A major car dealership cyberattack has AutoNation and others struggling into a second week (2024)

Car dealerships around the U.S. are struggling to provide service as major system provider CDK Global’s core products remain down for the fifth day in a row.

Suggested Reading

American Airlines has stopped training new pilots

Paramount+ is getting on the streaming price hike bandwagon

Nvidia's head of finance and investor relations is leaving for a startup

Suggested Reading

American Airlines has stopped training new pilots

Paramount+ is getting on the streaming price hike bandwagon

Nvidia's head of finance and investor relations is leaving for a startup

The Fed needs to start cutting rates now, strategist says

The Fed needs to start cutting rates now, strategist says

CDK, which serves almost 15,000 car dealerships across North America, was first hit by an attack early morning on June 19. That forced it to shut down its systems, which are relied on by dealerships to conduct most of their routine business. Later that evening, a second “cyber incident” occurred, according to a message to customers.

Advertisem*nt

Related Content

UnitedHealth Group says it paid a ransom to protect patient data from a cyberattack

Cyber attackers are using AI to get better, Microsoft executive says

Related Content

UnitedHealth Group says it paid a ransom to protect patient data from a cyberattack

Cyber attackers are using AI to get better, Microsoft executive says

CDK provides a number of services to dealerships, including online appointment scheduling, messaging tools, and e-signing, according to its website. In addition to car dealerships, CDK works with more than 1,000 heavy truck locations across the continent.

Advertisem*nt

“Late in the evening of June 19, we experienced an additional cyber incident and proactively shut down most of our systems,” CDK said in a statement last week. “We remain vigilant in our efforts to reinstate our services and get our dealers back to business as usual as quickly as possible.”

Advertisem*nt

Although most dealerships haven’t completely closed business, activity has slowed because of a lack of access to their usual tech — and a reluctant switch to the old fashioned art of using pens and paper. A dealer in Philadelphia last week told Bloomberg News that it was struggling to accommodate customers, since they couldn’t print out repair orders or even access customer records.

Group 1, which operates 202 dealerships across the U.K. and U.S., said Monday that its U.S. operations have been disrupted by the cyber incident and that its dealers will conduct business using “alternative processes.” CDK told Group 1 that restoring its dealer management system will “require several days and not weeks.”

Advertisem*nt

“Our associates are coming together with an unwavering focus on delivering the best possible customer experience,” Group 1 CEO Daryl Kenningham said in a statement. “Their efforts have been nothing short of exemplary. We’d like to thank our team, our customers, and our partners for their patience as we navigate this outage.”

Sonic Automotive, Lithia Motors, and AutoNation have said they are determining the impact of the incident on their operations. AutoNation said Friday that it “immediately” took action to protect its systems and data, noting that its more than 300 locations are open and servicing customers through alternative methods.

Advertisem*nt

Penske Automotive Group said its Premier Truck business uses CDK’s systems and has implemented plans to protect its systems and operate its 48 locations in the U.S. and Canada. CarMax CEO Bill Nash last week said the company does not use CDK’s systems, although there has been a small impact on its work with some dealerships that do.

Bloomberg, citing a person familiar with the matter, reported Friday that the a group claiming to have been behind the hack has demanded tens of millions of dollars in ransom. The group has been identified as the BlackSuit ransomware gang, according to BleepingComputer. BlackSuit became widely known last April and most recently published hundreds of stolen files from a Kansas police department that it claims refused to pay its ransom.

Advertisem*nt

The attack on CDK comes after the Findlay Automotive Group was hit by a cybersecurity attack earlier this month. The company has said its locations across five U.S. states were affected by the cybersecurity breach and that, while dealers stayed open, sales and service operations were hindered.

According to Malwarebytes, the number of known cyberattacks increased 68% in 2023, with ransom demands surging. The largest ransomware of last year was the $80 million demanded by LockBit after an attack on Royal Mail.

Advertisem*nt

Ransomware attacks are “mostly opportunistic,” said Satnam Narang, a senior staff research engineer at Tenable. “Ransomware affiliates will target all of the fish in the sea in hopes of catching a big one because they know that’s where the biggest payout comes from.”

A major car dealership cyberattack has AutoNation and others struggling into a second week (2024)

FAQs

How many car dealerships use CDK? ›

Some 15,000 dealers rely on CDK's dealer management software to run their business, including handling various aspects of buying or leasing a vehicle, such as adding dealer incentives and generating a discount for trade-ins.

Did CDK Global get hacked? ›

CDK Global, a software provider to some 15,000 car dealers, was waylaid by debilitating cyberattacks this week that have had a crippling effect on the auto sales industry.

Who are the CDK hackers? ›

The cybercriminals behind the CDK attack are linked to a group called BlackSuit, Bloomberg reported on Monday, citing Allan Liska of computer security firm Recorded Future. In a June 21 story, the media outlet also said the hackers were demanding tens of millions of dollars and that CDK planned to pay the ransom.

Who is attacking CDK? ›

A hacking group called BlackSuit is behind the cyberattack on CDK Global that's paralyzed car sales across the US, according to Allan Liska, a threat analyst at the security firm Recorded Future Inc.

What's going on with CDK? ›

What's happening: CDK Global, a data provider whose software is used by car dealerships to handle everything from records to scheduling, was hit by cyber attacks on June 19 that caused the company to shut down most of its systems. Cars sit on a Chevrolet dealership's lot on June 20, 2024 in Chicago, Illinois.

What does CDK stand for? ›

Cyclin-dependent kinases (CDKs) are involved in many crucial processes, such as cell cycle and transcription, as well as communication, metabolism, and apoptosis.

What is the most hacked company? ›

And while hacking affects big and small businesses alike, the biggest data breaches inevitably hit some of the most recognizable names.
  • LinkedIn - 165 million.
  • MyFitnessPal - 150 million.
  • Equifax - 148 million.
  • eBay - 145 million.
  • Quora - 100 million.
  • MyHeritage - 92 million.
  • Facebook - 87 million.
Jun 14, 2024

Who bought out CDK? ›

Last April it was announced that CDK Global, Inc., was being acquired by Brookfield Business Partners for $8.3 billion. Under merger agreement terms, CDK shareholders were said to receive $54.87 per share in cash upon completion of the transaction.

What company spun off CDK Global? ›

Effective October 1st, Automatic Data (ADP) completed a spinoff of CDK Global (CDK).

How did a cyberattack take 15000 car dealers offline? ›

How did this all start? CDK's systems first went down around 2 a.m. Eastern time on June 19, on what otherwise would have been a busy day for dealers because of the Juneteenth national holiday. The company told its customers that it had experienced a cyber incident and had shut down a majority of its systems.

Who are the black suit hackers? ›

BlackSuit, a believed Russian and Eastern European hacking group, is behind a ransomware attack on CDK, which has disrupted auto dealerships across the nation since late last week, multiple media reports say. CDK first shut down its management system to 15,000 dealerships June 19.

What is CDK and why is it down? ›

Austin, Texas-based CDK, a provider of software used by 15,000 dealerships, shut down most of its systems after the cyberattacks struck on June 18 and 19. CDK provides SaaS-based CRM, payroll, finance and other key functions for dealerships.

How many customers does CDK Global serve? ›

What is CDK Global? CDK Global is a software vendor headquartered in the U.S. that provides applications and services for the automotive industry. It serves nearly 15,000 dealer locations across North America.

Who owns CDK automotive? ›

On April 7, 2022, CDK Global agreed to be acquired by Brookfield Business Partners and institutional partners for a total enterprise value of $8.3 billion.

What is CDK in the automotive industry? ›

CDK Global is a major player in the auto sales industry. The company, based just outside of Chicago in Hoffman Estates, Illinois, provides software technology to dealers that helps with day-to-day operations — like facilitating vehicle sales, financing, insurance and repairs.

How many dealers use Dealertrack? ›

Origination Solutions

That's over 22,000 dealers throughout North America, linked to their choice of our 1600+ lenders.

Top Articles
Latest Posts
Article information

Author: Aron Pacocha

Last Updated:

Views: 5921

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.