Quick Facts
- ShinyHunters hacking group compromised 12.5 million CarGurus accounts through voice phishing attacks targeting employees
- Hackers published 6.1GB archive containing customer names, emails, phone numbers, physical addresses, and auto finance data
- Attack is part of broader campaign hitting 15 companies this year, including Harvard, Panera Bread, and SoundCloud
Automotive marketplace CarGurus confirmed a cybersecurity incident that exposed personal data from 12.5 million customer accounts. The breach notification service Have I Been Pwned reported the compromise on February 22, following the public release of a 6.1GB data archive by the ShinyHunters hacking group.
The stolen data includes customer names, email addresses, phone numbers, physical addresses, and IP addresses. The archive also contains auto finance application outcomes and dealer account information. Have I Been Pwned noted that 70% of the leaked data was previously available from other breaches, meaning approximately 3.7 million records represent fresh exposure.
ShinyHunters used voice phishing tactics to execute the attack, according to security researchers. The group impersonated IT support staff and contacted CarGurus employees by phone. They tricked employees into providing Single Sign-On codes, bypassing multi-factor authentication and gaining access to internal systems.
The attack began around February 13, 2026. The hackers issued a ransom demand with a February 20 deadline before publishing the data publicly. Security researcher Alon Gal from Hudson Rock confirmed the techniques match ShinyHunters’ known methods.
This breach represents the 15th attack claimed by ShinyHunters this year. Recent victims include Harvard University, University of Pennsylvania, Panera Bread (5.1 million accounts), Match Group properties, Betterment (1.4 million accounts), and SoundCloud (29.8 million accounts).
CarGurus acknowledged the incident in a statement to media outlets. The company said it secured the affected environment and launched an investigation with a cybersecurity firm. CarGurus maintains its systems remain fully operational and that core dealer services were not compromised.
The automotive sector faces increasing targeting by cybercriminals. Have I Been Pwned reported a CarMax breach last month affecting 431,000 email addresses. Criminal groups focus on automotive platforms because they contain valuable buying intent and finance data.
CarGurus stock (CARG) gained 4.56% despite the breach disclosure. However, DA Davidson analysts noted the incident creates reputational and regulatory risks. Oppenheimer lowered its price target from $40 to $38 while maintaining an Outperform rating.
Security experts recommend companies adopt phishing-resistant multi-factor authentication like FIDO2 hardware keys. As AI-powered deepfake voices make voice phishing more effective, traditional MFA methods become vulnerable to sophisticated social engineering attacks.
Read more: CarGurus data breach affects 12.5 million accounts
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
