CarGurus has suffered a major data breach that exposed the personal information of around 12.5 million users.
CarGurus is an online car marketplace that connects buyers with dealers and private sellers. It helps users compare prices, find deals, and explore financing options for new and used vehicles.
According to Have I Been Pwned, the data breach notification service run by security researcher Troy Hunt, millions of CarGurus accounts were compromised. The stolen information includes names, email addresses, phone numbers, and physical addresses.
The breach reportedly goes beyond basic contact details. Published data also included user account ID mappings, finance prequalification application information, and dealer account and subscription data.
Have I Been Pwned linked the incident to the hacking group known as ShinyHunters. The group is known for using social engineering tactics, such as calling company help desks and pretending to be employees who need password resets.





