Automotive · Online Marketplace · Vehicle listings, dealer subscriptions & financing · Consumer · USA
Online U.S. automotive marketplace connecting car buyers, dealers, and financing partners.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In mid-February 2026, ShinyHunters claimed to have breached CarGurus, Inc., a U.S. online automotive marketplace serving car buyers and dealers. Reporting attributes the intrusion to a voice-phishing (vishing) campaign that harvests SSO/MFA credentials to exfiltrate data from connected platforms. After a public extortion demand with a February 20 deadline went unpaid, the actor released the full dataset — over 12 million user records spanning account registrations back to 2006. CarGurus acknowledged a cybersecurity incident on February 21, said it secured the affected environment and opened a third-party investigation, and characterized the breach as limited in scope, though the published dataset (well beyond the initial 1.7M claim) suggests broader exposure. The data is now indexed and searchable across breach-intelligence platforms.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
12M+ records analyzed
CarGurus is a major U.S. automotive marketplace connecting car buyers, dealers, and financing partners. The platform supports vehicle listings and dealer subscriptions, buyer accounts, finance pre-qualification workflows, and dealer and corporate data integrations. If you created a CarGurus account, applied for auto financing through the platform, listed or inquired about a vehicle, or operated a dealership account, your data may be included.
Automotive marketplaces sit at the intersection of consumer identity and credit workflows. CarGurus holds buyer contact and account details, vehicle interest and inquiry history, finance pre-qualification application data, and dealer subscription and corporate records — a combination that pairs identity with financial intent.
CarGurus has stated that the affected environment was secured, an investigation is ongoing, the breach is 'limited in scope,' and that dealer feeds, APIs, and core systems remain operational. However, the publicly released dataset exceeds the initial 1.7M claim and includes over 12M user records, and scope assessments may evolve as the investigation continues.
This breach carries elevated risk because it pairs a full contact profile (email, phone, physical address, IP) with financial-intent context from auto-financing workflows, across nearly two decades of accounts. That combination raises the value of the data for fraud and targeting well beyond a typical contact-only leak.
Targeted phishing referencing vehicle interest • Auto-loan fraud attempts • Identity theft leveraging address and finance metadata • SIM-swap attempts where phone numbers are present • Credential stuffing against reused passwords.
This incident fits a broader campaign that compromises centralized identity (SSO) through social engineering rather than technical exploitation. For an affected individual the practical risk is targeted fraud: email, phone and home address paired with finance-application metadata support convincing auto-loan and 'dealer follow-up' pretexts, identity theft, and SIM-swap attempts. Because the records span nearly twenty years, exposure is durable and misuse may surface months later.
Attribution based on available breach intelligence.
Read the full threat-actor profile →Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request ConsultationIf you believe your information may be part of this breach,or want confirmation across other datasets,