The Clunker Junker Allegedly Breached, 1M Customer Records Offered for Sale

A threat actor claims to have stolen more than 1 million records from The Clunker Junker and is offering the alleged customer database for sale.
Threat actor post claiming The Clunker Junker was breached and more than 1 million customer records were stolen and offered for sale.

A threat actor claims to have breached U.S. vehicle-buying service The Clunker Junker and exfiltrated a database containing more than 1 million customer records, which is now being offered for sale.

The Sept. 19, 2026 listing alleges the attacker gained unauthorized access through an authentication bypass involving SQL injection. The actor is asking $700 for the purported database and published a sample containing approximately 2,000 records as evidence of the compromise.

BreachNews is not publishing or linking to the sample because it contains personally identifiable information belonging to alleged customers.

The Clunker Junker had not issued any public statement confirming the alleged breach at time of publication. BreachNews has also not independently verified the claimed intrusion method or the actor’s assertion that the database contains information belonging to more than 1 million customers.

Sample allegedly contains customer and vehicle information

The database fields displayed by the threat actor indicate that the alleged exposure could extend beyond basic contact information.

According to the listing, records can contain names, postal addresses, phone numbers, email addresses, password hashes and IP addresses. Vehicle-related information allegedly includes model years, manufacturers, models, trims, mileage, colors, VINs, vehicle condition information and owner names.

Other database fields appear related to account administration, password resets, customer claims, accepted offers and transaction workflows. The listing also indicates that some records could contain payment processor customer identifiers, although the sample does not establish that payment card information was exposed.

The presence of password hashes could create an additional credential risk if the database is authentic. The sample provided by the actor appears to contain bcrypt-formatted password hashes, rather than plaintext passwords.

BreachNews is not reproducing individual records, VINs, email addresses, phone numbers, IP addresses or other personal information contained in the actor’s sample.

Actor claims authentication bypass led to breach

The threat actor alleges that The Clunker Junker was compromised using an authentication bypass involving SQL injection.

No technical evidence has been publicly provided that independently establishes the claimed attack path, and The Clunker Junker has not confirmed that such a vulnerability existed.

The actor also claims more than 1 million customer records were exfiltrated. That figure should be treated cautiously.

The Clunker Junker’s own website currently states that the company has served more than 300,000 customers and sold approximately 600,000 vehicles. The difference does not necessarily disprove the threat actor’s claim because a database can contain multiple records associated with the same individual, historical accounts or other categories of users.

However, there is currently insufficient evidence to conclude that 1 million unique people were affected.

The Clunker Junker operates nationwide

The Clunker Junker is a Florida-based online vehicle-buying service that connects people selling used, damaged and junk vehicles with buyers, salvage yards, towing providers and other partners across the United States.

The company says it operates across all 50 states and has spent more than a decade building relationships with local vehicle buyers, towing companies and auctions.

The Clunker Junker describes itself as a small, family-owned business and says its platform provides customers with vehicle offers before coordinating pickup and payment through its network.

The potentially sensitive nature of the alleged database reflects the information required to process those transactions. Customers can provide both personal information and detailed information about vehicles they are attempting to sell.

Database offered for $700

The threat actor is offering the purported database for $700 and describes the price as negotiable.

Publishing a sample alongside a database sale is commonly used by data sellers to demonstrate possession of information they claim to have stolen. A sample alone, however, does not establish the full size of the database, when all of the records were collected or whether every record originated from the claimed victim.

If the information is authentic, the combination of customer contact information, vehicle ownership details and account data could increase phishing and identity-related risks for affected individuals.

The alleged password hashes would also make password reuse a concern if attackers were able to recover any underlying credentials.

The Clunker Junker had not publicly confirmed the incident at time of publication, and the number of affected individuals remains unknown.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site