HomeSecurityCarGurus: Data Breach Affects Millions of Users

CarGurus: Data breach affects millions of users

The ShinyHunters ransomware group recently published more than 12 million files allegedly stolen from the CarGurus platform , a U.S.-based digital automotive hub. The leak includes sensitive personal data and raises concerns about potential phishing attacks against the service’s users.

CarGurus Data Breach

CarGurus a publicly traded company that provides search, comparison and connection services for new and used vehicle sellers in the U.S., Canada and the U.K. With approximately 40 million monthly visitors, the platform plays a central role in how consumers buy and sell cars, making user data extremely valuable to malicious actors.

See also: Russian UAC-0050 targets European financial institution

ShinyHunters: What the exposed data includes

On February 21, ShinyHunters published a 6.1GB archive containing 12.4 million files . Breach monitoring platform HaveIBeenPwned (HIBP) added the data to its database the next day, reporting that it included:

  • Email addresses
  • IP addresses
  • Usernames
  • Phone numbers
  • Physical addresses
  • User account identifiers
  • Funding application data
  • Funding application results
  • Agency account details
  • Subscription information

CarGurus has not yet issued an official statement about the data breach, but HIBP is trying to verify the authenticity of the files before posting them on its platform, ensuring that the information is not false.

CarGurus: Data breach affects millions of users

New and old data – Who is at risk?

HIBP notes that approximately 70% of the exposed data was already in its database from previous incidents. This means that approximately 3.7 million records are new additions and can be exploited by cybercriminals for targeted phishing attacks and scams. CarGurus users are urged to remain vigilant for suspicious communications and requests that appear trustworthy but may be hiding malicious intent.

See also: Operation Olalampo: MuddyWater targets organizations with new malware

ShinyHunters activity and previous attacks

ShinyHunters has a history of multiple attacks on large companies, releasing data when ransom negotiations fail. Its recent activity includes breaches of:

  • Dutch telecommunications provider Odido
  • Advertising technology company Optimizely
  • Fintech company Figure
  • Clothing brand Canada Goose
  • Panera Bread restaurant chain
  • Online dating company Match Group
  • SoundCloud music streaming platform

The group primarily uses techniques social engineering, with a focus on voice phishing and credential collection pages, to gain access to SaaS such as Salesforce, Okta, and Microsoft 365. Additionally, previous campaigns have included the installation of malicious OAuth, which allowed for the reading of customer data tables in real time.

Risks and consequences for companies and users

Leaks of this magnitude not only compromise the personal data of users, but also the security of corporate infrastructure. Cybercriminals can use the information for targeted phishing attacks, credit card fraud, and social engineering. In addition, companies that suffer such breaches see serious damage to customer trust and their corporate reputation.

See also: XMRig Wormable Campaign: New attack with BYOVD exploit

CarGurus: Data breach affects millions of users

Protection and prevention strategy

To reduce the risk, users are advised to change passwords, enable two-factor authentication (2FA) and be wary of any unexpected communication. Companies are urged to strengthen monitoring systems, train staff in phishing recognition and adopt malicious activity detection tools.

The CarGurus and ShinyHunters case is a reminder that data security is not just a technical issue but also a strategic risk management. As attacks become increasingly targeted and sophisticated, prevention and early response are critical to protecting both users and corporate ecosystems.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS