CarGurus data breach exposes information of 12.4 million accounts
嗯,用户让我总结这篇文章的内容,控制在一百个字以内。首先,我需要快速浏览文章,抓住主要信息。 文章提到ShinyHunters勒索团伙泄露了超过1200万条记录,声称是从CarGurus窃取的。CarGurus是一个美国的汽车平台,用户量很大。泄露的数据包括电子邮件、IP地址、姓名、电话号码、地址等敏感信息。 接下来,用户要求用中文总结,并且不需要特定的开头,直接写描述。所以我要把重点放在事件本身和影响上。 然后,我需要确保字数控制在100字以内,所以要简洁明了。可能的结构是:勒索团伙泄露数据,涉及公司和记录数量,数据内容以及潜在风险。 最后,检查是否有遗漏的重要信息,比如ShinyHunters最近活跃的情况和他们的攻击手法,但考虑到字数限制,可能只能简要提及。 </think> ShinyHunters勒索团伙泄露超1200万条CarGurus用户数据,包括邮箱、IP地址、姓名等敏感信息。尽管CarGurus未确认数据泄露,但已有70%的数据来自以往事件。新泄露数据约370万条,可能被用于网络钓鱼攻击。 2026-2-24 18:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

CarGurus data breach exposes information of 12.4 million accounts

The ShinyHunters extortion group has published personal information in more than 12 million records allegedly stolen from CarGurus, a U.S.-based digital auto platform.

CarGurus is a publicly traded automotive research and shopping company that operates in the U.S., Canada, and the U.K. Its website has an estimated 40 million monthly visitors and helps people find, compare, and contact sellers of new and used vehicles.

On February 21, the threat group published a 6.1GB archive containing 12.4 million records, saying it was from CarGurus. A day later, the HaveIBeenPwned (HIBP) data breach monitoring and alerting platform added the dataset, listing the following data types as compromised:

Wiz

  • Email addresses
  • IP addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • User account IDs
  • Finance pre-qualification application data
  • Finance application outcomes
  • Dealer account details
  • Subscription information

Although CarGurus has not released an official statement disclosing a data breach and did not respond to BleepingComputer's request for comment, it is important to note that HIBP attempts to confirm the validity/authenticity of the leaked records before adding them.

HIBP reports that 70% of the leaked data was already on its database from previous incidents, so roughly 3.7 million records are fresh. Since the information is freely available for download, cybercriminals could take advantage of it for phishing attacks.

CarGurus listed as a victim on ShinyHunters data leak site
ShinyHunters lists CarGurus as their victim
Source: BleepingComputer

CarGurus users are advised to stay alert for potentially malicious communications and scam attempts leveraging the leaked information.

The ShinyHunters data extortion group has been very active recently, claiming multiple attacks on large companies and leaking their data when negotiations reached a dead end.

The most recent examples include Dutch telecommunications provider Odido, ad tech firm Optimizely, fintech firm Figure, outerwear brand Canada Goose, restaurant chain Panera Bread, online dating company Match Group, and music streaming platform SoundCloud.

The threat group typically uses social engineering, most commonly voice phishing, to breach organizations, directing victims to credential-harvesting pages that grant them access to SaaS platforms such as Salesforce, Okta, and Microsoft 365.

Previous ShinyHunters campaigns also involved tricking employees into installing malicious OAuth applications that granted them API-level read access to customer data tables inside Salesforce instances. 

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/cargurus-data-breach-exposes-information-of-124-million-accounts/
如有侵权请联系:admin#unsafe.sh