CarGurus Data Breach

Automotive · Online Marketplace · Vehicle listings, dealer subscriptions & financing · Consumer · USA

CarGurus Data Breach (2026): 12M+ Customer Records Exposed in ShinyHunters SSO Campaign

Online U.S. automotive marketplace connecting car buyers, dealers, and financing partners.

Confirmed by ObscureIQ Intelligence
Breach Risk Index i
64/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
12M+Records
2026Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
FinancialFinance pre-qualification data
Classification Tags
ShinyHuntersVoice phishing (vishing) / SSOAutomotiveOnline MarketplaceDirect Customers2026

Breach Summary

In mid-February 2026, ShinyHunters claimed to have breached CarGurus, Inc., a U.S. online automotive marketplace serving car buyers and dealers. Reporting attributes the intrusion to a voice-phishing (vishing) campaign that harvests SSO/MFA credentials to exfiltrate data from connected platforms. After a public extortion demand with a February 20 deadline went unpaid, the actor released the full dataset — over 12 million user records spanning account registrations back to 2006. CarGurus acknowledged a cybersecurity incident on February 21, said it secured the affected environment and opened a third-party investigation, and characterized the breach as limited in scope, though the published dataset (well beyond the initial 1.7M claim) suggests broader exposure. The data is now indexed and searchable across breach-intelligence platforms.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

12M+ records analyzed

About CarGurus

CarGurus is a major U.S. automotive marketplace connecting car buyers, dealers, and financing partners. The platform supports vehicle listings and dealer subscriptions, buyer accounts, finance pre-qualification workflows, and dealer and corporate data integrations. If you created a CarGurus account, applied for auto financing through the platform, listed or inquired about a vehicle, or operated a dealership account, your data may be included.

Why They Hold Your Data

Automotive marketplaces sit at the intersection of consumer identity and credit workflows. CarGurus holds buyer contact and account details, vehicle interest and inquiry history, finance pre-qualification application data, and dealer subscription and corporate records — a combination that pairs identity with financial intent.

Recent Developments

CarGurus has stated that the affected environment was secured, an investigation is ongoing, the breach is 'limited in scope,' and that dealer feeds, APIs, and core systems remain operational. However, the publicly released dataset exceeds the initial 1.7M claim and includes over 12M user records, and scope assessments may evolve as the investigation continues.

Data Points Exposed

9 verified field types
Account creation date
Dealer / corporate records
Email address
Finance pre-qualification data High
Full name
IP address
Phone number
Physical address High
User UUID / internal ID

Breach Impact

This breach carries elevated risk because it pairs a full contact profile (email, phone, physical address, IP) with financial-intent context from auto-financing workflows, across nearly two decades of accounts. That combination raises the value of the data for fraud and targeting well beyond a typical contact-only leak.

Exploitation & Downstream Threats

Targeted phishing referencing vehicle interest • Auto-loan fraud attempts • Identity theft leveraging address and finance metadata • SIM-swap attempts where phone numbers are present • Credential stuffing against reused passwords.

Principal Risk Advisory

What this means for a principal

This incident fits a broader campaign that compromises centralized identity (SSO) through social engineering rather than technical exploitation. For an affected individual the practical risk is targeted fraud: email, phone and home address paired with finance-application metadata support convincing auto-loan and 'dealer follow-up' pretexts, identity theft, and SIM-swap attempts. Because the records span nearly twenty years, exposure is durable and misuse may surface months later.

What You Should Do

  1. Change your CarGurus password immediately, along with any account that reuses similar credentials.
  2. Enable multi-factor authentication — email accounts first, then financial platforms.
  3. Watch for auto-loan scams: financing-approval messages, 'dealer follow-up' emails, and refund or rebate offers.
  4. Monitor your credit, especially if you submitted finance pre-qualification data.
  5. Stay alert for long-term abuse — the data spans nearly 20 years, so attacks may surface months later.

How ObscureIQ Can Help

  1. Cross-reference your exposure across automotive, finance, and identity datasets.
  2. Evaluate whether your financing or IP metadata increases targeting risk.
  3. Harden executive and dealer-facing accounts against the same vishing/SSO playbook.
S
Threat Actor: ShinyHunters
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation
Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom

Contact ObscureIQ for a free breach impact check.

If you believe your information may be part of this breach,or want confirmation across other datasets,

We use a multi-layered intelligence stack, combining public and restricted dark-web sources, to confirm whether your data is in circulation.