Security1 distinct publisher3 min readPublished
Have I Been Pwned traced the 50GB archive to Carhartt's Databricks analytics platform. The exposed fields are emails, names, phone numbers and addresses, which makes this a targeting corpus rather than a credential-stuffing list.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Databricks is the detail to carry forward. Troy Hunt traced the published archive to the compromise of Carhartt's Databricks analytics platform [5], and that puts this in the same class as the rest of ShinyHunters' year: more than a dozen Snowflake customers, hundreds of claimed Salesforce customers in the Aura and Salesloft Drift campaigns, and over 1.5 billion records claimed across those two [11], followed most recently by more than 100 organizations hit through an Oracle PeopleSoft zero-day [12]. The consistent target is the aggregated copy, the analytics tenant or the CRM, where one working credential returns the whole customer base in a single pull.
The refusal is the part operators can price. ShinyHunters asked $3.3 million and published after Carhartt declined [3]. Hunt counts more than 12.9 million affected accounts [6]. That is roughly 26 cents per exposed account for the option of keeping the archive off a dark web site [1], an option that expires the moment the data is indexed and searchable.
Read the field list before assuming stuffing risk. Hunt enumerates unique email addresses, names, phone numbers and physical addresses [6]. No passwords or hashes appear in that list [3]. On its own this dump does not log anyone into anything. What it does is match a real person to a real mailbox and a real street address at scale, which is the raw material for reset-flow abuse and for phishing that quotes back an order history. The gang's own description adds customer metadata it called royalty info alongside employee and internal corporate data [2]. Millions of synthetic records that pointed at nobody were stripped out of the count [7].
The employee number is the awkward one. Hunt found over 15,000 mailboxes on the carhartt.com domain inside the leaked database [8], against a company that reports more than 3,000 employees in the United States and Europe [10]. That is about five times the stated headcount [2], which points at years of accumulated former staff, service accounts, or non-employee addresses sitting in the same analytics store as the customer table. Those are the addresses that matter for the next intrusion, because credentials belonging to people with access to a data platform are precisely what this group has been buying, phishing and reusing.
Two things about the non-payment story are single-sourced. The $3.3 million figure and the negotiator's line, that after careful review and internal discussions with leadership the company decided not to move forward with negotiations or further discussions, come from ShinyHunters' own account [4]. Carhartt has not confirmed the breach, has issued no statement, and had no spokesperson available to BleepingComputer [9]. The archive is public and the record count is independently measured by Have I Been Pwned; the negotiation transcript is the extortionist's telling of it. Treat the first as evidence and the second as claim.
Ranked by verification strength, evidence, and original report placement.
ShinyHunters claimed the attack on August 13 and said it stole more than 50GB of documents containing customer, employee and corporate data, describing the haul as including customer data, PII, employee data, 'customer metadata (royalty info)' and other internal corporate data.
Hunt found over 15,000 employees with @carhartt.com email addresses in the leaked database.
Over the past year ShinyHunters has been linked to breaches at over a dozen Snowflake customers and many third-party integration providers, and claimed breaches at hundreds of Salesforce customers, saying it stole more than 1.5 billion records in the Salesforce Aura and Salesloft Drift campaigns.
ShinyHunters most recently claimed responsibility for breaches at more than 100 organizations in data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.
The ShinyHunters extortion group published sensitive data from nearly 13 million accounts stolen from clothing retailer Carhartt, according to data breach notification service Have I Been Pwned.
After analyzing the 50GB archive, Have I Been Pwned founder Troy Hunt linked the data breach to the compromise of Carhartt's Databricks analytics platform, a cloud platform combining business reporting and data storage.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named third-party analysis, silent victim, single outlet
The core scope claim is unusually well grounded for a breach story: a named practitioner service parsed the published archive, enumerated the exposed fields, excluded synthetic records and counted internal mailboxes. Against that, the entire cluster is one publisher, the victim has confirmed nothing, and the ransom figure, negotiation quote and 50GB volume are attacker-supplied with no corroboration.
Data already public and indexed at scale
This is a realized exposure rather than an announced risk: the archive is published, loaded into a public breach-notification service, and includes both a 12.9 million-account consumer corpus and over 15,000 internal mailboxes. The same actor's reported run across Snowflake, Salesforce and Oracle PeopleSoft tenants shows the pattern is recurring, not isolated.
Attacker framing outruns the verified field list
The gang's '50GB' and 'vast amount of sensitive information' framing is modestly overstated relative to what was verified: the loaded set is contact and identity fields with no credentials, and millions of records in the archive were synthetic. The reporting itself is restrained and correctly separates Hunt's findings from the extortion claims, so the gap is small and driven by the source's own attacker quotes rather than by the coverage.
Extortion-driven disclosure plus vendor-promo adjacency
Scored as strength of incentive pressure on the narrative, where higher means more distortion risk. The primary discloser is an extortion group with a direct interest in maximizing perceived damage after a refused payment; the verifying party is a breach-notification service whose visibility grows with high-profile loads; the victim's silence removes the main counterweight; and the article closes with a sponsored security-vendor report promotion adjacent to the news copy.
Scope solid, cause and cost unresolved
Confidence is moderate: the number of affected accounts and the nature of the exposed fields are supported by hands-on analysis of the published data, so the targeting-corpus read is dependable. Everything upstream and downstream is weaker: no confirmed access path into the Databricks environment, no victim or platform statement, attacker-only ransom details, and an unexplained mismatch between employee mailboxes and reported headcount.
product
RingCentral lost 1.6 million records to a phone call, not a missing patch1 distinct publisher
security
Snowflake's passwordless deadline turns Moucka-era credential debt into a due-dated cleanup1 distinct publisher
build
Databricks says the hard part of warehouse migration was the stored procedures, not the data1 distinct publisher
invest
Databricks raises $5B at $190B, and the multiple barely moved2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026