Skip to content
NetarxImpact Database
Vishing (Voice Phishing)UnknownReported

CarGurus hit by vishing that harvested Okta, Microsoft and Google SSO codes

CarGurus · Technology · United States · February 13, 2026

What happened

Automotive marketplace CarGurus was attacked on 13 February 2026. ShinyHunters said it used vishing to trick employees into surrendering single sign-on codes from Okta, Microsoft and Google, and claimed roughly 1.7 million records plus more than 12 million email addresses and internal corporate data. CarGurus said the incident was contained and limited in scope, that dealer systems and APIs were not compromised, and that no broad set of highly sensitive data appeared to be involved.

How the deception worked

Callers impersonating trusted internal parties telephoned CarGurus staff and, under the cover of an account or access problem, asked them to read back the one-time codes generated by Okta, Microsoft and Google sign-in prompts. Because the attacker was simultaneously driving a real login, each code the employee recited completed the attacker's session rather than the employee's. The crew then pulled marketplace user and corporate records and moved to extortion, threatening a dark web release if CarGurus did not engage quickly.

The control that would have caught it· our reading, not a claim from the sources

One-time codes readable aloud are the weakness; migrating SSO to FIDO2 passkeys makes there be nothing for the caller to ask for.

Sources (2)

  1. CarGurus probes cyberattack, ShinyHunters claims theft of 1.7M records in data breach
    Dealership Guy News·news.dealershipguy.comOpen ↗
  2. CarGurus Reported Data Breach
    ComplyAuto·complyauto.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.