CDK cyberattack shuts down auto dealerships across the U.S. Here's what to know. (2024)

MoneyWatch

By Megan Cerullo

Edited By Aimee Picchi

/ CBS News

CDK Global, a company that provides auto dealerships across the U.S. with software for managing sales and other services, was shut down for a third straight day Friday after cyberattacks crippled the platform.

The outage is disrupting roughly 15,000 car sellers that depend on CDK's dealer management software to run their businesses, including vehicle sales. Some dealership employees have resorted to pen and paper to handle transactions, but said most deals had ground to a halt. CDK has not indicated when its systems will be back up and running, but suggested the outage could last several days.

"We are actively investigating a cyber incident," a CDK spokesperson told CBS News. "Out of an abundance of caution and concern for our customers, we have shut down most of our systems and are working diligently to get everything up and running as quickly as possible."

CDK, which said it had restored some services on Wednesday, told CBS MoneyWatch on Thursday afternoon that its systems were again offline after it suffered another cyberattack.

"Late in the evening of June 19, we experienced an additional cyber incident and proactively shut down most of our systems," a CDK spokesperson said. "In partnership with third-party experts, we are assessing the impact and providing regular updates to our customers. We remain vigilant in our efforts to reinstate our services and get our dealers back to business as usual as quickly as possible."

Calls to a CDK customer support hotline produced a continuous busy signal. But the company's automated recording said the outage could affect dealerships for days, according toPC Mag. The message told callers, "At this time, we do not have an estimated time frame for resolution and therefore our dealers' systems will not be available likely for several days," the publication reported.

The message also warned callers that "bad actors" posing as CDK support staff were trying to obtain customers' credentials in what are known as phishing attacks, according to The Associated Press.

The number of cyberattacks has been on the rise in the last year, with more than 3,200 data breaches in 2023, a 78% jump from the prior year, according to a new study from data firmSOAX. Those breaches impacted more than 65 million victims last year, it added.

What is CDK?

CDK's dealer management system, or DMS, lets car vendors operate their business, including handling payroll, inventory, customer relations and office operations. The technology also enables dealers to line car buyers line up with financing and insurance.

On its website, it also touts its cybersecurity capabilities. "CDK Cybersecurity Solutions provide a three-tiered cybersecurity strategy to prevent, protect and respond to cyberattacks so you can defend your dealership," it says.

Brookfield Business Partners, a Toronto-based private equity firm, acquired the company in 2022 in adealvalued at more than $8 billion.

When did the cyberattack begin?

The cyberattack on CDK Global began Tuesday evening, Bleeping Computer, a cybersecurity news site, reported Wednesday, taking the 15,000 car dealerships it serves offline.

As mentioned above, CDK said it suffered another cyberattack on Wednesday evening. It is not currently known who, or what group, is behind the cyberattacks.

Mike Stanton, CEO of the National Automobile Dealers Association, said in a statement on Friday that "dealers are very committed to protecting their customer information and are actively seeking information from CDK to determine the nature and scope of the cyber incident so they can respond appropriately."

How are dealerships responding?

Some dealerships appeared to get creative to continue doing business during the outage. Dealership employees posted about the outage onRedditWednesday, sharing that they were relying on spreadsheets and sticky notes to sell customers small parts and make repairs, but that they weren't making any large transactions.

One employee asked other dealership employees, "How many of you are standing around because your whole shop runs on CDK?" under the heading "CDK down," with users in Wisconsin and Colorado confirming their dealership transaction systems were offline.

—The Associated Press contributed to this report.

    In:
  • Technology
  • CDK Global
  • Cybersecurity and Infrastructure Security Agency
  • Cyberattack
  • Ransomware

Megan Cerullo

Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News 24/7 to discuss her reporting.

CDK cyberattack shuts down auto dealerships across the U.S. Here's what to know. (2024)

FAQs

What is the CDK cyber attack? ›

Hackers took down CDK's sales and client management software tools two weeks ago, crippling the auto industry in what the company called a "ransom event."

What's going on with CDK? ›

CDK Global faces multiple lawsuits from dealerships crippled by cyberattack. CDK Global faces at least eight lawsuits from auto dealerships over cyberattacks that took down the software provider's dealer management system, crippling car sellers' operations.

How many dealerships use CDK? ›

Fallout from the ransomware attack has dragged into a third week for the 15,000 car dealerships that rely on CDK's sales, inventory management and customer relations systems to run their businesses.

What is CDK in automotive? ›

CDK offers cloud-based software to more than 15,000 auto dealerships across North America that manages vehicle acquisitions, sales, financing, insuring, repairs and maintenance.

Did CDK pay the ransom? ›

It is unclear whether CDK chose to pay the ransom, although one news outlet reported that they did. The software company managed to restore services to a small test group of dealers a week after the attack and has since been bringing more dealerships online.

Who hacked CDK Global? ›

Multiple outlets later reported that the group behind the attack was identified as BlackSuit, a cybercriminal team that spun off of an older, Russian-linked hacking group called RoyalLocker, according to Reuters.

Which dealerships use CDK Global? ›

Five of the six — Asbury Automotive Group, AutoNation, Group 1 Automotive, Lithia Motors and Sonic Automotive — use CDK as their primary DMS provider. Penske Automotive Group said it does not use CDK's DMS at franchised dealerships in the U.S. or the U.K. but does for its Premier Truck Group.

Who bought out CDK? ›

Last April it was announced that CDK Global, Inc., was being acquired by Brookfield Business Partners for $8.3 billion. Under merger agreement terms, CDK shareholders were said to receive $54.87 per share in cash upon completion of the transaction.

What company spun off CDK Global? ›

On October 1, 2014, ADP Dealer Services division was spun-off to form the independent company CDK Global.

How much does CDK cost a dealership? ›

The outage would have cost care dealerships millions of dollars more if it stretched on. According to an estimate by Anderson Economic Group, CDK's system collapse could result in approximately $944 million in direct losses due to business interruptions for affected car dealers if the outage lasted a full three weeks.

What company owns the most dealerships? ›

In comparison, Lithia Motors has continuously expanded its dealership network without falter since 2014, acquiring 32 locations in 2022 alone. With over 290 storefronts, it now claims to have surpassed AutoNation in size, making it the biggest dealer group in the U.S.

Who is the largest auto parts supplier in the world? ›

Bosch continues to be the world's largest automotive supplier, and Denso remains the world's second largest. Next in line are ZF, Hyundai Mobis, and Magna. On the other hand, CATL moved up to sixth place in FY2022 due to increased battery demand.

What does CDK stand for? ›

Cyclin-dependent kinase, a major class of enzymes involved in the regulation of the cell cycle.

Is CDK still down? ›

CDK Global said Tuesday that “substantially all” of the car dealerships it serves are back online, two weeks after the software maker was struck by a crippling ransomware attack.

What is a CDK outage? ›

In this incident, CDK Global was infected with ransomware taking many of its core systems offline. As CDK Global is a trusted provider of software services to many organizations in the automotive industry, the ransomware impact was widespread.

What are the top 3 types of cyber attacks? ›

What are the 12 most common types of cyberattacks?
  • Malware.
  • Denial-of-Service (DoS) Attacks.
  • Phishing.
  • Spoofing.
  • Identity-Based Attacks.
  • Code Injection Attacks.
  • Supply Chain Attacks.
  • Social Engineering Attacks.
May 14, 2024

What are the 4 types of cyber attack we have looked at? ›

  • Malware attack. Malware is the name given to hostile or dangerous elements that usually breach a network through vulnerability. ...
  • Phishing attack. This type of attack usually occurs over emails and targets personal information. ...
  • Drive-by attack. ...
  • Password attack.

References

Top Articles
Latest Posts
Article information

Author: Kieth Sipes

Last Updated:

Views: 5795

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.