{"id":43899,"date":"2026-02-25T02:08:31","date_gmt":"2026-02-24T18:08:31","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/25\/cargurus-data-breach-exposes-information-of-12-4-million-accounts\/"},"modified":"2026-02-25T02:08:31","modified_gmt":"2026-02-24T18:08:31","slug":"cargurus-data-breach-exposes-information-of-12-4-million-accounts","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/25\/cargurus-data-breach-exposes-information-of-12-4-million-accounts\/","title":{"rendered":"CarGurus data breach exposes information of 12.4 million accounts"},"content":{"rendered":"\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/02\/24\/CarGurus.jpg\" width=\"1600\" alt=\"CarGurus data breach exposes information of 12.4 million accounts\"><\/p>\n<p>The ShinyHunters extortion group has published personal information in more than 12 million records&nbsp;allegedly stolen from CarGurus, a U.S.-based digital auto platform.<\/p>\n<p>CarGurus is a publicly traded automotive research and shopping company that operates in the U.S., Canada, and the U.K. Its website&nbsp;has an estimated 40 million monthly visitors and helps people find, compare, and contact sellers of new and used vehicles.<\/p>\n<p>On February 21, the threat group published a&nbsp;6.1GB&nbsp;archive containing 12.4 million records, saying it was from&nbsp;CarGurus. A day later, the&nbsp;HaveIBeenPwned (HIBP) data breach monitoring and alerting platform <a href=\"https:\/\/haveibeenpwned.com\/Breach\/CarGurus\" target=\"_blank\" rel=\"nofollow noopener\">added the dataset<\/a>, listing the following data types as compromised:<\/p>\n<div align=\"center\" style=\"width:98%; margin:0 auto; text-align:center; padding:4px; background:#f0f0f0; border:1px solid #ccc; border-radius:6px;\">  <a href=\"https:\/\/www.wiz.io\/lp\/ai-security-board-report-template?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q4_INB_FORM_AI-Security-Board-Report-Template&amp;sfcid=701Vh00000Wn7E1IAJ&amp;utm_term=FY27-bleepingcomputer-article-970x250&amp;utm_content=AI-Board-Report\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/w\/ai-security-board-report-template.jpg\" style=\"margin-top: 0px;\" alt=\"CarGurus data breach exposes information of 12.4 million accounts\"><\/a> <\/div>\n<ul>\n<li>Email addresses<\/li>\n<li>IP addresses<\/li>\n<li>Full names<\/li>\n<li>Phone numbers<\/li>\n<li>Physical addresses<\/li>\n<li>User account IDs<\/li>\n<li>Finance pre-qualification application data<\/li>\n<li>Finance application outcomes<\/li>\n<li>Dealer account details<\/li>\n<li>Subscription information<\/li>\n<\/ul>\n<p>Although CarGurus has not released an official statement disclosing a data breach and did not respond to BleepingComputer&#8217;s request for comment, it is important to note that HIBP&nbsp;attempts to confirm the validity\/authenticity of the leaked records before adding them.<\/p>\n<p>HIBP <a href=\"https:\/\/x.com\/haveibeenpwned\/status\/2025432800606957885\" target=\"_blank\" rel=\"nofollow noopener\">reports<\/a> that 70% of the leaked data was already on its database from previous incidents, so roughly 3.7 million records are fresh. Since the information is freely available for download, cybercriminals could take advantage of it for phishing attacks.<\/p>\n<div style=\"text-align:center\">\n<figure style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" height=\"406\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/February\/cargurus.jpg\" width=\"900\" alt=\"CarGurus data breach exposes information of 12.4 million accounts\"><figcaption><strong>ShinyHunters lists CarGurus as their victim<\/strong><br \/><em>Source: BleepingComputer<\/em><\/figcaption><\/figure>\n<\/div>\n<p>CarGurus users are advised to stay alert for potentially malicious communications and scam attempts leveraging the leaked information.<\/p>\n<p>The ShinyHunters data extortion group has been very active recently, claiming multiple attacks on large companies and leaking their data when negotiations reached a dead end.<\/p>\n<p>The most recent examples include Dutch telecommunications provider <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions\/\" target=\"_blank\" rel=\"nofollow noopener\">Odido<\/a>, ad tech firm <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\/\" target=\"_blank\" rel=\"nofollow noopener\">Optimizely<\/a>, fintech firm <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">Figure<\/a>, outerwear brand <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/canada-goose-investigating-as-hackers-leak-600k-customer-records\/\" target=\"_blank\" rel=\"nofollow noopener\">Canada Goose<\/a>, restaurant chain <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers\/\" target=\"_blank\" rel=\"nofollow noopener\">Panera Bread<\/a>, online dating company <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\/\" target=\"_blank\" rel=\"nofollow noopener\">Match Group<\/a>, and music streaming platform <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">SoundCloud<\/a>.<\/p>\n<p>The threat group typically uses social engineering, most commonly voice phishing, to breach organizations, directing victims to credential-harvesting pages that grant them access to SaaS platforms such as Salesforce, Okta, and Microsoft 365.<\/p>\n<p>Previous ShinyHunters campaigns also involved tricking employees into installing malicious OAuth applications that granted them API-level read access to customer data tables inside Salesforce instances.&nbsp;<\/p>\n<style> .ia_ad {     background-color: #f0f6ff;     width: 95%;     max-width: 800px;     margin: 15px auto;     border-radius: 8px;     border: 1px solid #d6ddee;     display: flex;     align-items: stretch;     padding: 0;     overflow: hidden; }  .ia_lef {     flex: 1;     max-width: 200px;     height: auto;     display: flex;     align-items: stretch; }  .ia_lef a {     display: flex;     width: 100%;     height: 100%; }   .ia_lef a img {     width: 100%;     height: 100%;          border-radius: 8px 0 0 8px;     margin: 0;     display: block; }  .ia_rig {     flex: 2;     padding: 10px;     display: flex;     flex-direction: column;     justify-content: center; }  .ia_rig h2 {     font-size: 17px !important;     font-weight: 700;     color: #333;     line-height: 1.4;     font-family: Georgia, \"Times New Roman\", Times, serif;     margin: 0 0 14px 0; }  .ia_rig p {     font-weight: bold;     font-size: 14px;     margin: 0 0 clamp(6px, 2vw, 14px) 0; }  .ia_button {     background-color: #FFF;     border: 1px solid #3b59aa;     color: black;     text-align: center;     text-decoration: none;     border-radius: 8px;     display: inline-block;     font-size: 16px;     font-weight: bold;     cursor: pointer;     padding: 10px 20px;     width: fit-content; }  .ia_button a {     text-decoration: none;     color: inherit;     display: block; }  @media (max-width: 600px) {     .ia_ad {         flex-direction: column;         align-items: center;     }      .ia_lef {         max-width: 100%;     }      .ia_lef a img {         border-radius: 8px 8px 0 0;     }       .ia_rig {         padding: 15px;         width: 100%;     }      .ia_button {         width: 100%; \tmargin: 0px auto;     } } <\/style>\n<div>\n<div>         <a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">             <img decoding=\"async\" src=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cargurus-data-breach-exposes-information-of-124-million-accounts\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-src=\"https:\/\/www.bleepstatic.com\/c\/t\/tines-in-art-square.jpg\" alt=\"CarGurus data breach exposes information of 12.4 million accounts\"><\/a>     <\/div>\n<div>\n<h2><a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">The future of IT infrastructure is here<\/a><\/h2>\n<p>Modern IT infrastructure moves faster than manual workflows can handle.<\/p>\n<p>In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.<\/p>\n<p>          <button><a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">Get the guide<\/a><\/button>     <\/div>\n<\/p><\/div>\n<div>\n<h3>Related Articles:<\/h3>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts\/\">Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts\/\">Data breach at fintech firm Figure affects nearly 1 million accounts<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/canada-goose-investigating-as-hackers-leak-600k-customer-records\/\">Canada Goose investigating as hackers leak 600K customer records<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers\/\">Panera Bread breach impacts 5.1 million accounts, not 14 million customers <\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\/\">Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match<\/a><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The ShinyHunters extortion group has published personal [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-43899","post","type-post","status-publish","format-standard","hentry","category--bleepingcomputer"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43899","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=43899"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43899\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=43899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=43899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=43899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}