ShinyHunters-Linked Extortion and Data Leak Claims Targeting Automotive Retailers
Data allegedly sourced from US automotive retailer CarMax was published online after a failed extortion attempt, according to a Have I Been Pwned breach entry. The exposed dataset reportedly includes 431,000 unique email addresses along with names, phone numbers, and physical addresses, indicating a PII-heavy leak that could enable targeted phishing and identity-focused fraud.
Separately, CarGurus was reported as being purportedly breached by the ShinyHunters hacking operation, with claims of 1.7 million corporate files stolen and an extortion deadline tied to negotiations. The intrusion was alleged to have occurred via single sign-on (SSO) codes obtained through voice phishing, consistent with ShinyHunters’ prior claims of compromising other organizations using SSO-code access; CarGurus has been positioned as another extortion-driven theft where internal records and PII may be at risk of exposure.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters set Feb. 20 deadline after claiming CarGurus data theft
After the alleged CarGurus intrusion, ShinyHunters claimed it had stolen 1.7 million corporate files and threatened to leak them if negotiations did not progress by 2026-02-20. The claim was publicly reported as part of the extortion effort tied to the purported breach.
ShinyHunters allegedly accessed CarGurus via voice-phished SSO codes
ShinyHunters claimed it gained access to CarGurus on 2026-02-13 by using single sign-on codes obtained through voice phishing. The group said this enabled theft of corporate files containing personally identifiable information and internal company records.
CarMax data allegedly published online after failed extortion attempt
In January 2026, data allegedly sourced from CarMax was published online following a failed extortion attempt. The exposed dataset reportedly contained 431,000 unique email addresses along with names, phone numbers, and physical addresses.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
1 reference tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


