CarMax 2026 Data Breach
Automotive · Used Vehicle Retail · Omnichannel retail and financing · Consumer · USA
CarMax Circulating Data Breach (2026): 452K Customer Contact Records Exposed via Salesforce Campaign
U.S. used vehicle retailer with omnichannel car buying, selling and financing.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Breach Summary
CarMax customer data was taken in a 2025 compromise of the company's hosted Salesforce environment, part of the ShinyHunters / Scattered Lapsus$ Hunters extortion campaign against Salesforce tenants. A verified sample of 451,994 records was released on 3 October 2025, and the full corpus was published in January 2026 after CarMax declined to pay. The circulating dataset contains names, email addresses, phone numbers and physical addresses, together with CRM metadata and marketing-consent flags consistent with Salesforce lead and account tables. Have I Been Pwned loaded the corpus on 20 February 2026 at 431,400 unique email addresses; this is the same dataset measured on a different basis, not a second incident. No payment data or Social Security numbers appear in the released sample. The actor's forum post additionally claims dates of birth and fax numbers, neither of which is present in the indexed circulating set and both of which remain unverified.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
431,400 records analyzed
About CarMax
CarMax is the largest used-vehicle retailer in the United States, operating an omnichannel model that lets customers browse, finance, buy and sell vehicles across hundreds of physical stores and its e-commerce platform. The publicly traded company built its position on fixed, no-haggle pricing, standardised vehicle inspections and in-house financing through CarMax Auto Finance, positioning itself as a consumer-friendly alternative to conventional dealership networks.
Why They Hold Your Data
Used-vehicle retailers hold customer identity and contact records, trade-in and appraisal history, purchase and service records, and financing application data. Where sales and marketing run through a hosted CRM, that platform typically also holds lead records, campaign membership and marketing-consent flags for customers and prospects who never completed a purchase.
Recent Developments
CarMax has continued shifting toward online-completed purchases while navigating a used-vehicle market marked by elevated prices and softer consumer demand. The company has not issued a detailed public statement about the exposure. Its appearance in the Salesforce extortion campaign places it alongside dozens of other victim brands from the same operation, several of which also appear in this corpus.
Data Points Exposed
Breach Impact
CarMax has not published a detailed statement, and no notification programme or regulatory response is documented in public sources as of early 2026, which leaves affected customers without an authoritative channel to confirm whether they are included. Because the data was taken from a hosted CRM rather than CarMax's own systems, remediation sits partly with a platform the company does not control, and the incident carries the reputational cost of a breach it could not have contained by hardening its own infrastructure. Publication following a refused ransom removed any prospect of containment: the corpus is now mirrored, repackaged and redistributed rather than held privately, so exposure is permanent rather than time-limited.
Exploitation & Downstream Threats
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
What this means for a principal
The confirmed field set is a complete contact profile — name with email, phone and home address — and contains no credential or payment material, so direct account takeover and card fraud are not the pathway here. The realistic risk is targeted impersonation. Customers who recently financed or sold a vehicle are credible marks for dealership, service-reminder, title-transfer and financing-follow-up pretexts, and the marketing-consent flags let an attacker mimic CarMax's own contact cadence closely enough to defeat the usual "was I expecting this" test. Home address alongside an inferable recent vehicle purchase supports physical targeting and vehicle-theft reconnaissance, a narrower but more serious pathway than phishing. Risk rises materially if the actor's date-of-birth claim proves accurate, since name, address and date of birth together move this record out of contact data and into identity-proofing territory.
What You Should Do
- Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
- Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
- Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.
How ObscureIQ Can Help
- Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
- Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
- ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
Protect Yourself
Check If You're Affected
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
High-Risk? Get an Exposure Audit
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation