Carhartt Data Breach: 12.9 Million Records, and What Is Not in Them
In August 2026 the extortion group ShinyHunters published data it says came from Carhartt — 12.9 million unique email addresses with names, phone numbers and postal addresses. Carhartt has issued no statement. Two things follow from that, and most pages about this case skip the second: there is no settlement to claim, and the published data does not include Social Security numbers or payment card details.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Was Published, and by Whom
ShinyHunters runs a “pay or leak” model: steal a dataset, demand payment, publish it when the demand is refused. On or about August 13, 2026 the group claimed to hold more than 50 GB of Carhartt documents covering customer and employee data. It then published a customer dataset. Have I Been Pwned, the independent breach index, added the incident on August 25, 2026 and records 12.9 million unique email addresses with the data classes “email addresses, names, phone numbers, physical addresses”. That index entry is the most checkable public record of the incident, and it is where you can look yourself up. Carhartt has neither confirmed nor denied the claim and did not respond to press enquiries.
Case Details
No class action over this incident had been filed as of early September 2026 — the case trackers list it under investigations, not lawsuits. Edelson Lechtzin LLP announced an investigation on August 27, 2026, and several other consumer firms have followed. An announced investigation is a law firm looking for plaintiffs; it is not a docketed case, it creates no class, and it sets no deadline.
Status: Claimed Breach, No Company Statement, No Case
How to Tell Whether You Are in the Dataset
There is no class to join and no list to be added to. What you can do is check, in this order:
• Look up the email address you use for Carhartt orders on haveibeenpwned.com. The incident is indexed there, so a match is a real signal rather than a guess.
• Search your own mail for Carhartt order confirmations. If you have ordered from the site, your address, name and phone number were in the account record.
• Keep a screenshot of any match. If a case is eventually filed and certified, proof of an account matters more than a memory of one.
Employees are a separate question. ShinyHunters claimed the stolen material included employee data, but the published customer dataset is what has been indexed; no employee dataset has been verified publicly.
What This Data Is Worth in a Case
Carhartt Breach Timeline
- 1
On or About August 13, 2026 — The Claim
ShinyHunters says it holds more than 50 GB of Carhartt documents with customer and employee data, under a pay-or-leak demand.
- 2
August 2026 — The Data Is Published
The group releases a customer dataset after the demand is not met. Reporting puts it at roughly 12.9 million accounts.
- 3
August 25, 2026 — Indexed by Have I Been Pwned
The independent breach index adds the incident: 12.9 million unique email addresses, with names, phone numbers and physical addresses.
- 4
August 27, 2026 — First Firm Investigation
Edelson Lechtzin LLP announces it is investigating data-privacy claims. Other consumer firms follow. No complaint is filed.
- 5
Through Early September 2026 — Company Silence
Carhartt issues no statement and does not answer press enquiries. Without an acknowledgement there are no notification letters.
- 6
What Would Have to Happen Next
A confirmation or a regulator filing, then a complaint, then certification, then a settlement with an administrator. Only at the last step does a claim form exist.
Where This Case Gets Exploited
A leaked list of names, addresses and phone numbers is raw material for the next fraud, not just for the last one:
“Carhartt settlement claim” sites
No lawsuit has been filed, so no settlement exists and no claim form does either. A site asking for your Social Security number to process a Carhartt payout is collecting exactly the field the leak did not contain.
Order and delivery messages
The leaked fields are precisely what a convincing fake delivery notice needs. Treat unexpected texts about a Carhartt order as phishing until you have checked the order in your own account, typed in yourself.
“Remove your data” offers
Published breach data cannot be recalled, and no service can delete it from the copies already circulating. Paying for removal buys nothing.
Carhartt Breach — Questions People Actually Ask
Is the Carhartt data breach real?
A dataset attributed to Carhartt was published and independently indexed by Have I Been Pwned on August 25, 2026, covering 12.9 million email addresses. What has not happened is a confirmation from Carhartt, which has made no public statement. So: the data is real and public; the company's account of it does not exist.
What information was in it?
Per the Have I Been Pwned entry: email addresses, names, phone numbers and physical addresses. Social Security numbers and payment card data are not among the listed data classes.
How do I check whether I am affected?
Enter the email address you use for Carhartt orders at haveibeenpwned.com. The incident is indexed there. That is a direct check rather than an inference from whether you happen to have shopped there.
Is there a Carhartt settlement or claim form?
No. No class action has been filed, so there is no fund, no administrator, no claim form and no deadline. Several law firms have announced investigations, which is a search for plaintiffs, not a case.
Why did I not get a notification letter?
Because Carhartt has not acknowledged the incident. Notification letters follow a company's own determination or a regulator filing; neither has happened publicly here. That is why the breach index is doing the work the letter normally does.
Should I freeze my credit over this?
A freeze is free, reversible and never a bad idea, but it protects against new credit opened in your name — which needs a Social Security number, and that is not in the published data. The more proportionate response here is to treat unexpected messages about orders and deliveries as phishing.
Was employee data taken too?
ShinyHunters claimed the stolen material included employee data. Only a customer dataset has been published and indexed. No employee dataset has been publicly verified, so treat that part as an unconfirmed claim.
Will there eventually be a lawsuit?
Possibly. Firms are recruiting, and a 12.9-million-record leak is the kind of scale that attracts filings. But contact-data-only breaches are harder cases than Social-Security-number breaches, and no complaint has been docketed. We update this page when the record changes.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
TriZetto Breach (3.4M, MDL 3185)
Eleven months undetected — consolidated federal case
Aesto Health Breach (9.5M)
Healthcare vendor breach — the full provider list
Data Breach Payout Estimator
What a breach pays by data type, plus 30+ tracked cases
Return to Kroll, P.O. Box 980108
How to tell a breach notice from a settlement check