Tendvane

← All articles

SecurityAugust 27, 2026

Carhartt's leaked customer list was half invented. The other half is real.

Round numbers in a data breach are usually somebody's guess. This one got audited, and it shrank by half.

The extortion group ShinyHunters published roughly 50GB of Carhartt customer data on 13 August, after the workwear brand refused to negotiate a $3.3 million demand. The dump looked like it covered more than 25 million people. Troy Hunt, who runs Have I Been Pwned, went through it and found millions of the records had simply been made up to inflate the total. Some of the tells are almost funny: email addresses like michelle.larue@lkvb06fkzsjv.org, an odd pile of .edu and .org domains, birth dates clustered in the early 1900s, and more customers in Montenegro than in the United States. Once the fiction was stripped out, the genuine count came to 12,933,413 email addresses, added to HIBP on 25 August.

What's left is real enough. Names, email addresses, phone numbers and postal addresses for close to 13 million shoppers, taken according to Hunt's analysis from Carhartt's customer analytics warehouse running on Databricks. No passwords and no card numbers appear in the published set. Around 83% of the addresses had already surfaced in earlier breaches, which tells you how these lists compound over the years: sold, merged, resold, and eventually padded with invented rows to look more frightening than they are.

So there's nothing to reset here, which makes this a phishing problem rather than an account problem. Someone holding your name, mobile number and street address can write a very believable missed-delivery text or refund email, and that's exactly what this data gets used for. You can check whether your address is in the set at haveibeenpwned.com. Since a successful phishing attempt eventually has to land on an account, Tendvane's Privacy and accounts check gives you a plain summary of how each account on your PC is signed in and what it opens.

Sources

Download Tendvane