ZeroHour
Troy Huntpublished ()ingested

Troy Hunt

infoData breachimportance 30
AI summary · glm-5.3-flash

Troy Hunt warns ShinyHunters' Carhartt breach claim of 50GB and millions of records is unverified, while Sri Lanka joins Have I Been Pwned.

Troy Hunt's blog roundup centers on a cautionary tale about data breach claims: ShinyHunters claims it compromised Carhartt and stole over 50GB of compressed data containing millions of customer records, employee information and loyalty data, but Hunt stresses criminal claims require verification. The feed also covers Sri Lanka CERT becoming the 48th government onboarded to Have I Been Pwned's free government monitoring service, following Nepal as the 47th. Other commentary addresses ransomware economics, Brinks Home's lawyer-heavy extortion FAQ, and the Origin Energy breach in Australia.

  • ShinyHunters claims 50GB compressed Carhartt data with millions of customer records; verification advised
  • Sri Lanka CERT becomes 48th government using HIBP's free breach monitoring service
  • Hunt commentary on ransomware: young crews profit while litigation constrains breached firms
  • Origin Energy breach shows disputes over reporting and potential payment or deletion agreements
Full article987 words · extracted from troyhunt.com · click to collapse

Sponsored by:

Hi, I'm Troy Hunt, I write this blog, run "Have I Been Pwned" and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals

Weekly Update 520: The Unscripted Edition

07 September 2026

I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it's chosen this week is spot on: that Lockwood ES2100 electric strike looks like the perfect solution for my first fully installed Ubiquiti Access door lock. Having the door position sensor built in really simplifies things, and hopefully Ubiquiti will later add suppor...

Weekly Update 519: Breaches & Data Integrity

02 September 2026

It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers keep dumping more data too! Oh, and still finalising all the IoT door lock stuff, along with mapping out all the cameras, APs and door hubs in Ubiquiti's designer to make sure we don't miss anything there. It's ordered chaos... just....

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

26 August 2026

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber Alert ‼️ 🇺🇸US - 𝗖𝗮𝗿𝗵𝗮𝗿𝘁𝘁 ShinyHunters hacking group claims to have compromised Carhartt and allegedly stolen more than 50 GB of compressed data containing millions of customer records, employee information, customer metadata, loyalty-related information, and…...

Weekly Update 518: IoT Doorlock Nirvana with UniFi

24 August 2026

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets: 1. Main power (never have to rely on batteries) 2. Fail-secure (needs to remain locked on power outage) 3. Local control (no cloud latency to contend with) 4. Manual override ("the house is on fire, let me out") Which is exactly what we have here in this week's vid (and sorry about the sec...

Welcoming the Sri Lankan Government to Have I Been Pwned

23 August 2026

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches. As with the other governments already using the service, this is about using breach data for good: giving national cyber teams practical visibility into their public sector exposure and supporting their wor...

Weekly Update 517: Cyber Ransoms

18 August 2026

The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a truckload of money but can't spend it without getting caught and the companies they breach rapidly get piled onto by class action lawyers that keeps them busy fighting and being cautious not to say anyting to customers lest that then gets used against them in litigation. That's mostly it; more in thi...

Weekly Update 516: Live From Vietnam

12 August 2026

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to actually answer most of the questions?! Being conscious that they're the target of criminal extortion and are genuinely the victims here, I still struggle to grasp how simple incident response questions can be so lawyer-speaked as to remove all se...

Welcoming the Nepalese Government to Have I Been Pwned

03 August 2026

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in a new data breach. This is precisely what the HIBP government service was built for: helping national cyber teams strengthen threat monitoring and in...

Weekly Update 515: Seeking Caffeine Utopia

03 August 2026

Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy, no, it's just not the same. It's not the same ubiquity of high-quality coffee shops and passion for what many view as the art of making espresso-based drinks. There's comparably little tolerance for the likes of Starbucks (who have not fared well in Australia), and other mass-pro...

Weekly Update 514: This Week in Data Breaches

26 July 2026

The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn't respond when I tried to report it", and now news that the two parties have "come to an agreement". Maybe money was paid, or maybe Origin made some promises to restrain the hounds if commitments about data deletion were made. But both outcomes, of course, provide no guaran...

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.troyhunt.com/