CarGurus
Incident posture
Timeline
Summary
CarGurus experienced a cybersecurity incident in which the hacking group ShinyHunters published a file containing approximately 12.4 million user records, including names, phone numbers, email addresses, physical addresses and finance pre‑qualification details; about 3.7 million of those records were newly exposed while the remainder had appeared in earlier breaches. The company stated it secured the affected environment, engaged a leading cybersecurity firm to investigate, and found the activity contained and limited in scope with no evidence that dealer data feeds, APIs or core systems were compromised. ShinyHunters, known for leaking data after unsuccessful ransom attempts, typically gains access through social engineering tactics such as phishing calls or fake login pages.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 21, 2026, the hacking group ShinyHunters published a 6.1GB file that it claimed contained 12.4 million user records taken from CarGurus, the U.S.-based auto research and shopping platform. The group asserted that the data included names, phone numbers, email addresses, physical addresses, and finance pre‑qualification details. Have I Been Pwned later added the dataset to its breach database, reporting that the exposed information also comprised IP addresses, full names, account IDs, dealer details, subscription information, and finance pre‑qualification application data along with outcomes. According to Have I Been Pwned, approximately 70% of the records had already appeared in previous breaches, leaving roughly 3.7 million records newly exposed. CarGurus operates in the United States, Canada, and the United Kingdom and attracts an estimated 40 million monthly visitors to its website for vehicle comparisons, seller contacts, and financing applications.
The leaked data provides detailed personal profiles tied to car shopping and financing activity, which could be valuable to criminals seeking to conduct identity theft or fraud. Although most of the information was previously available, the addition of 3.7 million new records increases the potential risk for affected individuals. CarGurus has not issued an official statement confirming the breach and did not respond to media requests for comment. A CarGurus spokesperson stated that the company recently experienced a cybersecurity incident, promptly secured the affected environment, and is working with a leading cybersecurity firm to investigate. The spokesperson added that, based on the investigation to date, the activity has been believed to be contained and limited in scope, with no indications that dealer data feeds, APIs, or core systems or products used by consumers or dealer partners have been compromised, and that services remain fully operational without interruption.
ShinyHunters is known for leaking company data when ransom negotiations fail and typically gains access through social engineering tactics such as phone calls or fake login pages that trick employees into handing over credentials. In some cases, the group has convinced employees to install malicious applications that grant access to cloud systems storing customer data, allowing attackers to read stored information without triggering obvious alarms. The group has previously claimed attacks on major brands across telecom, retail, finance, and tech sectors. CarGurus’s response has focused on securing the environment, engaging external investigators, and asserting containment of the incident while maintaining normal operations.
Sources
Sources available to members: 1 source.