If you’ve ever searched for a car on CarGurus, your personal information could now be circulating online. A known as ShinyHunters has published what it claims are 12.4 million records taken from CarGurus, a popular auto shopping platform used by millions of people each month.
The leaked data includes names, phone numbers, email addresses, physical addresses and even finance pre-qualification details. While most of the records were already exposed in past incidents, about 3.7 million are newly added to the pile. That means fresh data is now freely available for criminals to download.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide â free when you join my CYBERGUY.COM newsletter.
The group behind the leak, ShinyHunters, published a 6.1GB file on Feb. 21, claiming it came from CarGurus. The file allegedly contains 12.4 million user records tied to the U.S.-based auto research and shopping platform CarGurus.
CarGurus operates in the U.S., Canada and the U.K., and its website attracts an estimated 40 million monthly visitors. It allows you to compare vehicles, contact sellers, and, in some cases, apply for financing.
According to Have I Been Pwned, which later added the dataset to its breach database, the exposed information includes email addresses, IP addresses, full names, phone numbers, physical addresses, account IDs, dealer details, subscription information and finance pre-qualification application data, along with outcomes.
Have I Been Pwned reports that about 70% of the data had already appeared in previous breaches. Roughly 3.7 million records are new. CarGurus has not released an official statement confirming the incident and did not respond to media requests for comment. ShinyHunters is known for leaking company data when ransom negotiations fail. The group has recently claimed attacks on major brands across telecom, retail, finance, and tech.
ShinyHunters typically gains access by tricking employees, not by smashing through firewalls. In past cases, the group used phone calls or fake login pages to convince staff to hand over credentials. Once inside, attackers can quietly access cloud systems that store customer data.
In some campaigns, they also convinced employees to install malicious apps that granted access to customer databases. That means attackers could read stored information without triggering obvious alarms. If this dataset is legitimate, criminals now have detailed personal profiles tied to car shopping and financing activity, which is valuable.
is especially sensitive. Even if it does not include full Social Security numbers, it signals that you were actively sharing financial details. That makes you a prime target for follow-up scams, identity theft attempts and fake loan offers. Because the data is publicly available for download, it does not take much skill for criminals to start using it.
“We recently experienced a cybersecurity incident,” a CarGurus spokesperson told CyberGuy. “We promptly responded by securing the affected environment, and we are currently working with a leading cybersecurity firm to investigate. Based on the investigation to date, we believe the activity has been contained and limited in scope. Also, at this time, there are no indications that dealer data feeds, APIs, or core systems or products used by our consumers or dealer partners have been compromised. We remain fully operational, and our services continue without interruption. We will notify any affected individuals in accordance with applicable laws.”
Here’s what you can do right now to reduce your risk and stay ahead of potential scams tied to this leak.
To see if your email was affected, visit Have I Been Pwned at haveibeenpwned.com

