Data breach
CarMax
- Records
- 431,610
- Breach date
- 24 January 2026Estimated
- Added
- 25 January 2026
What was exposed
1 type of data · 3 more reported
- Email addresses431,610
- NamesReported, not counted
- Home addressesReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Data linked to CarMax, the used-car retailer, surfaced in an extortion attempt in January 2026. According to our investigation team, the listing contains 431,610 rows of data with an estimated attack date of January 24, 2026. ShinyHunters, a cybercrime group known for extorting companies after stealing their data, claimed responsibility in posts reviewed by The Register, saying it took more than 500,000 records totaling 1.7 GB compressed from the car-buying platform. The group told the outlet the CarMax theft came from an earlier intrusion separate from other attacks it claimed the same week. No ransom amount, proof of payment, or confirmed victim count has been independently established.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Fall 2025: Scattered Lapsus$ Hunters, a group with ties to ShinyHunters, posted CarMax on its now-defunct data-leak site and said at the time that the company was among dozens whose Salesforce environments it had compromised, according to The Register.
January 27, 2026: The Register reported that ShinyHunters claimed it stole more than 500,000 CarMax records. The outlet noted that none of the three companies named that week, including CarMax, responded to its inquiries.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
The number of email addresses in the listing could not be determined from the available fields. Coverage of the ShinyHunters claims indicates the stolen files also contained names, home addresses, phone numbers, and account details, though those categories come from the criminals' own descriptions rather than a confirmed company notice.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, email addresses, home addresses, and phone numbers give scammers the raw material for targeted phishing. A message that uses your real name and references car buying or vehicle financing is far more convincing than generic spam, and criminals often time these emails to follow a breach announcement while attention is high.
Phone numbers open the door to smishing, which is phishing by text message, and to voice scams in which callers pose as a bank, a dealer, or a support agent. Home addresses can support more elaborate fraud attempts and, in rare cases, unwanted physical contact. Anyone whose account details appeared in the data should assume those accounts are at risk of takeover, especially if the same password was reused elsewhere.
What Should You Do If You Were Affected?
Change the password on your CarMax account, and change it anywhere else you reused it. Use a unique, long password for each important account.
Turn on multi-factor authentication wherever it is offered. An app-based or hardware key method is stronger than text codes.
Treat unexpected emails, texts, and calls about your CarMax account, a vehicle order, or a payment problem with suspicion. Do not click links or share codes; contact the company through its official website instead.
Watch your financial statements for charges you do not recognize, and consider a credit freeze or fraud alert with the major credit bureaus if your home address was exposed.
Delete or archive suspicious messages rather than responding to them.
