On 13 August 2026, the extortion group ShinyHunters published roughly 50GB of data it said it had taken from Carhartt, the American workwear manufacturer. The dump followed a failed negotiation over a $3.3 million demand — the group publicly complained that Carhartt had hired what it called “a very unskilled and incompetent negotiator.”
The data contains email addresses, names, phone numbers and physical addresses, along with employee records, customer metadata including loyalty information, and internal corporate material.
Then something useful happened. Somebody counted.
12,933,413
When the dataset was analysed for Have I Been Pwned, the number of accounts believed to be genuine came to 12,933,413 — roughly half of what the volume of the dump implied.
The rest was synthetic data: millions of lines of fabricated records deliberately injected into the archive to inflate its apparent size.
That is not corruption, or duplication, or sloppy exfiltration. It is a choice made by the people doing the stealing, and it is worth understanding why they made it.
Why Attackers Pad
Three reasons, all of them rational from the attacker’s side.
It raises the ransom. Extortion pricing is anchored on scale. “We have 25 million of your customers” supports a larger demand and a more frightening board presentation than “we have 13 million.” The victim company, mid-incident and without the ability to verify the archive, has to price the worst case.
It raises the group’s standing. These crews compete for reputation in a market where reputation determines who gets paid without a fight. A bigger number on a leak site is marketing.
It poisons the response. A defender trying to determine notification obligations has to first separate real records from fake ones. Every hour spent on that is an hour not spent on containment — and if they get it wrong in the cautious direction, they notify millions of people who were never affected.
That last effect is the one with public consequences.
What Padding Breaks
Breach notification law assumes a countable set of people. Every US state statute, the GDPR’s Article 33 and 34, and every sectoral regime is written around identifying affected individuals and telling them. A dataset engineered so that its own contents cannot be trusted attacks that assumption directly.
Two failure modes follow, and both are bad:
- Over-notification. Companies notify everyone in the archive, including the fabricated entries and, more importantly, real customers whose records were not actually taken. People take costly action — freezes, card reissues, password churn — for an exposure that did not happen. And every unnecessary notice makes the next real one slightly less believable.
- Under-notification. Companies conclude the dump is “mostly fake,” discount it publicly, and quietly under-count the genuine victims. This is the more tempting error, because it is cheaper and the attacker’s own exaggeration provides the excuse.
It corrupts the statistics. Aggregate breach reporting — the numbers we cited in the ITRC’s H1 2026 report showing 471 million victim notices — is assembled largely from company disclosures and public claims. If claims are systematically inflated, the trend lines everyone uses to argue about policy are inflated with them. Nobody knows by how much.
It creates deniability. Once “the attackers padded it” is a known phenomenon, it becomes an available defence for any company that would rather not notify. Sometimes it will be true. There is no way for an outsider to tell which times.
Why It Was Caught Here
Because an independent party with no incentive in the negotiation looked at the raw data and did arithmetic on it.
Have I Been Pwned’s role in this ecosystem is easy to undervalue. It is one of the very few mechanisms where a breach is characterised by someone who is neither the attacker (who wants the number high) nor the breached company (which wants it low). The 12,933,413 figure exists because of deduplication and validation work, not because either party to the extortion volunteered it.
That is a fragile piece of public infrastructure to be leaning on this hard.
What Carhartt Customers Should Actually Do
The genuine 12.9 million is not a small breach, and the data type matters. There are no passwords or payment cards reported here — but email, name, phone and postal address, tied to a specific retailer and loyalty history, is an excellent phishing kit.
- Check Have I Been Pwned. Enter your email at haveibeenpwned.com. It will tell you whether your address appears in the validated Carhartt set, which is far better information than a corporate notification letter will give you.
- Expect Carhartt-branded phishing, and expect it to be good. Attackers know your name, what you bought, and your loyalty status. “There’s a problem with your recent order” from someone who can cite the order is convincing. Navigate to the retailer directly; never through the email.
- Expect SMS and voice too. Phone numbers were in this set. A text about a delivery problem for a package you actually ordered is the highest-conversion scam there is.
- Do not reuse the email address for anything sensitive. If this address is also your bank login, your recovery address, or your Apple/Google ID, change what you can. Consider aliasing — Brave now generates disposable forwarding addresses natively, and Apple’s Hide My Email and Fastmail’s masked addresses do the same job.
- Ignore anyone who contacts you offering to remove your data from the leak. That is its own scam, running on the back of this one.
The Structural Point
We have spent years training people to read breach numbers as a proxy for severity. A 25-million-record breach sounds twice as serious as a 13-million-record one, and headlines are written accordingly.
Attackers have noticed, and they have started supplying the number themselves.
The right posture is the one Have I Been Pwned modelled here: treat any figure that originates with the attacker as marketing until somebody independent has counted. And when a company tells you its breach was smaller than claimed, ask the follow-up question — smaller according to whom, and did anyone outside the negotiation look?



