dealers.cargurus.com
2026 Cyberattacks Target Automotive Sector: CarGurus Breach and Vendor Incident
Article Content
In 2026, the automotive retail sector experienced significant cyberattacks, including a breach at CarGurus and a vendor incident affecting Nissan and Infiniti dealerships. The CarGurus breach, attributed to the ShinyHunters group, involved vishing attacks that led to the exfiltration of 6.1 gigabytes of data, impacting over 12.4 million records, although sensitive data was reportedly limited. The vendor incident involved the Everest ransomware group exploiting weak FTP credentials without multi-factor authentication, affecting a third-party vendor connected to Nissan and Infiniti. Both incidents highlight the vulnerabilities within the automotive supply chain and underscore the need for enhanced cybersecurity measures. CarGurus has since confirmed that their systems remain operational and that no sensitive dealer information was compromised. The investigations into both incidents have been corroborated by independent cybersecurity firms.
Key Points: • CarGurus experienced a data breach due to vishing attacks, affecting over 12.4 million records. • The Everest ransomware group exploited a vendor's weak FTP credentials, impacting Nissan and Infiniti dealerships. • Both incidents emphasize the importance of securing third-party vendor connections in the automotive sector.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.