December 26, 2024

CDK Global car dealer outage — Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds CDK outage likely slumped June auto sales, may have cost more than $600M.

Kevin Purdy – Jul 8, 2024 6:57 pm UTC Enlarge / Vehicles for sale at an AutoNation Honda dealership in Fremont, California, US, on Monday, June 24, 2024. Getty Images reader comments 64

After “cyber incidents” on June 19 and 20 took down CDK Global, a software-as-a-service vendor for more than 15,000 car dealerships, forum and Reddit comments by service tech workers and dealers advised their compatriots to prepare for weeks, not days, before service was restored.

Further ReadingSingle point of software failure could hamstring 15K car dealerships for daysThat sentiment proved accurate, as CDK Global last expected to have “all dealers’ connections” working by either July 3 or 4, roughly two weeks’ time. Posts across various dealer-related subreddits today suggest CDK’s main services are mostly restored, if not entirely. Restoration of services is a mixed blessing for some workers, as huge backlogs of paperwork now need entering into digital systems.

Bloomberg reported on June 21 that a ransomware gang, BlackSuit, had demanded “tens of millions of dollars” from CDKand that the company was planning to pay that amount, according to a source familiar with the matter. CDK later told its clients on June 25 that the attack was a “cyber ransom event,” and that restoring services would take “several days and not weeks.” Allan Liska, with analyst Recorded Future, told Bloomberg that BlackSuit was responsible for at least 95 other recorded ransomware breaches around the world.

Lisa Finney, senior manager for external communications at CDK, told Ars on Monday that the firm had no additional information to provide about the attacks, service restoration, or plans for dealers preparing against future attacks.

During the outage, many dealerships pivoted from all-in-one software platforms to pens, paper, Excel sheets, phone calls, and, in some cases, alternative local software. Car Dealership Guy rounded up some of the dealerships’ work-arounds. Repair part numbers, hours, and partial VIN numbers were being tracked in Excel. Lots of dealers grabbed the last contracts they had on hand, blanked out customer information, and made editable PDFs out of them.

Lots of dealers and service managers advocated preparing for the next outage with “no Internet days.” Others noted that the steps some dealerships were taking, like using their own phones for contacting sales leads, could run afoul of privacy and “Do not call” provisions.

Anderson Economic Group, a Michigan-based auto analyst, estimated that CDK’s shutdown cost auto dealers more than $600 million over a two-week period. CDK’s outage is expected to play a large part in a June car sales slump. reader comments 64 Kevin Purdy Kevin is a senior technology reporter at Ars Technica, covering a variety of technology topics and reviewing products. He started his writing career as a newspaper reporter, covering business, crime, and other topics. He has written about technology and computing for more than 15 years. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars