Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.

Details available here: https://haveibeenpwned.com/Breach/Carhartt

Commenting on this news is Paul Bischoff, Consumer Privacy Advocate at Comparitech:

“ShinyHunters is a high-profile cybercriminal group and its claims areusually credible, so breach victims should take the risks seriously. Based on what Have I Been Pwned found, the breached customer data was mostly limited to contact information. That doesn’t pose a direct threat to customer’s bank accounts or identities, but it could be usedto target them with phishing messages. Employees could have moresensitive data risk, but we’ll probably have to wait a few weeks for Carhartt to finish its investigation before we learn exactly what datawas compromised.”

Just like any other breach, you should check Have I Been Pwned to see if you are affected. And if so you should of course change your password. While you are at it, you should make all your passwords unique to lessen the chance that a credential stuffing attack will work on you.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading