CSIDB logo
Incident

CarGurus

Incident posture

Attack window
Feb 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-14 01:54

Linked entities

Victim
CarGurus
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Undetermined

Summary

CarGurus experienced a cybersecurity incident in which the hacking group ShinyHunters published a file containing approximately 12.4 million user records, including names, phone numbers, email addresses, physical addresses and finance pre‑qualification details; about 3.7 million of those records were newly exposed while the remainder had appeared in earlier breaches. The company stated it secured the affected environment, engaged a leading cybersecurity firm to investigate, and found the activity contained and limited in scope with no evidence that dealer data feeds, APIs or core systems were compromised. ShinyHunters, known for leaking data after unsuccessful ransom attempts, typically gains access through social engineering tactics such as phishing calls or fake login pages.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 21, 2026, the hacking group ShinyHunters published a 6.1GB file that it claimed contained 12.4 million user records taken from CarGurus, the U.S.-based auto research and shopping platform. The group asserted that the data included names, phone numbers, email addresses, physical addresses, and finance pre‑qualification details. Have I Been Pwned later added the dataset to its breach database, reporting that the exposed information also comprised IP addresses, full names, account IDs, dealer details, subscription information, and finance pre‑qualification application data along with outcomes. According to Have I Been Pwned, approximately 70% of the records had already appeared in previous breaches, leaving roughly 3.7 million records newly exposed. CarGurus operates in the United States, Canada, and the United Kingdom and attracts an estimated 40 million monthly visitors to its website for vehicle comparisons, seller contacts, and financing applications.

The leaked data provides detailed personal profiles tied to car shopping and financing activity, which could be valuable to criminals seeking to conduct identity theft or fraud. Although most of the information was previously available, the addition of 3.7 million new records increases the potential risk for affected individuals. CarGurus has not issued an official statement confirming the breach and did not respond to media requests for comment. A CarGurus spokesperson stated that the company recently experienced a cybersecurity incident, promptly secured the affected environment, and is working with a leading cybersecurity firm to investigate. The spokesperson added that, based on the investigation to date, the activity has been believed to be contained and limited in scope, with no indications that dealer data feeds, APIs, or core systems or products used by consumers or dealer partners have been compromised, and that services remain fully operational without interruption.

ShinyHunters is known for leaking company data when ransom negotiations fail and typically gains access through social engineering tactics such as phone calls or fake login pages that trick employees into handing over credentials. In some cases, the group has convinced employees to install malicious applications that grant access to cloud systems storing customer data, allowing attackers to read stored information without triggering obvious alarms. The group has previously claimed attacks on major brands across telecom, retail, finance, and tech sectors. CarGurus’s response has focused on securing the environment, engaging external investigators, and asserting containment of the incident while maintaining normal operations.

Sources

Sources available to members: 1 source.

CSIDB