Carhartt data breach exposed information from 12.9 million user accounts
- ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks
- Data stolen from Databricks platform included names, emails, phone numbers, and addresses
- Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption
Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.
The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach.
"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.
Compromising analytics platforms
It added that the demand was $3.3 million, which Carhartt turned down:
"After careful review and...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE