CarGurus Data Breach Exposes 12.5 Million Accounts; Here’s What Hackers Got

CarGurus Data Breach Exposes 12.5 Million Accounts; Here’s What Hackers Got


If you’ve ever compared a car price, searched for a vehicle or checked your financing options on CarGurus, your information may now be sitting in a file that criminals have already distributed online.

The extortion group ShinyHunters published a 6.1GB archive on February 21, claiming it contained roughly 12.4 million records stolen from CarGurus. “CarGurus” appears in Have I Been Pwned’s breach database with a 12.5 million pwn count, with the service identifying the incident as a verified breach.

That number is attention-grabbing. But it isn’t the most important part of the breach. The more worrying detail is what some of those records reveal: not just who you are and how to contact you, but whether you were recently looking for an auto loan.

The Data Goes Beyond Email

“Names, phone numbers, physical addresses, IP addresses, email addresses, user account ID mappings, dealer account and subscription information, and finance pre-qualification application data and outcomes” are among the data types listed by Have I Been Pwned for the CarGurus breach. That last category changes the risk.

CarGurus allows shoppers to apply for auto-financing pre-qualification through its platform. So for some affected users, the leaked record doesn’t simply tell a scammer who you are. It can indicate that you were actively shopping for a car loan.

A scammer with an email address can send a generic phishing message. A scammer with your name, phone number, address and evidence that you recently sought auto financing can make the same message feel remarkably specific.

12.5 Million Isn’t 12.5 Million New Victims

The headline number needs an important correction. Have I Been Pwned found that roughly 70% of the email addresses in the dataset had already appeared in previous, unrelated breaches. That means about 3.7 million records represent newly exposed email addresses, while the rest were already circulating elsewhere.

That does not make the CarGurus breach harmless. It does mean that saying 12.5 million people have suddenly become newly exposed would be misleading.

For many users, this breach adds another piece of information to a profile that criminals may already possess. For the newly exposed group, however, the CarGurus data can provide an entirely new layer of context around someone’s identity and financial intentions.

The Attack May Have Started With A Phone Call

Security researchers and other reporting have attributed the breach to voice phishing, or vishing. Attackers reportedly impersonated IT support personnel and contacted CarGurus employees by phone, attempting to obtain single sign-on codes that could be used to bypass multi-factor authentication.

If that account is accurate, the attackers didn’t need to discover a sophisticated software vulnerability. They convinced a person to hand over access.

That fits a broader pattern associated with ShinyHunters, which has been linked to multiple breaches involving social engineering. “We have completed our investigation with the assistance of a leading independent cybersecurity firm,” CarGurus said in its May 2026 incident update, adding that the incident was “limited in scope and contained.”

What CarGurus Says Wasn’t Hit

“Our investigation, corroborated by a 3rd party investigation, concluded that no dealer data feeds, APIs, dealer CRMs, core systems or products used by our dealer partners or consumers have been compromised,” CarGurus said.

There is no public evidence from the reporting that bank-account numbers or payment-card credentials were included in the exposed dataset. The financial information identified by Have I Been Pwned concerns pre-qualification applications and their outcomes, not payment credentials.

So this is not a case where the available evidence supports saying that 12.5 million people’s bank accounts or credit cards were stolen. The risk is different: criminals may have enough personal and behavioral information to make their next scam far more convincing.

What You Should Do Now

If you’ve used CarGurus, be especially skeptical of unexpected calls, texts or emails mentioning CarGurus, a recent vehicle search, financing or account verification. Don’t click a link or call back a number supplied in an unsolicited message. If something appears legitimate, find CarGurus’ contact information independently and make the call yourself.

“Review these breaches to see what personal information was compromised and take appropriate action, such as changing passwords,” Have I Been Pwned advises users. You don’t need to assume your identity has been stolen. You do need to assume that information about you may be available to someone who wants to make a convincing scam look real.

The 12.5 million figure makes this breach sound enormous. The more consequential fact is what the database can tell a criminal about a particular person. A name and email address are useful. A name, phone number, home address and evidence that someone recently sought auto financing are considerably more useful.



Source link

Posted in

Liam Redmond

As an editor at Forbes Europe, I specialize in exploring business innovations and entrepreneurial success stories. My passion lies in delivering impactful content that resonates with readers and sparks meaningful conversations.

Leave a Comment