CarGuru's databreach claimed by attack group
Discussion
Just seen the following on the Register: https://www.theregister.com/2026/02/18/shinyhunter...
Anyone from PH towers able to comment whether:
1) this is true/has been validated
2) whether PH is effected?
Anyone from PH towers able to comment whether:
1) this is true/has been validated
2) whether PH is effected?
Here to ask the same question after seeing this
https://www.techradar.com/pro/security/major-cargu...
https://www.techradar.com/pro/security/major-cargu...
CarGuru breach data is now searchable on https://haveibeenpwned.com/Breach/CarGurus (near the bottom for the search option)
For my domain, pistonheads emails don't appear to be in the data, just the CarGurus main site, but that' just from querying above site for my domain. Pistonheads should confirm.
For my domain, pistonheads emails don't appear to be in the data, just the CarGurus main site, but that' just from querying above site for my domain. Pistonheads should confirm.
I cant see anything on have been pwned in relation to my phone email and this leak.. so possible that the UK operations of CarGuru's are not impacted, or ph is on separate systems.
I would also allow the CarGurus team a little time to work out what is what, and what may have been exposed or not- as working this out when dealing with a databreach, and figuring out what data systems actually has been exposed, versus hasn't etc, is not always straightforwards or clearcut..
So they may not know at this point, but that in itself does not mean it has been exposed.
Edited for SPAG etc
I would also allow the CarGurus team a little time to work out what is what, and what may have been exposed or not- as working this out when dealing with a databreach, and figuring out what data systems actually has been exposed, versus hasn't etc, is not always straightforwards or clearcut..
So they may not know at this point, but that in itself does not mean it has been exposed.
Edited for SPAG etc
Edited by HiAsAKite on Sunday 22 February 22:23
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn’t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.
RacingPete said:
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.
I would call this highly sensitive data & certainly something that can be used to socially engineer money out of the unwary;haveibeenpwned said:
Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.
Fwiw, my email address which is unique to PistonHeads has not been compromised.RacingPete said:
CarGurus recently experienced a cybersecurity incident; the team secured the affected environment and launched an investigation with the assistance of a leading independent cybersecurity firm. Based on the investigation to date, the activity has been contained and limited in scope. At this time, it doesn t appear that the incident involved a broad set of highly sensitive data; however, the investigation remains ongoing. CarGurus and PistonHeads remain fully operational, and services continue without interruption.
Thanks RP.Fully appreciate these things do take time to investigate, and figure out exactly what has, and has not been exposed (or potentially at exposed).
As and when things progress, it would be good to know whether any PH data (or PH user data) is thought to have been at risk or not.
Fully appreciate this is not always easy to tell depending on the back end system architecture/mode of compromise etc, but be good to know one way or another.
I note that I (and I suspect others) have not had urgent messages to change user credentials etc
HAAK
Gassing Station | Website Feedback | Top of Page | What's New | My Stuff


