HomeData BreachesCarhartt Data Breach Exposes 12.9 Million Accounts After Company Refuses to Pay...

Carhartt Data Breach Exposes 12.9 Million Accounts After Company Refuses to Pay ShinyHunters

Clothing retailer Carhartt has confirmed a data breach affecting 12.9 million customer and employee accounts after the extortion group ShinyHunters published stolen data online this week, following the company’s refusal to pay a ransom.

According to reporting from BleepingComputer, the breach traces back to a compromise of Carhartt’s Databricks environment, a cloud-based platform the company used to combine data storage with business reporting and analytics. Attackers were able to pull more than 50 gigabytes of data out of that system.

The stolen records include customers’ names, email addresses, phone numbers and physical addresses, along with metadata tied to Carhartt’s customer loyalty program. The dataset also contained internal corporate information and more than 15,000 email addresses belonging to Carhartt employees, using the company’s own @carhartt.com domain. Separately, researchers noted that part of the stolen dataset consisted of millions of synthetic, or artificially generated, test records that did not correspond to real people; those records were excluded when calculating the 12.9 million figure.

ShinyHunters first announced the attack on August 13, and reportedly demanded $3.3 million from Carhartt in exchange for not releasing the data. Carhartt did not pay. A company negotiator, quoted in the leaked communications, told the group: “After careful review and internal discussions with leadership, we have decided not to move forward with negotiations.” ShinyHunters published the stolen data on August 27 after the deadline passed without payment. As of publication, Carhartt has not issued a public statement about the incident.

ShinyHunters is a financially motivated extortion group that has claimed responsibility for a long string of high-profile breaches over the past two years, including the mass theft of data from companies that stored information in Snowflake’s cloud platform, attacks against organizations using Salesforce, and breaches tied to Oracle’s PeopleSoft software. The group has also claimed intrusions affecting Google, Cisco, the dating app operator Match Group, and video game publisher Rockstar Games, among others. Rather than deploying ransomware to encrypt files, the group’s typical approach is to steal data directly from cloud platforms and then threaten to publish it unless a ransom is paid, a tactic that has become increasingly common as more companies centralize sensitive data in third-party cloud services.

Customers whose information may have been exposed should be alert to phishing emails or phone calls that reference their name, address or loyalty account details, since attackers often use breached personal data to make follow-up scams appear more convincing. Carhartt employees whose email addresses were included in the leak should also be cautious of targeted phishing attempts referencing internal company details.

Source: BleepingComputer

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular