CarGurus data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
CarGurus data breach (2026): what was exposed and what to doBy Delist Editorial Team · Updated September 28, 2026 · Corrections
September 28, 2026
What happened
CarGurus, a U.S.-based automotive research and shopping marketplace (also operating in Canada and the U.K.), appeared in public breach reporting in February 2026 after the ShinyHunters extortion group published a large archive they said came from the company.
BleepingComputer reported on February 24, 2026, that on February 21, 2026, the group published a ~6.1 GB archive containing about 12.4 million records. Have I Been Pwned (HIBP) added the dataset around February 22, 2026, listing 12.5 million affected accounts / email addresses and describing finance-application and dealer-related fields alongside contact data. HIBP attempts to validate authenticity before listing; its count is a researcher/monitoring census, not necessarily a company AG filing. SecurityWeek and Cybernews independently covered the same publication window and HIBP field list.
On February 22, 2026, CarGurus published a dealer-facing update, and on May 1, 2026, a Cybersecurity Incident Information page stated the company had completed its investigation with an independent cybersecurity firm, described the incident as limited in scope and contained, and said investigations concluded that dealer data feeds, APIs, dealer CRMs, core systems, or products used by dealer partners or consumers were not compromised. That dealer notice focuses on dealer/partner impact and does not replace HIBP’s consumer contact/finance-field inventory for people whose emails appear in the published archive—prefer any individual notice you receive.
Sources
- CarGurus – Have I Been Pwned breach entry (12.5M; added Feb 22, 2026)
- CarGurus Cybersecurity Incident Information – dealers.cargurus.com (May 1, 2026)
- CarGurus data breach exposes information of 12.4 million accounts – BleepingComputer (Feb 24, 2026)
- CarGurus Data Breach Impacts Over 12 Million Users – SecurityWeek
- ShinyHunters dump 12.4M CarGurus records – Cybernews
What data was exposed
Per HIBP’s CarGurus breach entry and press summaries (BleepingComputer, SecurityWeek, Cybernews), compromised data types included:
- Email addresses (~12.5M on HIBP)
- Full names
- Phone numbers
- Physical addresses
- IP addresses
- User account IDs / account ID mappings
- Finance pre-qualification application data
- Finance application outcomes
- Dealer account details / subscription information (as listed by HIBP/press)
Exact fields vary by record. HIBP noted a large share of emails were already known from prior breaches; that does not reduce the contact/finance-field risk for phishing. CarGurus’ May 2026 dealer update says dealer passwords were not compromised and that there was no evidence user accounts were at risk—still change reused passwords and watch for auto-finance phishing.
Breach details
| Detail | Value |
|---|---|
| Breach name | CarGurus (actor publication / HIBP listing; company dealer investigation update May 2026) |
| Date | Actor publication ~February 21, 2026; HIBP added ~February 22, 2026; company investigation wrap described May 1, 2026 |
| Disclosed | Public leak + HIBP/press February 2026; dealer incident page Feb 22 / May 1, 2026 |
| Accounts affected | ~12.4M records (BleepingComputer / actor archive); 12.5M accounts on HIBP |
| Domain | cargurus.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by CarGurus; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
Based on the contact and auto-finance fields named by HIBP/press:
- Be alert for phishing that references a car you viewed, a “pre-qualification,” or a dealer follow-up—verify through CarGurus or the dealer using contacts you look up yourself.
- Change passwords on CarGurus and any reuse accounts; enable MFA where available (prefer authenticator apps over SMS when possible—CarGurus’ dealer FAQ makes the same point).
- Watch for loan or credit offers you did not start; consider a credit freeze if you submitted sensitive finance-application data and are concerned. See how to freeze your credit.
- Treat unsolicited “CarGurus breach settlement / refund” emails as likely scams (CarGurus’ dealer FAQ makes the same point for dealer phishing).
- Keep any official notice if CarGurus or a regulator later mails one.
Short checklist: first 48 hours after a data breach.
How this shows up on the open web
Names, emails, phones, and physical addresses are core people-search building blocks. After an auto-shopping leak, messages that cite a vehicle, zip code, or “finance approval” can sound tailored. Run a free open-web scan to see which people-search and broker sites expose your personal data. Delist does not claim to have scanned CarGurus systems or this dump, and it does not remove dump copies.
Related reading: 700Credit (2025) (dealer-credit identity rail) and AssuranceAmerica (2026).
My email showed up in the CarGurus HIBP listing—what first?
Watch for auto-finance and dealer phishing; change reused passwords; consider a credit freeze if you submitted finance pre-qual data. Company dealer update says core dealer systems were not compromised—still treat the published contact fields seriously.
Frequently asked questions
How many CarGurus accounts were affected?
BleepingComputer described a ~12.4 million-record archive published around February 21, 2026. Have I Been Pwned listed 12.5 million affected accounts. Those are HIBP/press figures—not a Delist count.
What finance-related fields were listed?
HIBP’s entry and press summaries list finance pre-qualification application data, finance application outcomes, and dealer/subscription-related details alongside names, emails, phones, addresses, and IP addresses.
Did CarGurus publish an official notice?
Yes—a dealer-facing Cybersecurity Incident Information page (updated May 1, 2026) says the investigation found the incident limited/contained and that dealer feeds/APIs/core systems were not compromised. That does not erase HIBP’s consumer contact/finance-field inventory for emails in the published archive. Prefer any individual notice you receive.
Can Delist remove my CarGurus row from the leak?
No. Delist does not scrub marketplace systems or breach dumps. A free scan checks open-web people-search and broker listings only.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- 700Credit breach (2025)
- AssuranceAmerica breach (2026)
- First 48 hours after a data breach
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.