By MFJ Staff | Sources: Troy Hunt and The Register
Key takeaway: When a breach number hasn’t been through full independent verification, treat it as provisional, whether it originated with the attacker or with the first researcher to look at the data, until an independent audit or the affected company confirms it.
A security researcher’s audit found that nearly half the data in a Carhartt breach dataset posted by hacking group ShinyHunters was fabricated test data, cutting the estimated breach size from an initial 24.8 million records down to 12.9 million genuine accounts.
Hacking group ShinyHunters said in mid-August 2026 that it had compromised Carhartt’s Databricks analytics environment, taking more than 50GB of compressed data that included customer records, loyalty information, and employee details from the workwear manufacturer. ShinyHunters did not publicly state a specific record count; the initial 24.8 million figure came from security researcher Troy Hunt’s own preliminary extraction of the leaked files, run through an open-source email address extraction tool before deeper analysis began.
Hunt, who runs the breach-notification site Have I Been Pwned, then dug further into the dataset and found that roughly 11.6 million of those records, a 47% drop from the initial count, were synthetic test data drawn from a standard database benchmarking set, not real customers. The fake entries were identifiable by patterns a genuine customer list wouldn’t show: an almost perfectly even spread of birth years from 1924 to 1992, equal representation across all 211 ISO country codes, and gibberish email domains that appeared only once each, according to Hunt’s writeup.
After stripping out the synthetic records along with inactive, routing-alias, and other non-genuine accounts, Hunt confirmed 12.9 million real customer records, including names, email addresses, dates of birth, physical addresses, and purchase history. He also found 15,057 internal @carhartt.com employee email addresses in the same dataset. Hunt concluded the breach itself was real and that ShinyHunters most likely did not realize the benchmark data was mixed in with genuine customer records, rather than deliberately inflating the count. Carhartt had not issued a public statement on the breach as of Hunt’s analysis.
Why it matters: Breach headlines move fast, and the first number that circulates, whether from an attacker or from a researcher’s own preliminary pass at the data, isn’t always the real one. For merchants and risk teams tracking vendor and platform breaches, that’s a reason to wait for independent verification before recalibrating fraud models, issuing customer notifications, or making decisions based on an early record count.
Source: Troy Hunt, and The Register












