CarGurus Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
CarGurus disclosed on February 14, 2026 that a data breach had exposed the email addresses, IP addresses, names, phone numbers, and physical addresses of 12.5 million individuals. People who have interacted with the platform should check whether their information was affected and consider changing passwords or monitoring accounts for suspicious activity.
What happened
CarGurus was targeted in an intrusion that the group ShinyHunters claimed responsibility for. After an extortion attempt, the actors published multiple files containing more than 12 million email addresses. The material also encompassed user account ID mappings, finance pre-qualification application data, dealer account and subscription information, names, phone numbers, physical addresses, IP addresses and auto finance application outcomes. The breach was first reported on 14 February 2026. No further technical details on the initial access method or the precise timeline of the intrusion have been disclosed.
Who is shinyhunters?
ShinyHunters is a threat actor group that has repeatedly claimed responsibility for intrusions at large online services. Public reporting has linked the group to tactics that involve initial network access, data exfiltration, extortion demands and eventual public release of material when payment is not received. The group has appeared on data-leak forums and similar platforms in connection with prior incidents involving technology and consumer-service companies. In this case, the attribution rests on the group’s own statements and the subsequent publication of the CarGurus files.
About CarGurus
CarGurus operates an online platform that connects consumers with vehicle listings, dealer inventory and financing options. Companies in this sector routinely collect and store contact details, account identifiers and information generated during pre-qualification or financing processes. A breach at such a service therefore touches both individual consumers and the dealer networks that rely on the platform for customer leads and transaction support.
The information in question
The published files contain email addresses, names, phone numbers, physical addresses and IP addresses. Additional records include user account ID mappings, finance pre-qualification application data, dealer account and subscription information, and auto finance application outcomes. The exact scope of every field within the released files remains tied to the material posted by the actors; organisations of this type commonly hold further details such as login credentials or payment information, but no confirmation has been provided that those categories were included.
The real-world impact
Individuals whose email addresses, phone numbers and physical addresses appear in the data may receive increased volumes of unsolicited contact or targeted phishing attempts. Finance-related records could be used to infer credit-seeking behaviour or to support social-engineering efforts against financial institutions. For CarGurus, the incident adds to the operational burden of breach notification, customer support and any subsequent regulatory scrutiny. No public statements have quantified financial losses or legal exposure at this stage.
Were you affected?
Users can check whether their email address appears in known breach datasets through free public exposure scanners. Practical next steps include monitoring email and phone accounts for unexpected messages, reviewing statements from any financial institutions linked to past CarGurus activity, and considering the use of unique passwords or password-manager alerts for any accounts that may share credentials. Organisations that held data with CarGurus should also review their own logging for signs of follow-on activity.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Vimeo Data Breach (2026)Woflow Data Breach (2026)Sysco Data Breach (2026)American Tower Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the CarGurus Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.