Automotive marketplace CarGurus was the target of a data breach in which the names, email addresses, phone numbers, and physical addresses of millions of customers were stolen.
Have I Been Pwned, a data notification site provider by security researcher Troy Hunt, reported that 12.5 million CarGurus accounts were compromised in the data breach.
CarGurus, founded in 2006, operates an online marketplace that allows customers to buy, sell, and finance vehicle purchases.
Have I Been Pwned attributed the breach to the ShinyHunters hacking group.
The ShinyHunters group is known for its social engineering skills, such as calling up helpdesks and pretending to be employees who need their password reset. The hackers have used their social engineering skills to steal reams of data from several universities, over a billion records from Salesforce customers, including Google and Workday, and claimed recent hacks at Pornhub and fintech lending giant Figure.
TechCrunch has reached out to CarGurus for comment and will update this article if the company responds.
The customer data that was published included user account ID mappings, finance pre-qualification application data and dealer account and subscription information, according to Have I Been Pwned.
This is the second automotive-related data breach reported by Have I Been Pwned this year. Last month, data allegedly from CarMax was published following a failed extortion attempt, the data breach notification site reported. The data breach included about 431,000 unique email addresses along with names, phone numbers, and physical addresses.
#CarGurus #data #breach #affects #million #accounts