be extremely useful to attackers.
A stolen email address by itself isn’t necessarily catastrophic.
Combine it with:
name + phone number + physical address
and you’ve got a much more valuable phishing and social-engineering dataset.
Attackers can construct messages that look significantly more convincing.
For example:
“We noticed an issue with your recent Carhartt order…”
That doesn’t require a password.
The attacker simply needs enough information to make the victim believe the message is legitimate.
83% Had Already Appeared in Other Breaches
There’s another fascinating statistic.
According to HIBP, around 83% of the confirmed email addresses had already appeared in previous breaches.
That doesn’t make the Carhartt breach harmless.
But it does demonstrate how fragmented personal-data exposure has become.
Attackers don’t necessarily need a brand-new password database.
They can combine information from multiple incidents.
One breach provides:
email + name.
Another provides:
phone number.
Another provides:
address.
And another might provide:
password hashes.
Data aggregation can therefore become more dangerous than any single breach.
This Is Also a Lesson About Cybercrime Propaganda
There is another side to this story that I think is particularly relevant.
Cybercriminals have an incentive to make their breaches look as large as possible.
A bigger number creates:
more media attention.
more pressure on the victim.
more fear.
more leverage during negotiations.
That doesn’t necessarily mean every breach claim is fake.
Far from it.
But it means the initial claim should be treated as:
an allegation.
Not a verified statistic.
The Carhartt case is a perfect demonstration.
The original dataset was huge.
The final verified count was approximately half that size.
And even that final number required substantial forensic filtering.
The Fix
For Carhartt customers, the biggest immediate risk is likely phishing and social engineering.
If your information appears in the breach:
- be suspicious of Carhartt-themed emails;
- don’t click unexpected account links;
- don’t provide verification codes;
- don’t trust phone calls simply because the caller knows your name;
- use unique passwords;
- enable MFA where available;
- monitor accounts for suspicious activity.
For organizations, the lesson is different.
Know what your data warehouse actually contains.
If production customer information is mixed together with massive quantities of synthetic test data, an incident becomes much harder to investigate.
And organizations should know which systems contain:
real customer data.
test data.
historical data.
duplicates.
inactive accounts.
Without that classification, even the company itself may struggle to determine what was stolen.
Bugstoday Opinion
This is one of those breaches where the investigation is almost more interesting than the attack.
The original story was:
“Hackers stole almost 25 million customer records.”
The much more accurate story is:
“Hackers published a huge dataset containing millions of synthetic records, but approximately 12.9 million genuine accounts were ultimately identified.”
That’s still a major breach.
But it’s also a lesson in cybersecurity journalism.
Don’t blindly repeat the number supplied by the attacker.
Verify it.
Analyze the data.
Look for duplicates.
Look for synthetic records.
Look for test data.
Look for impossible patterns.
Because otherwise, the attacker controls not only the stolen data — they control the headline.
Bugstoday verdict: 12.9 million genuine Carhartt accounts is bad enough. But the Carhartt case demonstrates something equally important: when a ransomware group announces a huge breach, the first number you see may be part of the extortion strategy rather than the actual victim count.




