CDK Global Pwned In Cyberattack Taking Down Thousands Of Car Dealers

Tuesday night, car dealership Saas provider CDK Global was hit by a cyberattack, causing the company to shut down its IT systems, phones, and applications leaving its 15,000 clients unable to operate normally.

The company’s SaaS product provides auto industry clients with a platform that handles all aspects of a car dealership’s operations, including CRM, financing, payroll, support and service, inventory, and back-office operations.

To use CDK’s services, car dealerships configure an always-on VPN to the SaaS provider’s data centers, allowing their locally installed applications to access the platform. Also, the software has administrative privileges used to deploy updates. CDK has recommended disconnecting from the data centers.

Some dealerships appear to have gotten creative to continue doing business during the outage, logging in with old credentials on old CDK platforms, and sharing that they were simply relying on spreadsheets and sticky notes to sell customers small parts and make repairs, but that they weren’t making any large transactions. 

CDK’s systems first went down around 2:00 a.m. EDT and some functions began to come back online by Wednesday afternoon.

Ted Miracco, CEO, Approov Mobile Security had this to say:
 
   “This incident highlights a common vulnerability that is especially impacting the automotive supply chain and CDK’s breach exemplifies this risk. These apps provide extensive mobile tools for dealership management, offering functionalities such as real-time inventory management, customer relationship management, repair tracking, and mobile access to critical business information. However, without proper API security measures, these features can expose sensitive data and backend systems to potential breaches and malicious attacks. Many companies do not adequately secure their APIs, especially for mobile applications. API protection for web access does not adequately protect mobile interfaces, creating an easy target for hackers and ransomware attacks. These API attacks increasingly target the automotive supply chain, exploiting the lack of security in mobile interfaces.”

One of the reasons why I tend to warn my clients about using SaaS solutions is that you have to be able to trust that their security is top shelf. Because if they get pwned, you get pwned. And then your business is down for however long it takes for the SaaS provider to address their issues. Your organization has to ask if they want to take that risk.

One Response to “CDK Global Pwned In Cyberattack Taking Down Thousands Of Car Dealers”

  1. […] might recall that thousands of car dealerships have been shut down by their SaaS provider CDK Global not being […]

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading