VYPR
breachPublished Aug 26, 2026· 1 source

Carhartt Data Breach Scale Inflated by Synthetic Data, Analysis Reveals

A data breach claimed by ShinyHunters affecting Carhartt customers has been significantly downsized by analysis, with synthetic data found to have inflated the number of affected individuals.

Troy Hunt's Have I Been Pwned (HIBP) service has confirmed that a data breach attributed to the threat actor ShinyHunters impacted approximately 12.9 million individuals, a figure substantially lower than the 25 million initially claimed by the attackers. The discrepancy arose from the extensive use of synthetic data within the leaked dataset, a tactic employed to artificially inflate the perceived scale of the breach.

ShinyHunters had claimed to leak 50GB of Carhartt data on August 13, following a failed negotiation over a $3.3 million ransom demand. However, Hunt's meticulous analysis, a process he detailed on his HIBP blog, revealed that the attackers had injected millions of lines of fabricated data into the dump. This synthetic data included random domain names and improbable geographic and demographic information, making it appear as though a much larger number of unique individuals were compromised.

Hunt's investigation began with HIBP's open-source email address extractor, which initially identified nearly 25 million email addresses. Further analysis using OpenClaw, a tool for sifting through large datasets, flagged anomalies. For instance, the presence of numerous .edu and .org email domains, such as '[email protected]' and '[email protected]', raised suspicion. While the names appeared legitimate, the random strings used for domains are characteristic of synthetic data generation, often seen in TPC-DS datasets.

Further examination of the data associated with these suspicious email addresses revealed inconsistencies. The analysis indicated that some "individuals" were located in countries like Benin, which are not primary markets for Carhartt. More strikingly, the data suggested more customers were registered in Montenegro than in the United States, Carhartt's home country. Additionally, a disproportionately high number of customers had birth dates in the early 1900s, an unlikely demographic for a brand popular with younger, trend-conscious consumers.

After filtering out the clearly bogus entries, OpenClaw reduced the estimated number of genuine individuals from 24.8 million to 13.6 million. Hunt continued to refine this number by eliminating duplicates, such as multiple Microsoft 365 addresses, and addresses marked for deactivation. This rigorous process ultimately led to the identification of 12,933,413 accounts believed to be authentic.

The actual compromised data for these genuine individuals includes names, email addresses, phone numbers, and physical addresses. While Carhartt has yet to publicly comment on the breach or Hunt's findings, the HIBP platform noted that 83 percent of the confirmed affected individuals had already been part of previous data breaches.

Hunt emphasized the importance of critically evaluating breach claims, advising users to "take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This incident serves as a stark reminder that the word of cybercriminals should not be taken as gospel, especially when significant financial or reputational stakes are involved.

The findings underscore the evolving tactics of data breach actors, who are increasingly using sophisticated methods like synthetic data injection to mislead investigators and inflate their leverage in extortion attempts. Security professionals and consumers alike must remain vigilant and rely on verified analysis rather than initial attacker claims.

Synthesized by Vypr AI