CarGurus data breach (2026): what was exposed and what to do

Updated Corrections

September 28, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

CarGurus data breach (2026): what was exposed and what to do

By Delist Editorial Team · Updated September 28, 2026 · Corrections

September 28, 2026

What happened

CarGurus, a U.S.-based automotive research and shopping marketplace (also operating in Canada and the U.K.), appeared in public breach reporting in February 2026 after the ShinyHunters extortion group published a large archive they said came from the company.

BleepingComputer reported on February 24, 2026, that on February 21, 2026, the group published a ~6.1 GB archive containing about 12.4 million records. Have I Been Pwned (HIBP) added the dataset around February 22, 2026, listing 12.5 million affected accounts / email addresses and describing finance-application and dealer-related fields alongside contact data. HIBP attempts to validate authenticity before listing; its count is a researcher/monitoring census, not necessarily a company AG filing. SecurityWeek and Cybernews independently covered the same publication window and HIBP field list.

On February 22, 2026, CarGurus published a dealer-facing update, and on May 1, 2026, a Cybersecurity Incident Information page stated the company had completed its investigation with an independent cybersecurity firm, described the incident as limited in scope and contained, and said investigations concluded that dealer data feeds, APIs, dealer CRMs, core systems, or products used by dealer partners or consumers were not compromised. That dealer notice focuses on dealer/partner impact and does not replace HIBP’s consumer contact/finance-field inventory for people whose emails appear in the published archive—prefer any individual notice you receive.

Sources

What data was exposed

Per HIBP’s CarGurus breach entry and press summaries (BleepingComputer, SecurityWeek, Cybernews), compromised data types included:

  • Email addresses (~12.5M on HIBP)
  • Full names
  • Phone numbers
  • Physical addresses
  • IP addresses
  • User account IDs / account ID mappings
  • Finance pre-qualification application data
  • Finance application outcomes
  • Dealer account details / subscription information (as listed by HIBP/press)

Exact fields vary by record. HIBP noted a large share of emails were already known from prior breaches; that does not reduce the contact/finance-field risk for phishing. CarGurus’ May 2026 dealer update says dealer passwords were not compromised and that there was no evidence user accounts were at risk—still change reused passwords and watch for auto-finance phishing.

Breach details

Detail Value
Breach name CarGurus (actor publication / HIBP listing; company dealer investigation update May 2026)
Date Actor publication ~February 21, 2026; HIBP added ~February 22, 2026; company investigation wrap described May 1, 2026
Disclosed Public leak + HIBP/press February 2026; dealer incident page Feb 22 / May 1, 2026
Accounts affected ~12.4M records (BleepingComputer / actor archive); 12.5M accounts on HIBP
Domain cargurus.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by CarGurus; it reflects a publicly reported security incident.

For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.

What to do now

Based on the contact and auto-finance fields named by HIBP/press:

  • Be alert for phishing that references a car you viewed, a “pre-qualification,” or a dealer follow-up—verify through CarGurus or the dealer using contacts you look up yourself.
  • Change passwords on CarGurus and any reuse accounts; enable MFA where available (prefer authenticator apps over SMS when possible—CarGurus’ dealer FAQ makes the same point).
  • Watch for loan or credit offers you did not start; consider a credit freeze if you submitted sensitive finance-application data and are concerned. See how to freeze your credit.
  • Treat unsolicited “CarGurus breach settlement / refund” emails as likely scams (CarGurus’ dealer FAQ makes the same point for dealer phishing).
  • Keep any official notice if CarGurus or a regulator later mails one.

Short checklist: first 48 hours after a data breach.

How this shows up on the open web

Names, emails, phones, and physical addresses are core people-search building blocks. After an auto-shopping leak, messages that cite a vehicle, zip code, or “finance approval” can sound tailored. Run a free open-web scan to see which people-search and broker sites expose your personal data. Delist does not claim to have scanned CarGurus systems or this dump, and it does not remove dump copies.

Related reading: 700Credit (2025) (dealer-credit identity rail) and AssuranceAmerica (2026).

My email showed up in the CarGurus HIBP listing—what first?

Watch for auto-finance and dealer phishing; change reused passwords; consider a credit freeze if you submitted finance pre-qual data. Company dealer update says core dealer systems were not compromised—still treat the published contact fields seriously.

Frequently asked questions

How many CarGurus accounts were affected?

BleepingComputer described a ~12.4 million-record archive published around February 21, 2026. Have I Been Pwned listed 12.5 million affected accounts. Those are HIBP/press figures—not a Delist count.

What finance-related fields were listed?

HIBP’s entry and press summaries list finance pre-qualification application data, finance application outcomes, and dealer/subscription-related details alongside names, emails, phones, addresses, and IP addresses.

Did CarGurus publish an official notice?

Yes—a dealer-facing Cybersecurity Incident Information page (updated May 1, 2026) says the investigation found the incident limited/contained and that dealer feeds/APIs/core systems were not compromised. That does not erase HIBP’s consumer contact/finance-field inventory for emails in the published archive. Prefer any individual notice you receive.

Can Delist remove my CarGurus row from the leak?

No. Delist does not scrub marketplace systems or breach dumps. A free scan checks open-web people-search and broker listings only.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.