Normal view
Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams
A data breach doesn’t have to expose your password or credit card number to create problems. Sometimes, scammers just need enough information to make you believe they know you.
That’s the concern after data reportedly stolen from Carhartt was published online. Here’s what happened, why it matters, and what consumers should watch for next.
What Happened in the Carhartt Data Breach?
The cybercriminal group ShinyHunters published data it claims was stolen from Carhartt after an alleged $3.3 million extortion demand was rejected, according to TechRadar. Security researcher Troy Hunt analyzed the leaked information and determined that the compromised data was associated with roughly 12.9 million accounts, although the dataset also reportedly contained millions of synthetic records that did not correspond to real people.
For affected consumers, the important part is what was reportedly exposed: names, email addresses, phone numbers, and postal addresses.
This is also a useful example of how cyber extortion has evolved.
Traditional ransomware typically involves criminals getting inside an organization, encrypting its files so they can’t be accessed, and then demanding payment to restore them.
In this case, the reported strategy was different. ShinyHunters has increasingly focused on data exfiltration — security jargon for stealing or copying data out of a system — and then using the threat of publishing that information as leverage.
In plain English: Criminals don’t necessarily need to lock up a company’s computers anymore. Stealing its data can be valuable enough.
How Scammers Might Use This Information
The immediate question after any breach is usually, “Was my financial information stolen?” That’s important, but it isn’t the only risk.
A combination of your name, email, phone number, and home address can help scammers create a message that sounds much more believable than generic spam.
Instead of: “There’s a problem with your account. Click here.” you could receive something that appears to know your name, where you live, or which company you’ve done business with.
That context can lower your guard.
And scammers don’t necessarily have to pretend to be Carhartt. Stolen contact information can potentially be combined with information from other breaches, data brokers, or public sources to build a more complete picture of someone.
That’s why leaked personal information can remain useful to criminals long after the original breach disappears from the headlines.
Key Takeaways
- Personal information can be valuable to scammers even when passwords or payment information aren’t exposed.
- Names, emails, addresses, and phone numbers can make phishing attempts more personalized.
- Be particularly cautious of unexpected messages claiming there is a problem with an order, refund, account, or payment.
- A company knowing personal details about you is not proof that the person contacting you actually represents that company.
How McAfee Protects Against Breaches
Before a breach
Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.
Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.
During a breach
Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.
Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.
After a breach
Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even
Other Scam and Security News This Week
A Lenovo Login Flaw Exposed About 5,000 Dropbox Accounts
Dropbox says approximately 5,000 accounts were accessed after attackers exploited a flaw involving Lenovo ID authentication; fewer than a third reportedly had files viewed or downloaded. Dropbox has expired sessions authenticated through Lenovo IDs and changed the login process, while the incident is another good reason to enable two-factor authentication on cloud accounts.
Sources: BleepingComputer
Amazon Adds a New Way to Check Suspicious Messages
Amazon has added a feature to Alexa for Shopping that lets U.S. customers ask whether an email, text, phone call, or other message actually came from Amazon; the company says roughly 360,000 customers contact customer service each year with that question. It’s a useful reminder of one of the best scam-fighting habits: instead of trusting the message in front of you, verify it through a separate, official channel.
Sources: TechCrunch
Fake Late-Night TV Clips Show How Easily AI Can Borrow Someone’s Credibility
NPR reports that AI-generated videos impersonating late-night hosts including Jimmy Kimmel and Jon Stewart have accumulated significant audiences online, sometimes without obvious AI labels. The bigger consumer lesson goes beyond politics or entertainment: seeing a familiar face and hearing a familiar voice is no longer enough to prove that a video — or the product, investment, or claim it promotes — is authentic.
Source: NPR
This Week’s Safety Tips
✓ Treat unexpected personalization as information, not proof. A caller knowing your name, address, or other details doesn’t mean they’re legitimate.
✓ Turn on two-factor authentication. This can provide another barrier when someone tries to access an account without permission.
✓ Verify messages outside the message itself. Open the official app, type the website yourself, or contact the company using information you independently know is legitimate.
✓ Slow down when something feels urgent. Whether it’s a breach alert, delivery problem, suspicious login, or celebrity video, scammers benefit when you react before you verify.
And we’ll be back next week with more cybersecurity news and scam alerts.
The post Carhartt Data Breach Reportedly Exposes Millions. What to Know This Week in Scams appeared first on McAfee Blog.
ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years
-
The Register - Security
- Cisco searched for IOS XR bugs and found so many it rolled them into an update release
Cisco searched for IOS XR bugs and found so many it rolled them into an update release
OpenAI commits $1B in AI credits to frontline cyber defenders
Nobody Is Saying Why OpenAI and Anthropic Had Outages Today
Prediction Market Betting Is Getting People Banned and Arrested
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Drowning in CVEs and thirsty for answers? Try CTEM
This Is Flock’s AI Search Tool for Cops
UK's Online Safety Act has made 'absolutely no difference,' kids say
-
The Register - Security
- Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
Claude Mythos only model to complete full cyber kill chain, experts say
-
The Register - Security
- AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
SonicWall's SMA1000 boxes under active attack again
-
McAfee Blogs
- Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events
Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events
Labor Day weekend means sales. And if you spend any time on Facebook, Instagram or TikTok, some of the biggest discounts may find you before you even start shopping.
That convenience comes with a catch: Not every deal in your feed is really from the brand it appears to be.
Scammers can create polished social media ads that impersonate familiar retailers, advertise steep discounts and send shoppers to convincing lookalike websites. According to the Federal Trade Commission, nearly 30% of people who reported losing money to a scam in 2025 said that it started on social media. And the reported losses hit a whopping $2.1 billion last year.
So before a Labor Day “80% off” deal stops your scroll, give it a second look.
How Fake Social Media Shopping Ads Work
A fake shopping ad often starts with something completely ordinary: a product you actually want.
Maybe it’s sneakers from a familiar brand. Patio furniture you’ve been researching. A handbag, grill or appliance marked down for Labor Day.
The ad may use the real company’s logo, product photography and branding. Click it, and the website can look remarkably similar to the retailer’s actual site.
That’s the trick.
This is a form of brand impersonation: A scammer copies the appearance of a company people already know and trust. Instead of convincing you to trust an unfamiliar store, the scammer borrows the reputation of a familiar one.
Sometimes these ads lead to completely fake storefronts. Other times shoppers receive counterfeit products, something dramatically different from what they ordered or nothing at all.
The FTC recently warned consumers specifically about social media ads advertising brand-name products at unusually low prices. And the problem isn’t limited to one platform. A convincing ad can reach you wherever you scroll.

She Thought She Bought $800 Patio Chairs for $135
One shopper who shared her story with McAfee learned just how convincing these scams can be.
A few years ago, Jen was scrolling through Facebook when she spotted an ad for the exact Wayfair patio chairs she and her husband had been considering. Normally around $800, the chairs were advertised at 80% off — just $135 with free shipping.
She clicked.
The experience looked enough like Wayfair that she continued with the purchase, even though a few things started to feel strange. A new tab opened when she tried to buy the chairs. The checkout mentioned PayPal even though she was using her credit card. Then she learned the order would be shipping from China and could take six to 12 weeks.
When she checked her credit card, the charge wasn’t from Wayfair. It appeared in Chinese characters.
Weeks later, a package finally arrived.
It wasn’t a set of patio chairs. Inside the small package was a ceiling-fan chain with a cheap ring.
Her credit card company eventually reversed the charges. But the experience illustrates something important about fake shopping ads: You don’t necessarily land on an obviously fake website filled with misspellings and broken images. A scammer’s goal is to make the experience feel normal long enough for you to complete the purchase.
7 Signs a Social Media Ad or Shopping Site Could Be Fake
Before buying something you find through Facebook, Instagram, TikTok or another social platform, look for these warning signs:
1. The discount is dramatically better than everywhere else.
A legitimate sale can be generous. But if one ad offers a popular $800 product for $135 while reputable retailers are nowhere close, investigate before buying.
2. The website address doesn’t match the retailer.
A fake site can copy a logo much more easily than it can copy a company’s official domain. Look carefully for extra words, misspellings or unusual endings in the web address.
3. Clicking takes you somewhere unexpected.
Watch for redirects, new tabs or checkout pages on a different domain. A change doesn’t automatically mean fraud, but it’s a reason to verify where you are before entering payment information.
4. The checkout process feels off.
Pay attention when the payment method, merchant name or checkout experience doesn’t match what the site told you to expect.
5. There’s pressure to buy immediately.
Countdown timers and “only two left” warnings can push you to act before checking the seller. Urgency is useful to scammers because it shortens the time you spend thinking.
6. You can’t independently verify the sale.
Open a new browser window or the retailer’s official app and search for the product yourself. If the incredible sale exists only through the social ad, that’s a warning sign.
7. The merchant on your credit card doesn’t match the company you thought you paid.
Check the transaction after buying. An unfamiliar merchant name or unexpected international charge deserves immediate attention.
The Safest Way to Shop a Deal You See on Social Media
Here’s a simple safety checklist for Labor Day weekend:
✓ Leave the social app and find the retailer yourself. Don’t let the ad choose your destination.
✓ Compare the price elsewhere. A discount that’s wildly out of line with other retailers deserves extra scrutiny.
✓ Check the URL and merchant name. Make sure you’re dealing with the company you think you’re dealing with.
✓ Use a credit card when possible. And save screenshots, receipts and order confirmations in case you need to dispute the purchase.
What If You Already Bought Something From a Fake Ad?
Act quickly, but don’t panic.
Save screenshots of the ad, website, receipt and any emails or messages from the seller. Check your credit card or bank statement to see how the transaction appears.
If you believe the purchase was fraudulent, contact your card issuer or financial institution and explain what happened. Ask about disputing the transaction and whether your card information should be replaced.
If you created an account on the fake website and reused a password you use elsewhere, change that password anywhere you’ve used it. Unique passwords matter because a scammer who captures one password may try the same email-and-password combination on other accounts.
You can also report fraudulent ads to the social platform and report the scam to the FTC.
How McAfee Helps You Shop More Safely
Spotting every fake yourself is getting harder. Scammers can copy legitimate branding, product photos and storefront designs closely enough that a quick visual check isn’t always enough.
McAfee Scam Detector can help identify suspicious links, messages and websites and alert you when something may be a scam. Plus it has social media tools to help detect scams originating from your favorite platforms. That can provide another check when an attractive offer lands in a social message or sends you toward a questionable site.
Web Protection can also help warn you about risky websites as you browse, adding protection at the moment a convincing ad tries to move you away from the social platform and onto a malicious destination.
The goal isn’t to stop shopping the sales you see online. It’s to make sure the store getting your money is the store you intended to pay.
The post Is That TikTok Ad Legit? How to Spot Fake Ads on Social Media During Major Sales Events appeared first on McAfee Blog.
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
UK cyber bill targets AI users, not the vendors building it
Another Artifactory CVE under attack by AI agents or humans