ShinyHunters Padded the Carhartt Breach With Millions of Fake Records
When ShinyHunters dumped what it claimed was 50GB of Carhartt customer data earlier this month, the headline figure was somewhere north of 25 million affected individuals. Turns out that number was roughly twice the reality, because the criminals apparently couldn't resist stuffing the archive with synthetic garbage.
Troy Hunt, who runs the Have I Been Pwned breach notification service, reviewed the dataset before ingesting it and found significant signs of TPC-DS synthetic data injection. After working through the numbers, HIBP ended up listing 12,933,413 genuine accounts, not the 25 million-plus the raw dump initially suggested.
For context: ShinyHunters released the data on August 13 after Carhartt allegedly sent in what the group described as a "very unskilled and incompetent negotiator" to push back on a $3.3 million extortion demand. Whether the padding was deliberate face-saving or just a byproduct of how they obtained the data isn't clear. Either way, someone inflated the numbers.
Hunt walked through his methodology publicly. The process starts with an open-source email extractor, which initially pulled nearly 25 million addresses. That went through OpenClaw, an AI-assisted analysis tool, which started flagging oddities almost immediately.
For a workwear retailer, a suspiciously high proportion of .edu and .org email domains is a red flag. Addresses like [email protected] or [email protected] have plausible-sounding names attached to completely nonsensical random-string domains, a classic fingerprint of TPC-DS generated test data. The associated records made things worse: these phantom customers were supposedly located in places like Benin, and more Carhartt "customers" appeared to be registered in Montenegro than in the United States, where the company is actually based.
There was also an implausible cluster of birth dates from the early 1900s. Given that Carhartt's customer base has shifted heavily toward the kind of people who wear the brand as a fashion statement rather than because they're working a job site, centenarian customers weren't going to slip past scrutiny.
OpenClaw trimmed the estimated genuine count from 24.8 million down to 13.6 million. Hunt then manually cleared out Microsoft 365 duplicate addresses and accounts flagged for deactivation, eventually settling on the final figure.
Of those 12.9 million records, HIBP says 83 percent had already appeared in previous breaches. The actual data includes names, email addresses, phone numbers, and physical addresses.
Carhartt has not publicly acknowledged the breach at all, and did not respond to press enquiries about Hunt's analysis.
Hunt's summary is blunt: take breach numbers at face value only when you trust whoever is doing the counting. Cybercriminals have obvious incentives to exaggerate scale, whether for ransom leverage, reputation, or both. Until someone credible does the grunt work of actually verifying the data, the headline numbers are largely fiction.