Cybersafetyconnections June 24, 2024, vol# 174
From konbriefing CDK Car dealership software-as-a-service provider CDK Global has experienced a significant cyberattack that impacted thousands of US car dealerships.
- This cyberattack may have happened due to the always-on VPN.
- CDK is used by over 15,000 car dealerships in the us.
- NO cybercriminal group has claimed responsibility for the attack.
- CDK took steps to mitigate loss from the cyberattack.
What happened?

According to BleepingComputer.com Car dealership software-as-a-service provider CDK Global has experienced a significant cyberattack that prompted the company to deactivate its IT systems, phones, and applications to contain the threat leading to the shutdown of its systems and disrupting the normal operations of its clients.
Brad Holton, CEO of Proton Dealership IT, a firm specializing in cybersecurity and IT services for car dealerships, disclosed that the attack compelled CDK to take its two data centers offline at approximately 2 AM.
Why did this cyber-attack happen?
In order to utilize CDK’s services, car dealerships establish an always-on VPN connection to the SaaS provider’s data centers, enabling access to the platform through locally installed applications.
Some employees have expressed concerns that threat actors might exploit the always-on VPN to infiltrate the internal networks of car dealerships.
Who was impacted?Designer powered by DALL-E3
CDK Global offers a comprehensive SaaS platform to the automotive industry, encompassing critical functions such as CRM, financing, payroll, support and service, inventory management, and back-office operations.
The company serves over 15,000 car dealerships in North America and maintains a substantial workforce across the country. So CDK and the car dealerships, employees and customers were impacted.
Which cybercriminal group was responsible?
No cybercriminal group has claimed responsibility for the attack.
Here is how CDK mitigated loss from the cyberattack

OWASP Threat and Safeguard Matrix
OWASP Threat and Safeguard Matrix
Brad Holton, CEO of Proton Dealership IT, a firm specializing in cybersecurity and IT services for car dealerships, disclosed that:
- The attack compelled CDK to take its two data centers offline at approximately 2 AM.
- Reports from employees at various car dealerships suggested that CDK has communicated limited details, primarily issuing an email alert regarding the cyber incident.
- An IT professional from a dealership informed that CDK advised them to disconnect the always-on VPN as a precautionary measure.
- Holton elaborated on the administrative privileges of CDK software on devices, as it is used for deploying updates. This explanation could justify CDK’s recommendation to disconnect from the data centers.
- Notably, while some users mentioned successful logins with previous credentials that were updated during CDK’s transition to a modern single-sign-on platform, there are reports indicating that the application functionality is not as expected.
As always, we asked Copilot for help. And here you go;
To mitigate the losses from the recent, cyberattack, CDK Global can take several steps:
- Immediate Response and Containment:
- Isolate affected systems to prevent further spread of the attack.
- Engage cybersecurity experts to assess the damage and begin remediation efforts1.
- Communication:
- Inform stakeholders (dealerships, customers, and partners) about the incident and provide regular updates on the status of recovery efforts1.
- Transparency is key to maintaining trust and managing expectations2.
- Data Recovery and Backup:
- Restore systems from clean backups to ensure data integrity and minimize downtime1.
- Verify the integrity of the restored data to ensure no malware remains1.
- Strengthening Security Measures:
- Implement advanced threat detection and response systems to monitor for future threats3.
- Regularly update and patch software to close vulnerabilities3.
- Employee Training:
- Conduct cybersecurity training for employees to recognize phishing attempts and other common attack vectors3.
- Promote a culture of security awareness within the organization3.
- Legal and Financial Measures:
- Engage legal counsel to navigate any regulatory requirements and potential liabilities1.
- Consider cyber insurance to cover financial losses and recovery costs1.
Conclusion
By taking these steps, CDK Global can not only mitigate the immediate impact of the cyberattack but also strengthen its defenses against future incidents.
Subscribe to get the latest blog.
