ShinyHunters allegedly drove off with 1.7M CarGurus records
(2026/02/18)
- Reference: 1771447244
- News link: https://www.theregister.co.uk/2026/02/18/shinyhunters_cargurus_breach/
- Source link:
CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.
"This is a final warning to reach out by 20 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way," ShinyHunters wrote in its announcement, seen by The Register and [1]shared on social media. The digital crooks claimed the compromised files included personally identifiable information and "other internal corporate data."
CarGurus did not immediately respond to The Register 's inquiries. We will update this story when we hear back from the company.
[2]
We also reached out to ShinyHunters to find out when and how they breached the car shopping site, but did not receive an immediate response.
[3]
[4]
The Wednesday posts cap a string of 15 breaches claimed by [5]ShinyHunters and Scattered Lapsus$ Hunters since the beginning of the year, including penetrating two investment advisory firms, Mercer Advisors and Beacon Pointe Advisors, listed on Sunday.
The extortionists set a Wednesday deadline for both companies to negotiate and threatened to leak 5 million records from Mercer and 100,000 from Beacon Pointe. Neither firm has posted a breach notification, and they did not respond to The Register 's requests for comment.
[6]
At least one of the companies allegedly breached by ShinyHunters and posted to its leak site in February has said the compromise is from an old raid. On Monday, [7]Canada Goose told us that it was "aware that a historical dataset relating to past customer transactions has recently been published online."
The down-filled jacket purveyor, however, declined to say how old the data is or how it was originally stolen.
Blockchain lending firm Figure Technology Solutions was also listed on ShinyHunters' leak site last week, and according to Have I Been Pwned, the criminals [8]stole nearly 1 million customers' records.
[9]
A Figure spokesperson told us that "an employee was socially engineered, and that allowed an actor to download a limited number of files through their account."
[10]Canada Goose ruffles feathers over 600K record dump, says leak is old news
[11]Betterment breach may expose 1.4M users after social engineering attack
[12]ShinyHunters swipes right on 10M records in alleged dating app data grab
[13]Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim
"We acted quickly to block the activity and retained a forensic firm to investigate what files were affected," the spokesperson's statement, sent via email, continued. "We understand the importance of these matters and are communicating with partners and those impacted as appropriate."
The company also said it is adding "safeguards and training" to boost its digital defenses, and offering free credit monitoring to all affected individuals.
Other recent victims include investment platform [14]Betterment , [15]Match Group (with dating sites Hinge, Match.com, and OkCupid compromised during the intrusion), [16]Panera Bread , and car buying and review sites Carvana and Edmunds.
ShinyHunters previously told The Register that it [17]gained access to Betterment's systems by voice phishing its Okta single sign-on (SSO) codes, and Panera via a Microsoft Entra SSO code. The criminals' spokesperson said the CarMax and Edmunds breaches were from earlier, unrelated intrusions. ®
Get our [18]Tech Resources
[1] https://x.com/AlvieriD/status/2023924107025211646
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/10/13/scattered_lapsus_hunters_hiatus/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2026/02/16/canada_goose_shinyhunters/
[8] https://haveibeenpwned.com/PwnedWebsites
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2026/02/16/canada_goose_shinyhunters/
[11] https://www.theregister.com/2026/02/05/betterment_hack/
[12] https://www.theregister.com/2026/01/29/shinyhunters_match_group/
[13] https://www.theregister.com/2026/01/27/shinyhunters_claim_panera_bread/
[14] https://www.theregister.com/2026/02/05/betterment_hack/
[15] https://www.theregister.com/2026/01/29/shinyhunters_match_group/
[16] https://www.theregister.com/2026/01/27/shinyhunters_claim_panera_bread/
[17] https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/
[18] https://whitepapers.theregister.com/
"This is a final warning to reach out by 20 Feb 2026 before we leak along with several annoying (digital) problems that'll come your way," ShinyHunters wrote in its announcement, seen by The Register and [1]shared on social media. The digital crooks claimed the compromised files included personally identifiable information and "other internal corporate data."
CarGurus did not immediately respond to The Register 's inquiries. We will update this story when we hear back from the company.
[2]
We also reached out to ShinyHunters to find out when and how they breached the car shopping site, but did not receive an immediate response.
[3]
[4]
The Wednesday posts cap a string of 15 breaches claimed by [5]ShinyHunters and Scattered Lapsus$ Hunters since the beginning of the year, including penetrating two investment advisory firms, Mercer Advisors and Beacon Pointe Advisors, listed on Sunday.
The extortionists set a Wednesday deadline for both companies to negotiate and threatened to leak 5 million records from Mercer and 100,000 from Beacon Pointe. Neither firm has posted a breach notification, and they did not respond to The Register 's requests for comment.
[6]
At least one of the companies allegedly breached by ShinyHunters and posted to its leak site in February has said the compromise is from an old raid. On Monday, [7]Canada Goose told us that it was "aware that a historical dataset relating to past customer transactions has recently been published online."
The down-filled jacket purveyor, however, declined to say how old the data is or how it was originally stolen.
Blockchain lending firm Figure Technology Solutions was also listed on ShinyHunters' leak site last week, and according to Have I Been Pwned, the criminals [8]stole nearly 1 million customers' records.
[9]
A Figure spokesperson told us that "an employee was socially engineered, and that allowed an actor to download a limited number of files through their account."
[10]Canada Goose ruffles feathers over 600K record dump, says leak is old news
[11]Betterment breach may expose 1.4M users after social engineering attack
[12]ShinyHunters swipes right on 10M records in alleged dating app data grab
[13]Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim
"We acted quickly to block the activity and retained a forensic firm to investigate what files were affected," the spokesperson's statement, sent via email, continued. "We understand the importance of these matters and are communicating with partners and those impacted as appropriate."
The company also said it is adding "safeguards and training" to boost its digital defenses, and offering free credit monitoring to all affected individuals.
Other recent victims include investment platform [14]Betterment , [15]Match Group (with dating sites Hinge, Match.com, and OkCupid compromised during the intrusion), [16]Panera Bread , and car buying and review sites Carvana and Edmunds.
ShinyHunters previously told The Register that it [17]gained access to Betterment's systems by voice phishing its Okta single sign-on (SSO) codes, and Panera via a Microsoft Entra SSO code. The criminals' spokesperson said the CarMax and Edmunds breaches were from earlier, unrelated intrusions. ®
Get our [18]Tech Resources
[1] https://x.com/AlvieriD/status/2023924107025211646
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/10/13/scattered_lapsus_hunters_hiatus/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2026/02/16/canada_goose_shinyhunters/
[8] https://haveibeenpwned.com/PwnedWebsites
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEifSaJC9w3xhO8DG3AQAAAdM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2026/02/16/canada_goose_shinyhunters/
[11] https://www.theregister.com/2026/02/05/betterment_hack/
[12] https://www.theregister.com/2026/01/29/shinyhunters_match_group/
[13] https://www.theregister.com/2026/01/27/shinyhunters_claim_panera_bread/
[14] https://www.theregister.com/2026/02/05/betterment_hack/
[15] https://www.theregister.com/2026/01/29/shinyhunters_match_group/
[16] https://www.theregister.com/2026/01/27/shinyhunters_claim_panera_bread/
[17] https://www.theregister.com/2026/01/23/shinyhunters_claims_okta_customer_breaches/
[18] https://whitepapers.theregister.com/