Carvana Data Breach Exposes Driver’s License Numbers and Personal Records

Published: 6 October 2026
Automotive Technology data breach illustration
Breach Discovery: September 2026Breach Notification: October 2026

Carvana notified customers that a document containing their personal information, including names, dates of birth, driver’s license numbers, addresses, emails and phone numbers, was accidentally disclosed to the wrong recipient. Carvana discovered the mistake in September 2026 and says there’s no evidence of misuse so far. Affected customers should enroll in the free IDX identity protection services offered by Carvana before the March 2027 deadline.

CompanyCarvana
IndustryAutomotive Technology
Data Types ExposedFull Names, Dates of Birth, Driver’s License Numbers, Home Addresses, Email Addresses, Phone Numbers
People AffectedNot Publicly Disclosed
Attack MethodInadvertent Disclosure
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Carvana Data Breach?

Carvana, the online used car retailer, has begun notifying customers about a data exposure involving their personal information. According to the company’s own notice letter, a document holding customer records was sent to the wrong recipient by mistake. This was not described as a hacking event or cyberattack. Instead, Carvana frames it as an inadvertent disclosure of a document that should have stayed internal.

The company says it discovered the error in September 2026. As a result, Carvana reached out to the person who received the misdirected document. The notice letter itself is dated October 2026 and was mailed to affected customers through certified mail. Because this was a mistaken disclosure rather than an external intrusion, the details around how the document was created or sent have not been made public.

Carvana states it has no evidence the exposed information has actually been misused. However, that does not mean no risk exists. The company says it contacted the person who received the document directly. A copy of the notification letter was also filed with the Massachusetts state government, which is where many of the surviving details about this event come from. Carvana has not disclosed publicly how many customers were affected in total.

Because Carvana has only described this incident through a notification letter, much about the full scope remains unknown. The company has not detailed exactly how the document was misdirected or whether any internal safeguards failed. In addition, there is no public statement describing a forensic investigation into the cause of the error. This Carvana data breach appears, based on available information, to be a single document disclosure rather than a broader network compromise.

Who was affected?

The individuals affected by this incident are Carvana customers whose personal information appeared in the disclosed document. Carvana handles records tied to vehicle purchases, financing, registration and delivery. Therefore, the exposed document likely originated from one of these customer-facing processes.

Carvana has not publicly disclosed the total number of people affected by this breach. The notice letter does not state how many documents existed or how many customers had information within them. As a result, this page describes the incident using only what Carvana’s letter has confirmed.

Because Carvana operates as a nationwide online retailer, affected customers could be located across the United States. There is no indication in the notice letter that this incident was limited to one region or state. The letter was filed with Massachusetts regulators, which suggests at least some affected customers live there. However, nothing in the letter rules out a broader customer base being involved.

What Information Was Potentially Exposed?

According to the notice letter, the document contained several categories of sensitive personal details. This information could be useful to a scammer attempting to impersonate someone or open new accounts. Below is the list of data types Carvana says may have been included.

  • Full names
  • Dates of birth
  • Driver’s license numbers
  • Home addresses
  • Email addresses
  • Phone numbers

Even without a Social Security number, this combination of information gives a bad actor a lot to work with. For example, a driver’s license number paired with a full name and date of birth can support identity verification fraud. This means someone could attempt to open a new account, apply for credit, or impersonate the victim in other ways.

In addition, the home address, email and phone number together create an opening for convincing phishing attempts. A scammer could craft a message that appears to come from a car lender or dealership. Because the victim’s real information would be included, these messages might look legitimate at first glance. As a result, affected individuals should treat unexpected contact with real suspicion, even if it references accurate personal details.

What is the company doing?

Carvana says it has been in contact with the person who received the misdirected document. The company also states it has no evidence the information has been misused to date. This response suggests Carvana took some step to follow up directly with the recipient rather than simply mailing notice letters.

As a protective measure, Carvana is offering affected customers free identity theft protection services through IDX, a ZeroFox company. These services include 12 months of credit monitoring, CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and fully managed identity theft recovery support. Customers have been given until March 2027 to enroll, based on a 60-day window from the date they received their letter.

The notice letter also informed recipients of rights available under Massachusetts law. These include the right to obtain a police report and the right to request a security freeze from the credit bureaus at no charge. Carvana says it is coordinating with relevant authorities to help prevent similar incidents going forward. The company also filed formal notification of this incident with the Massachusetts Office of Consumer Affairs and Business Regulation.

What Should Affected Individuals Do?

Enroll in the Free Identity Protection Services

If you received a notice letter from Carvana, your first step should be enrolling in the free IDX identity protection services. This offer includes credit monitoring, CyberScan monitoring and a $1,000,000 insurance reimbursement policy. Because enrollment closes in March 2027, it’s worth acting on this soon rather than setting the letter aside.

These services exist specifically to catch misuse early, before it turns into a larger financial problem. For example, CyberScan monitoring can alert you if your information appears on dark web marketplaces. This gives you a head start on locking down accounts or alerting your bank if your data turns up somewhere it shouldn’t be.

Consider a Credit Freeze or Fraud Alert

Because driver’s license numbers and dates of birth were included in this exposure, a credit freeze is worth serious consideration. A freeze stops most lenders from accessing your credit file. This means a scammer generally cannot open new credit accounts in your name while the freeze is active.

You can request a free security freeze with Equifax, Experian and TransUnion individually. Alternatively, a fraud alert requires lenders to take extra verification steps before approving credit in your name. Either option adds a meaningful layer of protection, and under Massachusetts law, residents are entitled to request these freezes at no cost.

Monitor Your Credit Reports and Accounts Closely

Regularly checking your credit reports is one of the simplest ways to catch identity theft early. You can access free reports from all three major bureaus at annualcreditreport.com. Review each report for accounts or inquiries you don’t recognize.

In addition to credit reports, keep an eye on your regular bank and credit card statements. Look specifically for small or unusual charges, since scammers sometimes test stolen information with minor transactions first. If you spot anything suspicious, report it to your financial institution immediately.

Stay Alert to Phishing Attempts

Because your name, email, phone number and address may have been exposed, phishing attempts are a realistic risk. Scammers can use real personal details to make fake messages seem legitimate. Be especially cautious of any message referencing your vehicle, your Carvana account, or this breach specifically.

Before clicking links or sharing information, confirm the request through a phone number or website you already trust. Carvana will not ask for sensitive information through unsolicited texts or emails. If something feels off, it’s safer to contact the company directly using verified contact information rather than responding to the message itself.

Know Your Legal Options

If you received a notice from Carvana about this incident, you may have legal rights worth exploring. Companies that handle sensitive records like driver’s license numbers are expected to protect them carefully. When that doesn’t happen, affected individuals sometimes have grounds to pursue compensation.

Speaking with a data breach attorney can help clarify whether you qualify for a claim. Many offer free consultations, so there’s little downside to asking questions about your situation. This is especially worth considering if you later discover signs of misuse tied to your exposed information.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →