Whipflip, a U.S. vehicle marketplace, was impacted by a ransomware attack by the Nightspire group. The attack was announced on February 28, 2026, the same day it was discovered. The threat actors have indicated potential data exfiltration and hinted at leaking sensitive data.
Specific data types exposed, the number of affected individuals, and the states affected have not yet been disclosed. Whether SSN, medical, or financial data was involved remains unclear, as does information on official breach notification letters or statements. This appears to be an ongoing incident with limited transparency, and details about the breach may not yet be publicly disclosed.