CarGurus Lawsuit: Data Breach Class Actions and Account Guidance

The CarGurus data breach lawsuits are a set of class action complaints filed in Massachusetts federal court in early 2026, accusing the online auto marketplace of failing to protect the personal information of roughly 12.5 million user accounts exposed in a February 2026 attack by the hacking group ShinyHunters, and of failing to give timely notice once the breach was public.1TechCrunch. CarGurus Data Breach Affects 12.5 Million Accounts2Bloomberg Law. CarGurus Hit With Lawsuit Flurry Over ShinyHunters Data Breach

What Was Exposed

ShinyHunters published a 6.1 GB archive of stolen CarGurus data on February 21, 2026, after the company did not meet a ransom demand.3eSecurity Planet. 12.4 Million Accounts Exposed in CarGurus Leak4Morgan & Morgan. Massive Data Breach at CarGurus Have I Been Pwned cataloged about 12.5 million affected accounts the following day.5IDStrong. CarGurus Data Breach1TechCrunch. CarGurus Data Breach Affects 12.5 Million Accounts

The leaked records contained full names, email addresses, phone numbers, physical addresses, IP addresses, and user account identifiers.1TechCrunch. CarGurus Data Breach Affects 12.5 Million Accounts For users who applied for auto financing through the platform, the exposed data also included pre-qualification application details and outcomes.6WFMD. CarGurus Breach Linked to ShinyHunters Exposes 12.4M Records At least one analysis indicated that Social Security numbers for a subset of finance applicants may have been included, though CarGurus has not confirmed this.7OptMsg. Breach Breakdown: CarGurus

Of the 12.4 million records ShinyHunters claimed, roughly 70 percent had appeared in earlier, unrelated breaches. About 3.7 million records were newly exposed through this incident.8Fox News. CarGurus Breach Linked to ShinyHunters Exposes 12.4M Records

The Class Actions Filed Against CarGurus

Within days of the disclosure, plaintiffs filed at least three putative class actions in the U.S. District Court for the District of Massachusetts:

The Infield and Ramirez complaints both bring claims for negligence, breach of implied contract, unjust enrichment, and declaratory judgment. Ramirez adds a claim under the California Consumer Privacy Act.9Top Class Actions. Class Actions Claim CarGurus Data Breach Exposed Consumers’ PII The Campbell complaint alleges cybersecurity negligence, privacy violations, and breach of contract.10JoinTheClaim. CarGurus Data Breach Lawsuits Filed in the US After ShinyHunters Incident

The core theory is the same across the cases: CarGurus failed to implement reasonable data security, and then failed to give affected consumers timely notice once the breach became public.2Bloomberg Law. CarGurus Hit With Lawsuit Flurry Over ShinyHunters Data Breach

What the Plaintiffs Are Asking For

The plaintiffs seek monetary damages and injunctive relief. The requested injunction would require CarGurus to adopt stronger data security practices and provide lifetime identity theft protection for class members. The Infield and Ramirez plaintiffs are represented by Pastor Law Office, Lynch Carpenter, Stanzler Levine, and Migliaccio & Rathod.9Top Class Actions. Class Actions Claim CarGurus Data Breach Exposed Consumers’ PII

Current Status of the Litigation

On March 25, 2026, Judge Myong J. Joun administratively closed the Ramirez case and directed all further docket activity to the Infield case as the lead proceeding.11PACER Monitor. Ramirez v. CarGurus, Inc. The consolidated litigation remains active as of mid-2026. No motions to dismiss have been publicly reported, no settlement has been reached, and no trial date has been set.9Top Class Actions. Class Actions Claim CarGurus Data Breach Exposed Consumers’ PII There is nothing to “sign up for” yet; if the case reaches a settlement or a certified class, notice would go to affected users at that point.

What CarGurus Has Said

CarGurus told TechCrunch the incident was a “now-contained cybersecurity incident.”1TechCrunch. CarGurus Data Breach Affects 12.5 Million Accounts In a May 1, 2026 update on its dealer-facing site, the company said an independent cybersecurity firm had determined the incident was “limited in scope and contained,” and that the exposed data “mainly included publicly available dealer names and contact details.” It said dealer passwords, data feeds, APIs, CRM systems, and core products were not compromised, and that it had contacted partners directly in rare cases involving sensitive dealership information.12CarGurus Dealers. Cybersecurity Incident Information

That description differs sharply from the consumer-facing scope reflected in Have I Been Pwned’s catalog and the lawsuits. CarGurus did not announce credit monitoring or identity theft protection for affected users, and warned that emails claiming information was compromised were “most likely scams from opportunistic third parties.”12CarGurus Dealers. Cybersecurity Incident Information

What to Do If You Had a CarGurus Account

Check your exposure first. Enter your email address at haveibeenpwned.com to see whether it appears in the CarGurus dataset. Users who applied for financing on the platform are the most exposed group, since their records went beyond basic contact information.6WFMD. CarGurus Breach Linked to ShinyHunters Exposes 12.4M Records

Security researchers have recommended standard post-breach steps: place a fraud alert or credit freeze with the three major credit bureaus, monitor your financial accounts for unusual activity, and be alert for phishing emails or phone calls that reference the breach.6WFMD. CarGurus Breach Linked to ShinyHunters Exposes 12.4M Records Because CarGurus is not offering credit monitoring, any protection you want is one you’ll need to arrange yourself. If the consolidated Infield litigation produces a settlement or certified class, affected users would receive notice of how to participate at that time.