The CDK cyberattack has shut down car dealerships across the US and here’s what to know.


What to do if you think your personal information has been compromised

CDK Global, a company that provides car dealerships across the United States with software to manage sales and other services, has been hacked, prompting the company to temporarily shut down most of its systems.

This effectively prevents about 15,000 car dealers from making sales. GM dealers rely on CDK systems, as does Group 1 Automotive, an auto retailer with hundreds of dealerships across the United States. Holman, with agents in eight US states, is another CDK client.

“We are actively investigating a cyber incident,” a CDK spokesperson told CBS News on Wednesday. “Out of an abundance of caution and concern for our customers, we have shut down most of our systems and are working hard to get everything up and running as quickly as possible.”

Later on Wednesday afternoon, CDK said that after conducting tests and consulting with outside experts, some of its systems had been restarted.

“With the work done so far, our core [dealer management system] Digital retail solutions have been restored. “We are continuing to conduct extensive testing on all other applications, and will provide updates when we bring these applications back online,” CDK said in a statement to CBS MoneyWatch.

However, CDK told CBS MoneyWatch on Thursday afternoon that its systems were offline again, after suffering another cyberattack on Wednesday.

“Late on the evening of June 19, we experienced an additional cyber incident and proactively shut down most of our systems,” the spokesperson said. “In partnership with external experts, we are assessing the impact and providing regular updates to our customers. We remain vigilant in our efforts to restore our services and get our agents back to business as usual as quickly as possible.”

Calls to the CDK customer support hotline produced a persistent busy signal. But the company’s automated recording said the outage could affect agents for several days, according to Computer mag. “At this time, we do not have an estimated time frame to resolve the issue, so our merchant systems will likely be unavailable for several days,” the message stated to callers.

The number of cyberattacks rose last year, with more than 3,200 data breaches in 2023, a 78% increase on the previous year, according to a new study by the data company. SWAX. She added that these violations affected more than 65 million victims last year.

A CDK dealer management system, or DMS, is a hub that allows businesses to monitor operations from a single interface, while retail tools allow dealers to transact online and in showrooms.

What is CDK?

The CDK provides agents with tools to manage payroll, inventory, and office operations.

It also touts its cybersecurity capabilities on its website. “CDK Cybersecurity Solutions provides a three-tiered cybersecurity strategy to prevent, protect and respond to cyberattacks so you can defend your agency,” she says.

When did the cyber attack start?

The cyber attack on CDK Global began on Tuesday evening. Sleeping computera cybersecurity news site, on Wednesday took the 15,000 car dealerships it serves offline.

As mentioned above, CDK said it was hit by another cyberattack on Wednesday evening.

It is currently unknown who or group is behind the cyberattack.

How do agents respond?

It appears that some agents were creative to continue doing business during the outage. Agency staff posted information about the outage Reddit On Wednesday, they announced that they were relying on spreadsheets and sticky notes to sell small parts to customers and make repairs, but had not made any large transactions.

One employee asked other dealership employees, “How many of you are standing around because your entire store is CDK-based?” Under the heading “CDK Down,” users in Wisconsin and Colorado confirmed that their dealer transaction systems were offline.

See also  How does a 25 basis point Fed rate hike affect you?

Leave a Reply

Your email address will not be published. Required fields are marked *