[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2wgrkistrhvun":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":36,"seoTitle":37,"seoDescription":38,"logoUrl":39,"isVerified":4,"isSensitive":40,"isSpamList":40,"isMalware":40,"company":41},"6a452308a20f867c8ba8e741","CarGurus","CarGurus 2026 Data Breach","cargurus","cargurus.com","2026-02-14T00:00:00.000Z","2026-02-22T04:43:54.000Z",null,"2026-07-21T16:46:07.060Z","Verified breach record","https:\u002F\u002Fdealers.cargurus.com\u002Fblog\u002Fcybersecurity-incident-information",[16,18,19],"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F02\u002F18\u002Fshinyhunters_cargurus_breach\u002F","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fcar-gurus-2026",12461887,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35],"Email addresses","IP addresses","Names","Phone numbers","Physical addresses","\u003Cp>\u003Cstrong>The CarGurus data breach\u003C\u002Fstrong>, dated 14 February 2026, is a verified leak affecting 12,461,887 unique email addresses.\u003C\u002Fp>\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\u003Cp>The confirmed data classes are email addresses, names, phone numbers, physical addresses, and IP addresses. The files were also reported to contain account mappings, finance pre-qualification information, application outcomes, and dealer account and service-plan context. The figure of 12,461,887 counts unique email addresses; it does not mean every record held the same fields or that the total maps one-to-one to the same number of people. \u003Cstrong>The confirmed data types\u003C\u002Fstrong> do not include passwords or payment cards, but they can support personalized phishing, fraudulent support calls, and scams built around a vehicle or finance journey. A field found in one file must not be assumed to exist for every affected address.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>The actor associated with the incident claimed access occurred on 13 February 2026, while the verified record uses 14 February 2026 as the breach date. Early reports referred to roughly 1.7 million corporate records; later counting across released files identified 12,461,887 unique email addresses. One was an early claim about corporate records and the other is a deduplicated email count, so they should not be used interchangeably. The reported sequence involved attempted extortion followed by public release of the data. CarGurus said an independently supported investigation found the event had been contained and limited to an internal company database, with services remaining operational. It also said there was no evidence that dealer data feeds, integration connections, dealer customer-management systems, core products, or consumer services had been compromised. This assessment does not negate the verified email count in the released files.\u003C\u002Fp>\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\u003Cp>The most direct risk applies to consumers who researched vehicles on CarGurus, created an account, shared contact details, or used finance pre-qualification. Dealership employees and people linked to dealer accounts may also be targeted through work emails, phone numbers, or service-plan context. Finding an email in the dataset does not prove that the person submitted a finance application or that their address was exposed; different files contained different fields. When several fields align, an attacker can pretend to know a vehicle preference, dealership relationship, application stage, or region. A fake deposit request, loan approval, identity-document upload link, or account-verification call may therefore look credible. Risk should be assessed by the service used and communication channels that may have been linked, not only by the headline total.\u003C\u002Fp>\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\u003Cp>Independently verify unexpected email, text, or calls claiming to come from CarGurus, a dealership, a finance provider, or a vehicle seller. Type the known website address instead of following a link, and use the number on the official site rather than one supplied by the caller. Do not open unexpected attachments, install remote-access software, disclose a one-time code, or act on an urgent payment request before a second channel confirms it. \u003Cstrong>Passwords are not among the confirmed data classes\u003C\u002Fstrong>, but anyone who reused the same email and password should create a long, unique password for every account and enable multi-factor authentication. If you used finance pre-qualification, watch credit reports, new-account notices, and address-change alerts, and report unfamiliar applications directly to the financial institution.\u003C\u002Fp>\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\u003Cp>Contact data can create a lasting social-engineering risk even without a password. Separate email aliases for vehicle shopping, finance, and general memberships make an imitated service easier to identify. A password manager can hold a unique credential for every account and support review of recovery methods. Where a mobile carrier supports it, a port-out lock or account security code helps resist number-transfer attempts by someone who knows the phone number. Treat knowledge of an address, phone number, or date of birth as weak proof of identity; use random security-question answers stored in a password manager instead of truthful answers found online. Dealerships should train staff against email and voice phishing, separate duties in sensitive workflows, review access rights, and alert on unusual exports or sessions. Shorter retention periods and fewer optional fields reduce the impact of a future incident. Contact details are difficult to replace, so convincing approaches may appear months later.\u003C\u002Fp>\u003Ch2>Record Check and User Action\u003C\u002Fh2>\u003Cp>Use the record check on this page to see whether your email address is associated with this breach. A match does not mean every listed data type appeared in your record, nor does it prove someone accessed your account; it means the queried identifier matched the verified dataset. No match is not an absolute guarantee because more files can appear and formatting or deduplication differences can prevent some records from matching. Do not submit your full email address to untrusted sites, forums, or unsolicited contacts. If a match appears, list the services where you reused that email, review active sessions and recovery options, filter related messages, and report unusual finance or dealership contact directly to the organization concerned. Judge a message by the sender domain, link destination, urgency, and requested action rather than the displayed sender name. Regular checks, unique passwords, strong multi-factor authentication, and independent confirmation of sensitive requests work together to reduce phishing and fraud risk.\u003C\u002Fp>","CarGurus 2026 Data Breach (12.5 Million Reported Records)","CarGurus 2026 Data Breach. 12.5 Million reported records are reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcargurus_com.webp",false,{"name":7,"sector":42,"country":43,"website":10,"websiteArchiveUrl":44,"websiteStatus":44,"websiteCheckedAt":13},"Automotive","United States",""]