SINGAPORE, 30 AUG 2026 — ShinyHunters dumped 50GB of Carhartt customer data and claimed close to 25 million people. After Troy Hunt filtered it for Have I Been Pwned, the genuine figure was 12,933,413. The rest was synthetic data, deliberately inserted to inflate the count.

How the padding was detected

Hunt reviewed the dump before loading it, and the fabricated records did not survive inspection. The tells were data-quality anomalies common in fabricated data and rare at scale in a real customer database.

There were .edu and .org email domains attached to random strings. There were customers listed in countries where a US workwear retailer has negligible presence, including Benin and Montenegro. There were dates of birth in the early 1900s.

Filtering the obvious fabrications brought the count from nearly 25 million down to 13.6 million. Further refinement produced the final figure of 12,933,413 genuine accounts, which is close to half what was claimed.

~25mRecords ShinyHunters claimed
12,933,413Genuine accounts after filtering
50GBSize of the dump, published 13 August
US$3.3mThe extortion demand that was not met

Why a criminal group pads a dump

Inflating a victim count is not vanity. It has three commercial functions, and naming them is what lets a defender discount the number.

It raises the extortion price. A company negotiates against the harm it believes it faces, and 25 million affected customers implies a much larger regulatory and litigation exposure than 13 million does.

It raises the resale price. Stolen data is sold in bulk, and buyers pay by volume before they verify quality.

And it manages reputation within the ecosystem. A group's leverage in future negotiations depends on other victims believing its claims, which makes each published figure an advertisement for the next demand.

Why nobody else checks

The verification only happened because one person decided to look.

Journalists reporting a breach generally cannot load a 50GB dump of stolen personal data, and in many jurisdictions should not. Regulators receive notifications from the company rather than from the attacker, so they see the company's count and not the claim. The company itself has every incentive to state a lower number and no standing to comment on the attacker's file without acquiring it.

That leaves breach-notification services, which acquire the data precisely so that affected people can be told, and which therefore end up as the only parties routinely in a position to audit an attacker's arithmetic. It is an accidental role and a thin one, resting on a small number of operators.

The first number published is almost always the attacker's. It circulates for days or weeks unchallenged, and any later correction reaches a fraction of the same audience.

The pattern is now documented twice

This is the second time in nine days that a ShinyHunters figure has failed verification, and the two failures are of different kinds.

Earlier this month the group claimed 25 million Alcon records and 218,000 appeared — a claim that collapsed on volume alone, with under one per cent of the asserted total materialising.

Carhartt is the more sophisticated version. The data arrived, it was the right general shape, and it had been salted. That takes more work than an empty boast and it is harder to catch, which is precisely why it needed someone to sit down and audit the file rather than count the rows.

Coincidentally, both incidents involve the same claimed figure of 25 million. Whether that is a preferred round number or an accident of two separate estimates is not something the evidence settles.

What the company said, and what it faced

The dump followed a failed negotiation. ShinyHunters published on 13 August after Carhartt declined a US$3.3m demand, and the group's own commentary complained that the retailer had hired what it called an unskilled negotiator.

The detail reveals more about the business of extortion than it does about Carhartt. A criminal group publicly reviewing the professionalism of its victim's incident-response advisers is a group treating extortion as a recurring commercial relationship, in which reputation for consistent behaviour is an asset.

The refusal itself was the correct call, and it produced the ordinary consequence. Paying would have bought a promise of deletion from a party that has now been shown, twice, to misrepresent what it holds.

What this means for regional reporting

This matters to readers here because the same dynamic governs local breach figures, and the capacity to verify them is thinner still.

Regional breach claims are typically published by the attacker on a leak site, picked up by local outlets, and repeated into board papers without anyone loading the file. We have already noted how two incidents accounted for half of the Philippines' 335 million exposed records, a composition detail that the headline total obscured, and how a regional average cost figure rests on a sample of 26 organisations.

In each case the number that travelled was the one that was easiest to state and hardest to check. Carhartt is the same failure with an unusual ending, because somebody did the checking and published the working.

How to read the next breach headline

The practical guidance is short and it applies to every claim of this kind.

Treat an attacker's stated record count as an upper bound rather than a measurement, and treat a company's confirmed count as the number that carries consequences. Wait for an independent party to load the data before accepting either. Have I Been Pwned's count is derived from the file rather than from the claim, which is why it diverged here.

For an affected individual the total is irrelevant. A compromised record is a compromised record, whether it is one of 13 million or one of 25 million. Change reused passwords, expect targeted phishing that quotes real order details, and treat unexpected contact referencing a purchase as suspect.

The number matters for the company's regulatory position, for the size of any class action, and for the group's next demand. It does not matter to the person whose address is in there.