LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › CarGurus Data Breach (2026)

HIGH severityConfirmedHow we verify

CarGurus Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 14, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

CarGurus Data Breach (2026)

Reported February 14, 2026. Approximately 12.5M people affected.

HIGH
Severity
12.5M
People affected
5
Data types exposed
February 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

CarGurus disclosed on February 14, 2026 that a data breach had exposed the email addresses, IP addresses, names, phone numbers, and physical addresses of 12.5 million individuals. People who have interacted with the platform should check whether their information was affected and consider changing passwords or monitoring accounts for suspicious activity.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
12.5M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In February 2026, a data breach at the automotive marketplace CarGurus exposed information belonging to 12.5 million individuals. The incident was attributed to the threat actor ShinyHunters, who published the material online after an attempted extortion. The exposed records include email addresses, names, phone numbers, physical addresses and IP addresses, along with details tied to user accounts, finance applications and dealer subscriptions. The scale of the release means that a substantial portion of CarGurus users now face the possibility that their contact and account information is circulating among unknown parties.

What happened

CarGurus was targeted in an intrusion that the group ShinyHunters claimed responsibility for. After an extortion attempt, the actors published multiple files containing more than 12 million email addresses. The material also encompassed user account ID mappings, finance pre-qualification application data, dealer account and subscription information, names, phone numbers, physical addresses, IP addresses and auto finance application outcomes. The breach was first reported on 14 February 2026. No further technical details on the initial access method or the precise timeline of the intrusion have been disclosed.

Who is shinyhunters?

ShinyHunters is a threat actor group that has repeatedly claimed responsibility for intrusions at large online services. Public reporting has linked the group to tactics that involve initial network access, data exfiltration, extortion demands and eventual public release of material when payment is not received. The group has appeared on data-leak forums and similar platforms in connection with prior incidents involving technology and consumer-service companies. In this case, the attribution rests on the group’s own statements and the subsequent publication of the CarGurus files.

About CarGurus

CarGurus operates an online platform that connects consumers with vehicle listings, dealer inventory and financing options. Companies in this sector routinely collect and store contact details, account identifiers and information generated during pre-qualification or financing processes. A breach at such a service therefore touches both individual consumers and the dealer networks that rely on the platform for customer leads and transaction support.

The information in question

The published files contain email addresses, names, phone numbers, physical addresses and IP addresses. Additional records include user account ID mappings, finance pre-qualification application data, dealer account and subscription information, and auto finance application outcomes. The exact scope of every field within the released files remains tied to the material posted by the actors; organisations of this type commonly hold further details such as login credentials or payment information, but no confirmation has been provided that those categories were included.

The real-world impact

Individuals whose email addresses, phone numbers and physical addresses appear in the data may receive increased volumes of unsolicited contact or targeted phishing attempts. Finance-related records could be used to infer credit-seeking behaviour or to support social-engineering efforts against financial institutions. For CarGurus, the incident adds to the operational burden of breach notification, customer support and any subsequent regulatory scrutiny. No public statements have quantified financial losses or legal exposure at this stage.

Were you affected?

Users can check whether their email address appears in known breach datasets through free public exposure scanners. Practical next steps include monitoring email and phone accounts for unexpected messages, reviewing statements from any financial institutions linked to past CarGurus activity, and considering the use of unique passwords or password-manager alerts for any accounts that may share credentials. Organisations that held data with CarGurus should also review their own logging for signs of follow-on activity.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCarGurus security record
64/100
DoxxScan™ · Moderate doxx risk
D- 49Very poor record

1 reported incident on record.

See CarGurus’s full breach history →

More recent breaches

Vimeo Data Breach (2026)April 28, 2026Woflow Data Breach (2026)March 4, 2026Sysco Data Breach (2026)June 15, 2026American Tower Data Breach (2026)June 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the CarGurus Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram