The email arrives on a Tuesday and it looks right. Your first name at the top. A reference to the address your last order shipped to. A note that there is a problem with the delivery, and a link to fix it. Nothing about it feels like a scam, because almost nothing in it was guessed — your name, your phone number, your shipping address and your email address were published together in August, and whoever sent that message did not need to know a single thing about you that the leak had not already told them.
If you have bought Carhartt online, this is worth ten minutes of your attention.
What Company Was Breached?
Carhartt is the US clothing retailer, and data described as its customer records was published online in August 2026 after the company was named in a ShinyHunters “pay or leak” extortion campaign.
Have I Been Pwned lists the breach against the domain carhartt.com. Carhartt itself has published no statement about the incident, so everything below is sourced to the dataset and to the people who analysed it rather than to the company.
When Did the Breach Occur?
Have I Been Pwned records the breach date as 13 August 2026 and added the verified dataset to its index on 25 August 2026.
Those are two different dates and the distinction matters. The first is when the data surfaced publicly. When the underlying access actually happened, and for how long, has not been stated by Carhartt — and until it is, the honest answer is that nobody outside the company knows.
What Was Stolen?
Have I Been Pwned lists 12,933,413 unique email addresses in the Carhartt breach, alongside names, phone numbers and physical addresses. No passwords appear among the exposed data types.
The figure you may have seen reported is higher, and it is worth knowing why. The raw published corpus yielded close to 24.9 million email addresses, and several outlets reported a number in that range. When Have I Been Pwned’s Troy Hunt analysed the data, roughly half of it turned out to be synthetic — records generated by a standard database benchmarking tool that had been sitting in the same system as the real customer data and was scooped up with it. Addresses like violet.day@ob7.edu do not belong to anybody. Once those, plus duplicate routing aliases, deactivated-account rows and internal test records were removed, the count of addresses that represent real people came to 12,933,413.
Of those, 83% were already in Have I Been Pwned from earlier breaches.
How Can This Breach Be Used Against You?
An email address published next to a real name, phone number and shipping address makes a fake delivery or order-problem message far harder to spot than a generic one.
The specific things to expect:
- A fake delivery or order notice referencing a real address, asking you to click a link to reschedule, pay a small fee, or confirm details.
- A fake refund or “we owe you” message — retail breaches reliably produce these, because the offer of money owed is what gets a careful person to click.
- Text messages and phone calls, because the phone numbers went out with the addresses.
- Steadily more junk mail, as the address list is resold and reused long after the news cycle ends.
What is not indicated here: there are no passwords and no payment card numbers in the exposed data classes, so this is not a case where someone can take your login and open your accounts. The risk is what arrives, and how convincing it looks when it does.
How to Protect Yourself
- Check whether your address is in it. Have I Been Pwned’s search is free and takes a few seconds.
- Treat any Carhartt-branded message about an order as unverified. If you want to check an order, open
carhartt.comyourself and sign in there. Do not use the link in the message — that one rule defeats most of what follows a breach like this. - Be suspicious of texts and calls too. Your number went out with your address, and the same script works over SMS.
- Turn on stronger sign-in where you have the option — passkeys or an authenticator app rather than a code by text — on your email account first, because that account is how most of your others get reset.
- Use a separate email address for retail sign-ups. The next retailer to be breached will publish whatever address you gave them, and keeping that address away from your banking and account-recovery mail limits what any one leak is worth.
- Watch for identity misuse rather than assuming it. There are no Social Security numbers or card numbers in this dataset, so a credit freeze is a precaution here rather than an indicated response — but it is free, and if you have been in several breaches it is a reasonable thing to do anyway.
How OptMsg Helps
OptMsg is an opt-in email service: mail from a sender you have not approved is delivered to Trash rather than to your Inbox, and Trash is auto-deleted after 30 days. That is the whole of the patent-pending opt-in technology, and it is deliberately simple.
Be clear about what that does and does not change here. OptMsg had nothing to do with Carhartt’s systems and would not have changed what happened inside them. An address that has been published cannot be un-published, and no email service can pull it back off the lists it is now on.
What changes is the destination. Once your address is circulating, the mail written from it starts arriving — and on an opt-in inbox, the fake delivery notice from a sender you have not approved lands in Trash instead of sitting in your Inbox next to real mail, looking like real mail. If you are worried something got misfiled, the 30-day Trash window means it is still there to check.
That is a smaller claim than “you are protected”, and it is the accurate one. If the part of this that worries you is a convincing fake landing where you trust things to be real, that is the part an opt-in inbox is built for. You can create an OptMsg account and see how your own inbox behaves, or read more about how OptMsg approaches account security.
Create Your Account
Sources
- Have I Been Pwned — Carhartt breach entry (verified dataset, 12,933,413 accounts, added 25 August 2026)
- Troy Hunt, “A Cautionary Tale About Data Breach Claims, Verification and Carhartt”, 26 August 2026
- Cybernews — “ShinyHunters claims Carhartt data breach involving millions of customer records”, 14 August 2026
No link to a Carhartt disclosure appears above because there is not one.