---
title: "CarGurus internal-database cybersecurity incident"
description: "Evidence-backed account of CarGurus internal-database cybersecurity incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/cargurus-internal-database-cybersecurity-incident-2026"
markdown_url: "https://www.ally.security/incidents/cargurus-internal-database-cybersecurity-incident-2026.md"
stix_url: "https://www.ally.security/incidents/cargurus-internal-database-cybersecurity-incident-2026/stix.json"
---

# CarGurus internal-database cybersecurity incident

A contained cybersecurity incident involving an internal CarGurus company database. A later HIBP corpus associated with the incident and dealer information described by CarGurus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A contained cybersecurity incident involving an internal [CarGurus](https://www.cargurus.com/) company database. [1](#source-1)

## Impact

A later HIBP corpus associated with the incident and dealer information described by CarGurus. [2](#source-2)

Documented data types include:

- IP addresses — IP addresses listed for the HIBP corpus; not separately confirmed in CarGurus's dealer update. [2](#source-2)
- Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP corpus; dealer contact details were mainly publicly available according to CarGurus. [2](#source-2)
- Names — Names listed for the HIBP corpus; CarGurus separately confirmed that dealer data mainly included public dealer names and contact details. [2](#source-2)

A cited record reports 12,461,887 records (Unique email addresses represented in the HIBP corpus; not a CarGurus-confirmed number of customers, dealers, accounts, applications, or affected individuals; as of 2026-02-22). [2](#source-2)

CarGurus said dealer data mainly included publicly available dealer names and contact details. [1](#source-1) [2](#source-2)

CarGurus said the incident impacted limited sensitive data. [1](#source-1)

## Timeline

### February 14, 2026 — Documented event

HIBP BreachDate; CarGurus's public update confirms the incident but does not establish this as an exact intrusion, detection, or containment date. [2](#source-2)

### February 22, 2026 — Public disclosure

Date CarGurus said it published an update to its dealer-facing site and emailed primary dealership contacts. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

CarGurus said dealer passwords were not compromised and that it had no evidence user accounts were at risk. [1](#source-1)

CarGurus said dealer data feeds, APIs, dealer CRMs, and core systems or products used by dealer partners or consumers were not compromised. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

CarGurus emailed all primary dealership contacts and published a dealer-facing update on February 22, then continued direct communications as its investigation progressed. CarGurus said the limited event involved an internal company database that was promptly secured. CarGurus completed its investigation with assistance from an independent cybersecurity firm, whose findings it said were consistent with its internal assessment. HIBP described multiple files containing user-account ID mappings, finance pre-qualification application data, and dealer account and subscription information. CarGurus remained fully operational and reported no interruption to its services. CarGurus said the incident was limited in scope and contained. CarGurus said it directly contacted dealer partners in the rare cases where sensitive dealership information might have been involved. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/cargurus-internal-database-cybersecurity-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Cybersecurity Incident Information

official · CarGurus, Inc.

<https://dealers.cargurus.com/blog/cybersecurity-incident-information>

<a id="source-2"></a>

### CarGurus breach record

advisory · Have I Been Pwned · Feb 22, 2026

<https://haveibeenpwned.com/api/v3/breach/CarGurus>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   CarGurus customer and dealer data corpus: CarGurus said dealer data mainly included publicly available dealer names and contact details.
2. **Disclosed At · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: 2026-02-22
3. **Resulted In · 100% confidence · current**  
   CarGurus dealer incident communications: CarGurus emailed all primary dealership contacts and published a dealer-facing update on February 22, then continued direct communications as its investigation progressed.
4. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus dealer incident communications
5. **Affected Organization · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus, Inc.
6. **Resulted In · 100% confidence · current**  
   CarGurus customer and dealer data corpus: CarGurus said dealer passwords were not compromised and that it had no evidence user accounts were at risk.
7. **Exposed Data Category · 90% confidence · current**  
   CarGurus customer and dealer data corpus: IP addresses
8. **Occurred At · 80% confidence · current**  
   February 2026 CarGurus cybersecurity incident: 2026-02-14
9. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus said the limited event involved an internal company database that was promptly secured.
10. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus said dealer data feeds, APIs, dealer CRMs, and core systems or products used by dealer partners or consumers were not compromised.
11. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus completed its investigation with assistance from an independent cybersecurity firm, whose findings it said were consistent with its internal assessment.
12. **Resulted In · 90% confidence · current**  
   CarGurus customer and dealer data corpus: HIBP described multiple files containing user-account ID mappings, finance pre-qualification application data, and dealer account and subscription information.
13. **Resulted In · 95% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus customer and dealer data corpus
14. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus said the incident impacted limited sensitive data.
15. **Exposed Data Category · 95% confidence · current**  
   CarGurus customer and dealer data corpus: Contact information
16. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus remained fully operational and reported no interruption to its services.
17. **Resulted In · 100% confidence · current**  
   February 2026 CarGurus cybersecurity incident: CarGurus said the incident was limited in scope and contained.
18. **Resulted In · 100% confidence · current**  
   CarGurus customer and dealer data corpus: CarGurus said it directly contacted dealer partners in the rare cases where sensitive dealership information might have been involved.
19. **Exposed Record Count · 100% confidence · current**  
   CarGurus customer and dealer data corpus: 12,461,887 record
20. **Exposed Data Category · 95% confidence · current**  
   CarGurus customer and dealer data corpus: Names

</details>
