carvivo.com data breach

carvivo.com

What Happened

In late May 2026, French SaaS provider Carvivo, which offers lead-management tools for automotive dealerships, discovered a security incident involving its platform that led to unauthorized access to contact and prospect data. The company reported that the breach, detected on 27 May 2026 and disclosed in customer emails on 1 June 2026, exposed personal contact information such as names, email addresses, phone numbers, and update dates for customer/prospect records, but did not include passwords, payment data, IDs, or other highly sensitive documents. Threat actors on a dark web forum simultaneously claimed to be selling a large Carvivo marketing and CRM dataset covering 2017–2026, reportedly containing data on around 15 million people, 3.2 million unique email addresses, over 5 million vehicle registrations, and records for 1,706 garages and dealerships, including commercial history, lead notes, and vehicle details. While these figures from the attackers have not been fully and independently verified, Carvivo has confirmed an exposure via unauthenticated URLs / access-control flaws on its web application, initiated regulatory notifications (including to the CNIL), and launched remediation and infrastructure audits to close the exploited vulnerabilities.

Compromised Assets

  • email
  • phone

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.

Related Breaches