Skip links

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

security

One AI and two trained eyes delved into the heavily padded leaks

MOST POPULAR

Workwear and fashion retailer Carhartt’s data breach was about half as bad as ShinyHunters claimed, according to Troy Hunt, who reviewed the data dump before uploading it to his Have I Been Pwned website.

Hunt’s HIBP service reported 12.9 million individuals affected by the alleged breach, around half of what ShinyHunters purported when it claimed to leak the company’s data earlier this month.

ShinyHunters dumped what it said was 50GB worth of Carhartt’s data on August 13 after the retailer hired what the criminals called “a very unskilled and incompetent negotiator” to haggle the crooks down from their $3.3 million extortion demand.

According to Hunt, ShinyHunters data was injected with millions of lines of synthetic data, substantially padding out the number of affected individuals.

“You’re not going to believe this, but turns out you can’t always take criminals at their word,” said Hunt, before detailing the investigative process that goes into calculating the scale of breaches that make it to the HIBP site.

Hunt usually starts with HIBP’s open-source email address extractor, which spat out nearly 25 million addresses, before running it through OpenClaw to analyze the contents further and sift through the mass of information, looking for anomalies.

For a retailer, the AI thought that the millions of .edu and .org email domains looked off – like signs of TPC-DS synthetic data injection.

Examples included michael.ware@c.edu and michelle.larue@lkvb06fkzsjv.org. The first and last names look real, but a common finding among TPC-DS-generated data is that it will use completely random strings for domains.

A manual look at the data points with which these email addresses were associated further revealed these “individuals” were located in countries, such as Benin, which don’t represent dominant Carhartt markets.

Further, the AI found more customers registered in Montenegro than in the US, where Carhartt is headquartered. It also found a suspiciously large proportion of customers with birth dates set in the early 1900s – unlikely given the company’s clientele is more hipster-oriented than than blue-collar nowadays.

Hacking away at all the clearly bogus data, OpenClaw dropped the estimated number of genuine individuals among the data trove from 24.8 million to 13.6 million.

Hunt carried on eliminating suspicious findings he noticed, such as Microsoft 365 duplicate email addresses and addresses marked for deactivation, as well as prompting OpenClaw to continue doing the same.

He finally arrived at 12,933,413 accounts believed to be genuine among the ShinyHunters-leaked dataset. That’s the number that made it to the HIBP platform, which states that 83 percent of these were already gathered up in previous breaches.

The moral of the story is, as Hunt says, to “take headline numbers with a grain of salt unless you’re confident in the processes of those making the claims.” And until trustworthy sources do the arduous work, stop treating the word of cybercriminals as gospel.

The real data contains names, email addresses, phone numbers, and physical addresses.

Carhartt did not respond to our request for comment on Hunt’s findings. The company is yet to comment on the breach anywhere publicly. ®

Source