Carhartt’s alleged data breach appears to have affected 12.9 million people, not the much larger figure implied by the ShinyHunters leak claim, according to The Register’s report on Troy Hunt’s review of the dataset. Hunt, who runs Have I Been Pwned, examined the data before adding it to the breach-notification service. The final count published to HIBP was 12,933,413 accounts believed to be genuine, The Register reports. That is about half of what ShinyHunters purported when the group claimed to leak Carhartt data earlier this month. The underlying claim from ShinyHunters was that it dumped 50GB of Carhartt data on August 13. According to The Register, the group said the leak followed an attempted negotiation over a $3.3 million extortion demand. Those details remain the criminals’ account; Carhartt did not respond to The Register’s request for comment on Hunt’s findings. The important finding is not just the lower number. According to Hunt’s review, the dataset had been padded with millions of synthetic entries, inflating the apparent size of the breach. His initial extraction process returned nearly 25 million email addresses, but further analysis found patterns that did not look like a normal customer dataset for a retailer. The Register says Hunt used HIBP’s open-source email extractor first, then OpenClaw to analyze the contents and look for anomalies. The review flagged large volumes of .edu and .org addresses, randomly structured domains, unusual country distributions, and implausible birth-date patterns. After removing obviously bogus records, OpenClaw reduced the estimate from 24.8 million entries to 13.6 million likely genuine individuals. Hunt then continued removing suspicious records, including Microsoft 365 duplicate addresses and addresses marked for deactivation, according to The Register. That additional cleanup produced the 12,933,413-account figure that went into HIBP. HIBP also states that 83% of those accounts had already appeared in previous breaches. The real data still appears sensitive. The Register reports that the genuine records include names, email addresses, phone numbers, and physical addresses. Even if the criminal group’s headline number was inflated, the validated dataset remains large enough to matter for phishing, credential-stuffing triage, and personal-data exposure reviews. The case is a useful reminder for breach response: attackers have incentives to exaggerate. In this instance, the public number changed materially only after independent filtering separated probable customer records from synthetic padding. Who benefits: Affected Carhartt customers and HIBP users benefit from a cleaned dataset rather than a criminal group’s inflated headline number. Carhartt also faces a more precise public estimate, though 12.9 million affected accounts remains substantial. Who's exposed: People whose genuine records were in the dataset may have had names, email addresses, phone numbers, and physical addresses exposed, according to The Register. The overlap with prior breaches means many accounts were not newly unique to this incident, but the data still adds to cumulative exposure.