Sponsored

Car Dealers Nationwide Hacked

GrandpaD

Well-known member
First Name
Dennis
Joined
Nov 1, 2021
Threads
9
Messages
262
Reaction score
329
Location
Hampton Roads, Virginia
Vehicles
'24 Lariat PB FX4 502A 5.5 Space White
Occupation
Retired
If your headed to your dealer to buy an F-150, either wait a few days or plan on spending a real long time as they handwrite the paperwork.

CDK Global, the top dealer software was hacked earlier this week, then went back up only to be attacked again. We spent a long afternoon in finance buying a 24 PB Lariat (more on that in a different thread) only to leave with a single page receipt. The majority of paperwork was done on an in-house system which we reviewed and digitally signed. We'll get the final mountain of paperwork whenever CDK gets up and running.

https://www.cbsnews.com/news/cdk-cyber-attack-outage-auto-dealerships-cbs-news-explains/
Sponsored

 
Last edited:

bdginmo

Well-known member
Joined
May 15, 2024
Threads
1
Messages
66
Reaction score
79
Location
Missouri
Vehicles
2023 F-150
It's good that they had a backup system. I wonder how many dealers are fully reliant on CDK.
 

Parthery

Well-known member
First Name
Brian
Joined
May 26, 2024
Threads
4
Messages
330
Reaction score
247
Location
Atlanta
Vehicles
2023 F150 Lariat 3.5
I have another vehicle, a VW Passat, that was towed to the VW dealer here in Atlanta on Tuesday after it wouldn't start. It needs a starter. Under normal circumstances the dealer orders the part and it comes on the truck from Jacksonville overnight. However, with this mess they can't give me an estimate as required by GA law, (they can't get to the book hours for the labor), they can't get the starter from the warehouse because they can't order parts, and they have no idea when the systems will be restored. And they can't collect $$$ on an RO which doesn't exist, so essentially they are in the 3rd day of being dead in the water. They literally have no clue when I'll get the car back.
 
OP
OP
GrandpaD

GrandpaD

Well-known member
First Name
Dennis
Joined
Nov 1, 2021
Threads
9
Messages
262
Reaction score
329
Location
Hampton Roads, Virginia
Vehicles
'24 Lariat PB FX4 502A 5.5 Space White
Occupation
Retired
It's good that they had a backup system. I wonder how many dealers are fully reliant on CDK.
Their backup system just allowed them to do some of the paperwork but it has to get into the full system so they can do all the loan stuff, DMV, etc. The majority of paperwork was done by hand and cell phone calculators. Like going back to the 60s.

It's potentially seriously ugly. What concerns me is how "deep" the hack got into the systems. Virtually every car purchase includes everything about you except maybe your blood type. As Ricky said so eloquently "Lucy, you have some 'splainin' to do..."
 

SumGuy

Well-known member
First Name
Bill
Joined
Jul 21, 2021
Threads
18
Messages
633
Reaction score
591
Location
USA
Vehicles
F150 (perpetually on order)
Occupation
Drugs
I have another vehicle, a VW Passat, that was towed to the VW dealer here in Atlanta on Tuesday after it wouldn't start. It needs a starter. Under normal circumstances the dealer orders the part and it comes on the truck from Jacksonville overnight. However, with this mess they can't give me an estimate as required by GA law, (they can't get to the book hours for the labor), they can't get the starter from the warehouse because they can't order parts, and they have no idea when the systems will be restored. And they can't collect $$$ on an RO which doesn't exist, so essentially they are in the 3rd day of being dead in the water. They literally have no clue when I'll get the car back.
A good indication of how absolutely eff’d we all are in there was a serious cyber attack.

no goods would get anywhere.
 

Sponsored

fmdog44

Well-known member
First Name
steve
Joined
Apr 29, 2021
Threads
88
Messages
654
Reaction score
323
Location
Houston
Vehicles
2012 F150 XL
Occupation
Retired
A good indication of how absolutely eff’d we all are in there was a serious cyber attack.

no goods would get anywhere.
was thinking the same thing like what if WWIII started everything everywhere would be hacked and nations would shoot themselves in the foot.
 

National Superbike

Well-known member
First Name
Curt
Joined
Apr 23, 2024
Threads
19
Messages
301
Reaction score
287
Location
Atlanta, GA
Vehicles
23 F150 SC 2.7EB
Occupation
vintage motorcycle restoration
The crazy thing is that the most they will have to do is offer free credit monitoring for a year. The system is badly tilted towards protecting the corporations. A friend who is a software engineer and works in the auto dealer world, said he was on a conference call with 100's of dealers and they didn't even seem to be that worried about when they would get back up and running. They were worried about legal liability...
 

Gonski

Member
First Name
Matt
Joined
Jun 8, 2024
Threads
2
Messages
17
Reaction score
26
Location
Pennsylvania
Vehicles
2023 XLT 302A 2.7
I work in Cybersecurity and I was actually out shopping for a truck on the day the cyber attacks happened (how ironic).

The dealer was still able to process my credit (They had a secondary system available) and was able to complete the delivery paperwork in person today so I was able to drive off the lot thankfully.

I imagine it must be It's a pretty serious attack - likely ransomware, Am looking forward to reading the technical report once the technical details are shared in a few weeks.

As a security professional, it was quite unfortunate perfect timing for something like this to happen but it is the reality of our day in age. Use a password manager, make good passwords, don't reuse them and make sure you enable MFA on everything you possibly can.
 
Last edited:

Eskram

Well-known member
Joined
Dec 19, 2022
Threads
50
Messages
1,196
Reaction score
2,179
Location
Fl
Vehicles
2022 F150 Lariat PB 502a
From what I've read, it's a ransomware attack. CDK hasn't actually disclosed anything yet, other than they were hit by another attack last evening.

Glad to see they were able to still get you going. My truck is in service, and the whole process seems slower than normal, likely because of all of that. My SA isn't happy about the situation and looked like he was going to either quit or kill everyone around him..
 

Gonski

Member
First Name
Matt
Joined
Jun 8, 2024
Threads
2
Messages
17
Reaction score
26
Location
Pennsylvania
Vehicles
2023 XLT 302A 2.7
From what I've read, it's a ransomware attack. CDK hasn't actually disclosed anything yet, other than they were hit by another attack last evening.

Glad to see they were able to still get you going. My truck is in service, and the whole process seems slower than normal, likely because of all of that. My SA isn't happy about the situation and looked like he was going to either quit or kill everyone around him..
Yup, something of this tier/caliber feels like ransomware. Obviously until we get confirmation it's only speculation. I am interested to hear how initial access was obtained on the CDK network.

A lot of time it really just comes down to a simple weak password on an employee's account where MFA isn't implemented correctly. I've attacked networks successfully this way many times.

The dealer today told me that they received a memo from from CDK stating to be extra cautious about their phone conversations and not to share any sensitive information over the phone. Supposedly dealerships were receiving calls, presumably from the attackers, in an attempt to actually expand their foothold onto dealer networks...crazy stuff
 

Sponsored


Eskram

Well-known member
Joined
Dec 19, 2022
Threads
50
Messages
1,196
Reaction score
2,179
Location
Fl
Vehicles
2022 F150 Lariat PB 502a
A lot of dealers are jumping ship to R&R or DealerTrack. I'm sure it's a painful process, but I understand ya gotta do what ya gotta do. Multiple days of fuckery and losing money, time and possibly employees is going to add up.

Sadly, they should just pay the fee to get things back up, and hope the thieves are somewhat honorable afterwards.

Edit: https://www.reddit.com/r/serviceadvisors/ is a fun place now.
 

Natetroknot

Well-known member
First Name
Nate
Joined
Feb 12, 2023
Threads
5
Messages
341
Reaction score
424
Location
Dubuque, IA
Vehicles
2022 XLT 3.5 302A
So many disruptions to systems like this lately, 911 service and cell networks have been hit often around here in Iowa. And swatting calls to schools has ended with the summer’s beginning but those were out of hand too. I’m sure it’ll get worse before it gets better. Our way of life has way too much reliance on this stuff, take me back to the 50’s please and thanks.
 

Mtnman1

Well-known member
First Name
Tod
Joined
Feb 9, 2022
Threads
11
Messages
1,746
Reaction score
1,615
Location
Ohio
Vehicles
2022 F150 RCSB FX4
Occupation
Engineer
Its amazing how few companies/corporations have backups.

With proper server backups, ransomeware attempts are nothing but a nuisance.

Restore images, change passwards, back in business.
 

Eskram

Well-known member
Joined
Dec 19, 2022
Threads
50
Messages
1,196
Reaction score
2,179
Location
Fl
Vehicles
2022 F150 Lariat PB 502a
Its amazing how few companies/corporations have backups.

With proper server backups, ransomeware attempts are nothing but a nuisance.

Restore images, change passwards, back in business.
It's not even about backups. This is a cloud reliant system that has hooks in most parts of the dealers system, and is effectively down. Restoring a backup does no good here, as they can't use it anyway. They can't do sales, service, or parts and will have to paper-it for now and re-enter everything if/when it comes back up.

I do feel for them..
Sponsored

 
 







Top