
Edmunds.com Breach
Jan 24, 2026
163,310 rows
What happened in the Edmunds.com Breach?
DataBreach.com Team · January 26th 2026, 7:00 pm EST
In late January 2026, the notorious cybercriminal group ShinyHunters (often operating under or alongside the "Scattered Lapsus$ Hunters" collective) allegedly released a significant cache of data stolen from the automotive information platform Edmunds.com.
The breach came to light when a threat actor known as "Wadjet" posted the sensitive dataset on the revived illicit marketplace BreachForums, claiming it contained extensive personally identifiable information (PII), user engagement metrics, and account metadata. Security analysts believe the compromise may have stemmed from a vulnerability in a third-party vendor or a social engineering attack-tactics consistent with ShinyHunters' recent "vishing" (voice phishing) campaigns against major corporations.










