Millions of user records belonging to Carhartt customers have been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals. The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down. ShinyHunters uploaded the entire data archive that was stolen in the breach. The ransomware group added that the demand was $3.3 million, which Carhartt turned down:
"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told ShinyHunters.
Total Retail's Take: An important note to this story is that Carhartt has not publicly confirmed the incident or provided its own account of exactly what happened, according to recent reporting. Therefore, claims made by the ShinyHunters extortion group should be taken with a grain of salt. However, whether or true not, it's likely that damage to customer trust has already happened.
In addition to closing whatever security gap allowed the incident to occur, Carhartt must communicate clearly with affected customers, explain what information was compromised, and warn them about secondary fraud attempts (e.g., phishing attempts to disclose loyalty and payment data). The priority now is containing the incident and maintaining customer trust.
For the retail industry at large, the incident should reinforce that the more valuable customer data becomes to personalization, loyalty and AI strategies, the more valuable that exact same data becomes to fraudsters. Therefore, protecting the customer data layer and not merely securing the checkout page is one of the industry's most important technology priorities.
- Categories:
- Data Security
Joe Keenan is the editor-in-chief of Total Retail. Joe has nearly 20 years experience covering the retail industry, and enjoys profiling innovative companies and people in the space.





