CarGurus, Inc., an online automotive marketplace, experienced a data breach claimed by the ShinyHunters group around February 13, 2026, and disclosed in February 2026. The company confirmed a cybersecurity incident and is investigating, but a detailed official breach notification statement or letter has not been publicly issued. The breach involved vishing for SSO codes.
The breach is reported to have affected approximately 12.4-12.5 million user accounts, with an additional 1.7 million corporate records reportedly stolen. Exposed data types include names, email addresses, phone numbers, physical addresses, IP addresses, user account IDs, finance pre-qualification application data, finance application outcomes, dealer account details, subscription information, and internal corporate data. No SSN, medical, or direct financial data like payment details or passwords have been reported as compromised. The exact number of affected individuals and specific details about the compromised data types may evolve as the investigation progresses.
Details about this data breach can continue to emerge, and official notices to affected individuals may be delayed.