Search TorWire

Find cybersecurity guides and research articles

Home > News > Deep Web > ShinyHunters Leaks 50GB of Carhartt Data After $3.3M Ransom Demand Rejected

ShinyHunters Leaks 50GB of Carhartt Data After $3.3M Ransom Demand Rejected

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 28, 2026

Human Written
ShinyHunters Leaks 50GB of Carhartt Data After $3.3M Ransom Demand Rejected
  • Threat group ShinyHunters leaked 50 gigabytes of stolen data after Carhartt refused to pay the ransom demand of 3.3 million dollars.

  • Security researcher Troy Hunt traced the breach to the Databricks cloud analytics platform of Carhartt, which exposed 12.9 million user accounts and 15,000 employee emails.

  • ShinyHunters continues a major attack streak targeting cloud services and zero-day flaws across hundreds of global companies and government bodies.

The American clothing brand Carhartt has suffered a large-scale data infiltration involving millions of pieces of information. The hacking compromised personal details of retail customers and the employees of the company.

Cybercriminals stole the records earlier this month during a targeted digital intrusion. The attackers subsequently published the entire stolen dataset after extortion negotiations broke down.

Scope of the Breach and Exposed Records

An organized cybercriminal group called ShinyHunters has made a statement about hacking Carhartt cloud servers on August 13. The hackers took more than 50 gigabytes of corporate documents containing a lot of information about the company. The leaked information relates to the names, addresses, phone numbers, and primary email addresses of customers.

Also, forensic review confirmed the archive contained over 15,000 corporate email addresses –directly belonging to internal staff. The breach affected 12.9 million unique user accounts across global databases. Additionally, the stolen files contained internal corporate metadata alongside retail loyalty program information.

Data breach monitoring service Have I Been Pwned cataloged the stolen records following independent technical analysis. Security researcher Troy Hunt analyzed the exposed 50-gigabyte dark web archive directly. His technical review linked the stolen data to a compromised Databricks cloud analytics platform.

Organizations use Databricks to combine standard business reporting with central data storage across enterprise environments. Hunt confirmed the dataset contained millions of synthetic test records alongside real customer identities. Consequently, researchers filtered out non-human test entries to establish the accurate impact total.

Ransom Negotiations and Dark Web Data Release

ShinyHunters demanded a ransom payment of 3.3 million dollars to delete the stolen enterprise files. The cybercrime syndicate opened direct communications with company representatives to negotiate financial settlement terms.

However, corporate leadership chose to reject the extortion demand following internal risk assessments. A company negotiator informed the gang that Carhartt would not proceed with further payment discussions.

Following the failed negotiation attempt, the extortion group leaked the full 50-gigabyte data file online. Attackers uploaded the entire database onto their dark web leak portal for public access.

In California, Rusty James Estrella, 39, was charged with computer fraud and attempted extortion after allegedly hacking a Hesperia business and threatening to leak customer data on the dark web. He pleaded not guilty and remains in custody, highlighting growing law enforcement efforts against cyber extortion.

The released archives expose sensitive personally identifiable information to identity thieves worldwide. Carhartt representatives have not issued formal public statements regarding the incident or system recovery efforts.

The Growing Threat Landscape of Cloud Data Intrusions

The weaknesses in perimeter security of third-party cloud analytics services often lead to considerable risks for corporate networks. Hackers target centralized data storage solutions regularly in attempts at stealing sizable amounts of confidential customer data.

Moreover, new cybercriminal organizations are very keen on cloud environments because centralized data centers accumulate a wide range of useful information in one location. The compromised login credentials of employees may give cybercriminals access to the internal networks without triggering security alarms.

Cyber extortionists exploit stolen enterprise information to damage corporate brands and demand large ransoms. In case victims are unwilling to pay, the perpetrators will cash in on stolen information either through selling it on the dark web or leaking the information publicly.

Hence, it is necessary for enterprises to deploy continuous monitoring of all cloud services to detect unusual data exports. Security teams must enforce strict access controls and multi-factor authentication across external analytical databases.

Pattern of High-Profile Attacks by ShinyHunters

The cyber invasion of Carhartt is part of the growing list of intimidation campaigns that ShinyHunters has conducted recently. Over the past year, the group was able to break into a number of enterprises working with Snowflake cloud service at least a couple of times.

In addition, their activity focuses on hundreds of clients within Salesforce with the help of various third-party integrators. Their recent Salesforce campaigns allegedly harvested more than 1.5 billion records from connected corporate services.

In the meantime, it is important to point out that the gang has recently admitted they were able to break into more than 100 enterprises on a global scale. As a rule, these attacks relied on using a zero-day defect of Oracle PeopleSoft software apps.

Among the companies which fall within this breach are Google, Cisco, Match Group, PornHub, Vimeo, Rockstar Games, McGraw Hill, 7 Eleven, Carnival, Udemy, and Medtronic. Even the networks of the European Commission experienced some attacks during the same campaign.

Defensive Steps and User Recommendations

The customers affected by the breach should keep track of their digital identities to see if any unauthorized action occurs. For identity thieves, stolen phone numbers and addresses are a treasure that they can use for conducting focused spear-phishing operations.

In addition, those affected should change their passwords on all online services and activate two-step verification for key services. Users have to be careful about receiving phone calls, texts or emails that ask for confidential information about them.

Enterprise organizations must conduct thorough permission audits across all integrated cloud database services – also, systems administrators must ensure third-party analytics connections operate under the principle of least privilege.

Threat actors are constantly searching for unaddressed vulnerabilities, making timely incident response strategies essential for the avoidance of information theft. Regular security reviews help organizations isolate compromised analytics nodes before external data extraction occurs.

Share this article

You might also like

Hacker Claims 30TB Data Theft from more than 30 Universities Worldwide

Hacker Claims 30TB Data Theft from More Than 30 Universities Worldwide

A hacker claims to have stolen 30 TB of data from more than 30 universities around the world. The seller…

August 27, 2026
Threat Actor Offers Alleged Chilean Personal Data for Sale on Cybercrime Forum

Threat Actor Offers Alleged Chilean Personal Data for Sale on Cybercrime Forum

A threat actor advertised an unverified dataset on a cybercrime forum containing personal information belonging to Chilean residents. The seller…

August 12, 2026
Hackers Claims Sale of 1 39 Million Intermarché Customer Records on Cybercrime Forum

Hackers Claim Sale of 1.39 Million Intermarché Customer Records on Cybercrime Forum

A threat actor claims to have breached Intermarché and is selling over a million records of customers on a cybercrime…

August 6, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.