CarGuru's databreach claimed by attack group
CarGuru's databreach claimed by attack group
Author
Discussion

HiAsAKite

Original Poster:

2,521 posts

270 months

Thursday 19th February
quotequote all
Just seen the following on the Register: https://www.theregister.com/2026/02/18/shinyhunter...

Anyone from PH towers able to comment whether:
1) this is true/has been validated
2) whether PH is effected?


LordGrover

34,035 posts

235 months

Sunday 22nd February
quotequote all
Here to ask the same question after seeing this
https://www.techradar.com/pro/security/major-cargu...

plover

363 posts

234 months

Sunday 22nd February
quotequote all
CarGuru breach data is now searchable on https://haveibeenpwned.com/Breach/CarGurus (near the bottom for the search option)

For my domain, pistonheads emails don't appear to be in the data, just the CarGurus main site, but that' just from querying above site for my domain. Pistonheads should confirm.


CraigyMc

18,179 posts

259 months

Sunday 22nd February
quotequote all
Yeah, looks like PH is affected based on my data.

Scrump

23,729 posts

181 months

Sunday 22nd February
quotequote all
Checked my details and it shows no breach of my PH data.

Paft Dunk

352 posts

281 months

Sunday 22nd February
quotequote all
I can’t figure it. I use a custom email address for my PH account. But it’s not that address that’s in the leak. My ‘personal’ one is. Not aware I ever had a cargurus direct account.

Some more details would be good.

HiAsAKite

Original Poster:

2,521 posts

270 months

Sunday 22nd February
quotequote all
I cant see anything on have been pwned in relation to my phone email and this leak.. so possible that the UK operations of CarGuru's are not impacted, or ph is on separate systems.

I would also allow the CarGurus team a little time to work out what is what, and what may have been exposed or not- as working this out when dealing with a databreach, and figuring out what data systems actually has been exposed, versus hasn't etc, is not always straightforwards or clearcut..

So they may not know at this point, but that in itself does not mean it has been exposed.

Edited for SPAG etc


Edited by HiAsAKite on Sunday 22 February 22:23

gazza285

10,846 posts

231 months

Monday 23rd February
quotequote all

RacingPete

9,148 posts

227 months

PH TEAM

Monday 23rd February
quotequote all
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn’t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.

Fore Left

1,601 posts

205 months

Monday 23rd February
quotequote all
RacingPete said:
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.
I would call this highly sensitive data & certainly something that can be used to socially engineer money out of the unwary;

haveibeenpwned said:
Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.
Fwiw, my email address which is unique to PistonHeads has not been compromised.

HiAsAKite

Original Poster:

2,521 posts

270 months

Monday 23rd February
quotequote all
RacingPete said:
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.
Thanks RP.

Fully appreciate these things do take time to investigate, and figure out exactly what has, and has not been exposed (or potentially at exposed).

As and when things progress, it would be good to know whether any PH data (or PH user data) is thought to have been at risk or not.

Fully appreciate this is not always easy to tell depending on the back end system architecture/mode of compromise etc, but be good to know one way or another.

I note that I (and I suspect others) have not had urgent messages to change user credentials etc

HAAK


Agent57

2,312 posts

177 months

Saturday 7th March
quotequote all
I got a badly worded email asking me to send $2000 in bit coin due to Car Gurus being hacked.

Not sure if it was speculative or real. Car Gurus says I don't have an account with them.

poo at Paul's

14,546 posts

198 months

Thursday
quotequote all
Two recent emails to junk claiming to have hacked me via the car gurus data breach and asking for 2 grand in bitcoin.