Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
A later HIBP corpus associated with the incident and dealer information described by CarGurus. [2]
Documented data types include:
- IP addresses — IP addresses listed for the HIBP corpus; not separately confirmed in CarGurus’s dealer update. [2]
- Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP corpus; dealer contact details were mainly publicly available according to CarGurus. [2]
- Names — Names listed for the HIBP corpus; CarGurus separately confirmed that dealer data mainly included public dealer names and contact details. [2]
A cited record reports 12,461,887 records (Unique email addresses represented in the HIBP corpus; not a CarGurus-confirmed number of customers, dealers, accounts, applications, or affected individuals; as of 2026-02-22). [2]
CarGurus said dealer data mainly included publicly available dealer names and contact details. [1][2]
CarGurus said the incident impacted limited sensitive data. [1]
Timeline
Documented event
HIBP BreachDate; CarGurus’s public update confirms the incident but does not establish this as an exact intrusion, detection, or containment date.
[2]Public disclosure
Date CarGurus said it published an update to its dealer-facing site and emailed primary dealership contacts.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
CarGurus said dealer passwords were not compromised and that it had no evidence user accounts were at risk. [1]
CarGurus said dealer data feeds, APIs, dealer CRMs, and core systems or products used by dealer partners or consumers were not compromised. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
CarGurus emailed all primary dealership contacts and published a dealer-facing update on February 22, then continued direct communications as its investigation progressed. CarGurus said the limited event involved an internal company database that was promptly secured. CarGurus completed its investigation with assistance from an independent cybersecurity firm, whose findings it said were consistent with its internal assessment. HIBP described multiple files containing user-account ID mappings, finance pre-qualification application data, and dealer account and subscription information. CarGurus remained fully operational and reported no interruption to its services. CarGurus said the incident was limited in scope and contained. CarGurus said it directly contacted dealer partners in the rare cases where sensitive dealership information might have been involved. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
