CarGurus internal-database cybersecurity incident

A contained cybersecurity incident involving an internal CarGurus company database. A later HIBP corpus associated with the incident and dealer information described by CarGurus.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A contained cybersecurity incident involving an internal CarGurus company database. [1]

Impact

A later HIBP corpus associated with the incident and dealer information described by CarGurus. [2]

Documented data types include:

  • IP addresses — IP addresses listed for the HIBP corpus; not separately confirmed in CarGurus’s dealer update. [2]
  • Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP corpus; dealer contact details were mainly publicly available according to CarGurus. [2]
  • Names — Names listed for the HIBP corpus; CarGurus separately confirmed that dealer data mainly included public dealer names and contact details. [2]

A cited record reports 12,461,887 records (Unique email addresses represented in the HIBP corpus; not a CarGurus-confirmed number of customers, dealers, accounts, applications, or affected individuals; as of 2026-02-22). [2]

CarGurus said dealer data mainly included publicly available dealer names and contact details. [1][2]

CarGurus said the incident impacted limited sensitive data. [1]

Timeline

  1. Documented event

    HIBP BreachDate; CarGurus’s public update confirms the incident but does not establish this as an exact intrusion, detection, or containment date.

    [2]
  2. Public disclosure

    Date CarGurus said it published an update to its dealer-facing site and emailed primary dealership contacts.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

CarGurus said dealer passwords were not compromised and that it had no evidence user accounts were at risk. [1]

CarGurus said dealer data feeds, APIs, dealer CRMs, and core systems or products used by dealer partners or consumers were not compromised. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

CarGurus emailed all primary dealership contacts and published a dealer-facing update on February 22, then continued direct communications as its investigation progressed. CarGurus said the limited event involved an internal company database that was promptly secured. CarGurus completed its investigation with assistance from an independent cybersecurity firm, whose findings it said were consistent with its internal assessment. HIBP described multiple files containing user-account ID mappings, finance pre-qualification application data, and dealer account and subscription information. CarGurus remained fully operational and reported no interruption to its services. CarGurus said the incident was limited in scope and contained. CarGurus said it directly contacted dealer partners in the rare cases where sensitive dealership information might have been involved. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]