GKRootWire
AI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler DataAI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler Data
Security

Carhartt Breach Exposes Data From 12.9 Million Accounts

ShinyHunters extortion group leaks customer data stolen from the clothing retailer, according to Have I Been Pwned.

Clothing giant Carhartt has confirmed a significant data breach after the ShinyHunters extortion group published records tied to nearly 13 million customer accounts. The stolen dataset was verified and added to Have I Been Pwned, the breach notification service used to alert affected users.

Details on exactly what data was exposed and how attackers initially gained access haven't been fully disclosed, but the scale of the leak puts Carhartt among the larger retail breaches this year. ShinyHunters has been linked to a string of high-profile corporate data thefts, typically pairing breaches with extortion demands before dumping data publicly when companies don't pay.

Affected customers should watch for phishing attempts referencing their Carhartt purchases and change reused passwords, especially if the same credentials appear on other accounts.

Why it matters: Retailers sit on huge troves of customer PII with often weaker security investment than tech firms, making them attractive extortion targets. When groups like ShinyHunters go straight to public leaks instead of quiet ransom payments, the fallout shifts from the company's balance sheet to millions of individual users' inboxes.

Sources: BleepingComputer