CDK Global Cyberattack: 15,000 Car Dealerships Disrupted by BlackSuit Ransomware, Forcing Manual Processes and Financial Issues

North America, Various United States of America
BlackSuit ransomware gang believed to be behind the attack
CDK Global cyberattack affects 15,000 car dealerships in North America
Disruption of sales, financing, inventory, service and back office functions for dealerships
Negotiations ongoing between CDK and threat actors for decryptor and data leak prevention
Significant issues with financial transactions, inventory management, sales processes, financing and insurance for dealerships
CDK Global Cyberattack: 15,000 Car Dealerships Disrupted by BlackSuit Ransomware, Forcing Manual Processes and Financial Issues

A major cyberattack on CDK Global, a leading software provider for auto dealerships, has caused widespread disruption to businesses across North America. Approximately 15,000 car dealerships in the US and Canada have been affected by the attack.

CDK Global provides software-as-a-service (SaaS) used by car dealerships for sales, financing, inventory, service, and back office functions. The outage has forced many dealerships to switch to manual processes due to the disruption of these critical systems.

The BlackSuit ransomware gang is believed to be behind the attack. Negotiations between CDK and the threat actors are ongoing in an attempt to receive a decryptor and prevent data leakage. The group launched in May 2023 and is linked to attacks on at least 350 organizations worldwide since September 2022, with more than $275 million in ransom demands.

The outage has caused significant issues for car dealerships, including problems processing financial transactions for deals and managing inventory. Dealers have had to rely on manual methods such as spreadsheets and sticky notes to sell small parts and make repairs, but large transactions are not being processed.

Ford is providing assistance to its dealers by offering alternative processes for sales and service support. However, the impact of the outage extends beyond just sales and services. Dealerships have also reported issues with financing and insurance, rebates and incentives, payroll systems, vehicle repair/maintenance services, and more.

The cyberattack on CDK Global is not an isolated incident. In recent years, there has been a surge in ransomware attacks targeting various industries. These attacks can cause significant damage to businesses and their customers. It is essential for organizations to take steps to protect themselves from such threats, including implementing robust cybersecurity measures and regularly backing up critical data.



Confidence

96%

Doubts
  • Is it confirmed that the BlackSuit ransomware gang is behind the attack?
  • What percentage of dealerships have been fully restored to normal operations?

Sources

98%

  • Unique Points
    • CDK Global is experiencing an IT outage caused by the BlackSuit ransomware attack.
    • BlackSuit ransomware gang is responsible for CDK Global’s IT disruption.
    • Negotiations between CDK and BlackSuit are ongoing to receive a decryptor and prevent data leakage.
    • CDK provides software-as-a-service (SaaS) used by car dealerships for sales, financing, inventory, service, and back office functions.
    • Car dealerships have had to switch to manual processes due to the outage.
    • Penske Automotive Group and Sonic Automotive were also impacted by the CDK outage.
    • CDK’s dealer management system (DMS) and customer relationship management (CRM) system were affected.
    • Threat actors are posing as CDK agents or affiliates to gain unauthorized access to dealership systems.
    • BlackSuit ransomware gang launched in May 2023 and is believed to be a rebrand of the Royal ransomware operation.
    • Royal Ransomware, now BlackSuit, is linked to attacks on at least 350 organizations worldwide since September 2022 and more than $275 million in ransom demands.
  • Accuracy
    • BlackSuit ransomware gang is responsible for CDK Global’s IT disruption.
    • Negotiations between CDK and BlackSuit are ongoing to receive a decryptor and prevent data leakage.
    • CDK provides software-as-a-service (SaaS) used by car dealerships for sales, financing, inventory, service, and back office functions.
  • Deception (100%)
    None Found At Time Of Publication
  • Fallacies (95%)
    The article contains several statements made by sources familiar with the matter and companies affected by the CDK Global outage. These statements are not fallacies but rather facts being reported. The author also provides context and background information about the BlackSuit ransomware gang, which is not a fallacy but rather relevant information to help understand the situation. However, there is one instance of an appeal to authority when the author mentions that Bloomberg reported CDK's negotiations with the ransomware gang before BleepingComputer did. This does not affect the overall score significantly as it is a minor infraction and does not detract from the accuracy or validity of the article's content.
    • The same sources, who provided information on condition of anonymity, told BleepingComputer that CDK is currently negotiating with the ransomware gang to receive a decryptor and not leak stolen data.
  • Bias (100%)
    None Found At Time Of Publication
  • Site Conflicts Of Interest (100%)
    None Found At Time Of Publication
  • Author Conflicts Of Interest (100%)
    None Found At Time Of Publication

100%

  • Unique Points
    • Cyberattacks hit CDK Global on Wednesday, June 23, 2024.
    • Approximately 15,000 auto dealerships in the US and Canada were affected.
  • Accuracy
    • CDK Global is a major software provider for the auto industry.
    • CDK provides software-as-a-service (SaaS) used by car dealerships for sales, financing, inventory, service, and back office functions.
  • Deception (100%)
    None Found At Time Of Publication
  • Fallacies (100%)
    None Found At Time Of Publication
  • Bias (100%)
    None Found At Time Of Publication
  • Site Conflicts Of Interest (100%)
    None Found At Time Of Publication
  • Author Conflicts Of Interest (100%)
    None Found At Time Of Publication

98%

  • Unique Points
    • CDK Global, a software provider for auto dealers, experienced cyber incidents this week resulting in system outages.
    • Auto dealers and car shoppers have been affected by the CDK Global outages, with some reverting to manual operations.
    • The CDK Global outage has caused issues with processing financial transactions for deals.
    • CDK Global reported two separate cyber incidents this week and does not have an estimated time frame for resolution.
    • Manual workarounds are taking longer time to complete sales and repairs at dealerships affected by the CDK Global outage.
    • Parts inventory management is also affected due to the CDK Global outage, causing issues with replenishing parts from manufacturers.
  • Accuracy
    • CDK Global experienced cyber incidents this week resulting in system outages.
    • Negotiations between CDK and BlackSuit are ongoing to receive a decryptor and prevent data leakage.
    • Approximately 15,000 auto dealerships in the US and Canada were affected.
  • Deception (100%)
    None Found At Time Of Publication
  • Fallacies (100%)
    None Found At Time Of Publication
  • Bias (100%)
    None Found At Time Of Publication
  • Site Conflicts Of Interest (100%)
    None Found At Time Of Publication
  • Author Conflicts Of Interest (100%)
    None Found At Time Of Publication

96%

  • Unique Points
    • CDK cyberattacks could lead to litigation from consumers and dealers
  • Accuracy
    • CDK Global is experiencing an IT outage caused by the BlackSuit ransomware attack.
    • Approximately 15,000 auto dealerships in the US and Canada were affected.
  • Deception (100%)
    None Found At Time Of Publication
  • Fallacies (100%)
    None Found At Time Of Publication
  • Bias (100%)
    None Found At Time Of Publication
  • Site Conflicts Of Interest (100%)
    None Found At Time Of Publication
  • Author Conflicts Of Interest (0%)
    None Found At Time Of Publication

97%

  • Unique Points
    • Thousands of car dealerships in the US are facing difficulties handling sales and services due to a hack on their software vendor CDK Global.
    • CDK Global, which provides dealer management software for over 15,000 dealerships, has been down for three consecutive days following cyberattacks.
    • Dealerships are relying on manual methods such as spreadsheets and sticky notes to sell small parts and make repairs, but large transactions are not being processed.
    • Ford is providing assistance to its dealers by offering alternative processes for sales and service support.
  • Accuracy
    • , CDK Global, which provides dealer management software for over 15,000 dealerships, has been down for three consecutive days following cyberattacks.
    • , The affected areas include payroll, inventory, customer relations and office operations. Dealers also rely on the system for financing and insurance agreements.
    • , CDK has not provided an estimated time for when its systems will be operational again.
    • Vehicle repair/maintenance services are also affected as the inventory system within CDK is not deducting used parts from dealerships’ systems, causing delays in replenishment alerts to manufacturers.
  • Deception (100%)
    None Found At Time Of Publication
  • Fallacies (100%)
    None Found At Time Of Publication
  • Bias (100%)
    None Found At Time Of Publication
  • Site Conflicts Of Interest (100%)
    None Found At Time Of Publication
  • Author Conflicts Of Interest (0%)
    None Found At Time Of Publication