MediumBreachHave I Been Pwned — public breach catalog· 20 Feb 2026

CarMax — 431K accounts

Severity: Medium · Kind: Data breach

Plain-English summary on the way

We've ingested this item but haven't summarised it yet. Read the upstream advisory using the link below in the meantime — the AI summary will appear here once the next run completes.

From the source

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses.

Breach facts

Accounts affected
431,371
Verified
Yes
Sensitive
No
Domain
carmax.com
Data exposed
Email addressesNamesPhone numbersPhysical addresses

Was this useful?

00000Sign in to react

Plain-English summaries are AI-generated and reviewed for tone, not technical accuracy. For incident response, always rely on the original source linked above.