SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Cyberattack idles 1,000s of Car Dealers Today
Page 1 2 3 
Go
New
Find
Notify
Tools
Reply
  
Cyberattack idles 1,000s of Car Dealers Today Login/Join 
Member
Picture of JohnCourage
posted Hide Post
I work for a digital automotive marketing company selling and supporting car dealers in Atlanta. It has not been fun the last couple of days. Dealers are scrambling to connect and communicate with potential car buyers in an already soft market. For those that rely on CDK for their entire business it's even worse.

I miss the days when my dealers had on site servers. No mater what was going on in the world if they had a generator they could run their business.


JC
 
Posts: 1305 | Location: Roswell, GA | Registered: June 27, 2006Reply With QuoteReport This Post
CAPT Obvious
Picture of Spiff_P239
posted Hide Post
The dealership handling my truck repair informed me today that their systems were down as well. I’m hoping they were able to get the necessary part ordered as I’ve been without my vehicle for 9 days now.
 
Posts: 3538 | Location: SE Michigan | Registered: February 25, 2007Reply With QuoteReport This Post
Don't Shop. Adopt.
Picture of hapevo
posted Hide Post
I work for a Honda dealer and we have CDK. The parts department can still order parts but need to call in the order to the factory. Service is down and so is sales until sales can get on another program


______________________________________________

"Saving one dog will not change the world, but surely for that one dog, the world will change forever." - Karen Davison


"Man can measure the values of his own soul in the look of the eyes of an animal he's helped" - Author Unkown
 
Posts: 1549 | Location: NorCal | Registered: April 07, 2005Reply With QuoteReport This Post
No, not like
Bill Clinton
Picture of BigSwede
posted Hide Post
Day 3



 
Posts: 5560 | Location: GA | Registered: September 23, 2009Reply With QuoteReport This Post
thin skin can't win
Picture of Georgeair
posted Hide Post
Just had a tire shop tell me they couldn't find the 4th of a set of ordered tires that arrived Wed. My first thought was if they use this goofy system too.

5 minutes later; HEY!! Here it is right over there!
sweetbabyjeebus



You only have integrity once. - imprezaguy02

 
Posts: 12708 | Location: Madison, MS | Registered: December 10, 2007Reply With QuoteReport This Post
Political Cynic
Picture of nhtagmember
posted Hide Post
This is going to happen more and more and across other commercial industries. We’ve become too dependent on the net for tasks that can be done by phone with a paper system.

Oh how did we ever live in the 60’s and 70’s without the net.
 
Posts: 53851 | Location: Tucson Arizona | Registered: January 16, 2002Reply With QuoteReport This Post
Res ipsa loquitur
Picture of BB61
posted Hide Post
I showed up today for a complimentary service/oil change with my daughter for her RAV-4 we scheduled last week. Still down. We were told they could change the oil but it's a 2 1/2 hour wait- for an oil change and rotate tires because of this.

Apparently the Ford dealer across the street has shut down until this gets fixed. The cost to dealers and manufacturers has to be enormous at this point. If it's a state actor, I wonder how the US will respond? If it's some guy in his/her mom's basement, the feds won't be amused when they find him.


__________________________

 
Posts: 12583 | Registered: October 13, 2002Reply With QuoteReport This Post
Member
posted Hide Post
quote:
Originally posted by BB61:
If it's a state actor, I wonder how the US will respond?

An Apology, Flowers or maybe a Candy-Gram depending on who the perpetrator is.


____________________________________________________

The butcher with the sharpest knife has the warmest heart.
 
Posts: 13499 | Location: Bottom of Lake Washington | Registered: March 06, 2007Reply With QuoteReport This Post
The wicked flee when
no man pursueth
Picture of KevH
posted Hide Post
quote:
Originally posted by BB61:
If it's a state actor, I wonder how the US will respond? If it's some guy in his/her mom's basement, the feds won't be amused when they find him.


Likely nothing. With the current walking corpse in the oval office they might make him say, "Zibble zabble zibble," if they say anything at all.

If the perpetrator had registered Republican at any point in the past they might hang him.


Proverbs 28:1
 
Posts: 4253 | Location: Contra Costa County, CA | Registered: May 28, 2004Reply With QuoteReport This Post
No, not like
Bill Clinton
Picture of BigSwede
posted Hide Post
^^^^Crap


Day 4



 
Posts: 5560 | Location: GA | Registered: September 23, 2009Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
Skuttlebutt from some in the Automotive data industry, perpetrators are believed in Eastern Europe, possible ransom demand is $100 million.
 
Posts: 24341 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Member
Picture of vthoky
posted Hide Post
I visited my favorite local dealer this morning, for a long-scheduled inspection on my SUV. I noticed they were doing hand-written tickets, but didn't think much about it until my advisor mentioned the outage. I figured it was simply because I was there as the "early bird."

I chatted with my advisor for a few minutes before I left. He mentioned the outage and rumors he'd heard of an $80 million ransom.



quote:
Originally posted by BB61:
Apparently the Ford dealer across the street has shut down until this gets fixed.


My advisor mentioned that the two nearby Ford stores had also pretty much shut down over this thing. Yikes, what a costly mess.




God bless America.
 
Posts: 13909 | Location: Frog Level Yacht Club | Registered: July 15, 2007Reply With QuoteReport This Post
אַרְיֵה
Picture of V-Tail
posted Hide Post
I have often thought that we should have a remote island, with no means of escape. The sentence for certain criminal activities should be banishment to this island. Maybe give the criminals some seeds to grow food and tell them "Live or die, it's up to you. 'Bye-bye."



הרחפת שלי מלאה בצלופחים
 
Posts: 31451 | Location: Central Florida, Orlando area | Registered: January 03, 2010Reply With QuoteReport This Post
Get my pies
outta the oven!

Picture of PASig
posted Hide Post
quote:
Originally posted by HRK:
Skuttlebutt from some in the Automotive data industry, perpetrators are believed in Eastern Europe, possible ransom demand is $100 million.



Of course they are, all these scumbags are Ukrainian or Russians most of the time. Whenever they catch these people putting skimmers on ATM’s and gas pumps around here it seems they’re always from some Eastern European armpit country


 
Posts: 34642 | Location: Pennsylvania | Registered: November 12, 2007Reply With QuoteReport This Post
Political Cynic
Picture of nhtagmember
posted Hide Post
quote:
Originally posted by V-Tail:
I have often thought that we should have a remote island, with no means of escape. The sentence for certain criminal activities should be banishment to this island. Maybe give the criminals some seeds to grow food and tell them "Live or die, it's up to you. 'Bye-bye."


Lots of good places just off the Alaska coast.
 
Posts: 53851 | Location: Tucson Arizona | Registered: January 16, 2002Reply With QuoteReport This Post
Thank you
Very little
Picture of HRK
posted Hide Post
quote:
Originally posted by PASig:
quote:
Originally posted by HRK:
Skuttlebutt from some in the Automotive data industry, perpetrators are believed in Eastern Europe, possible ransom demand is $100 million.



Of course they are, all these scumbags are Ukrainian or Russians most of the time. Whenever they catch these people putting skimmers on ATM’s and gas pumps around here it seems they’re always from some Eastern European armpit country


CDK Global outage caused by BlackSuit ransomware attack
Link

The BlackSuit ransomware gang is behind CDK Global's massive IT outage and disruption to car dealerships across North America, according to multiple sources familiar with the matter.

The same sources, who provided information on condition of anonymity, told BleepingComputer that CDK is currently negotiating with the ransomware gang to receive a decryptor and not leak stolen data.

While BleepingComputer is the first to report that BlackSuit is behind the attack, the news that CDK is negotiating with threat actors was revealed by Bloomberg yesterday.

The negotiations come after the BlackSuit ransomware attack forced CDK to shut down its IT systems and data centers to prevent the attack's spread, including its car dealership platform. The company tried restoring services on Wednesday but suffered a second cybersecurity incident, causing it to shut down all IT systems again.

CDK is a software-as-a-service (SaaS) provider whose platform is used by car dealerships to run all aspects of its operation, including sales, financing, inventory, service, and back office functions.

As the platform is now shut down, car dealerships have had to switch to pen and paper to conduct their operations, with BleepingComputer told by car buyers that they could not purchase a car due to the outage or receive service for existing cars.

Two of the largest public car dealership companies, Penske Automotive Group and Sonic Automotive, disclosed yesterday that they, too, were impacted by the outages.

"Our Premier Truck Group business utilizes CDK's dealer management system which has been disrupted," Penske shared in an SEC filing.

"We immediately took precautionary containment steps to protect our systems and commenced an investigation of the incident, which efforts are ongoing. Premier Truck Group has implemented its business continuity response plans and continues to operate at all locations through manual or alternate processes developed to respond to such incidents."

"As a result, the Company experienced disruptions to its dealer management system ("DMS") hosted by CDK, which supports critical dealership operations including those supporting sales, inventory and accounting functions and its customer relationship management ("CRM") system," reported Sonic Automotive in an SEC filing.

"All of the Company's dealerships are open and operating utilizing workaround solutions to minimize the disruption caused by this CDK outage."

CDK also warns that threat actors are calling dealerships posing as CDK agents or affiliates to gain unauthorized systems access.

BleepingComputer contacted CDK to learn more about the ransomware attack but has not received a response yet.

The BlackSuit ransomware gang
BlackSuit launched in May 2023 and is believed to be a rebrand of the Royal ransomware operation.

Royal Ransomware, and thus BlackSuit, is believed to be the direct successor of the notorious Conti cybercrime syndicate, an organized cybercrime gang comprised of Russian and Eastern European threat actors.

In June 2023, the Royal Ransomware operation began testing a new encryptor called BlackSuit amid rumors that they planned to rebrand under a new name after they attacked the City of Dallas, Texas.

Since then, attacks under the Royal name have disappeared, with the threat actors now working under the BlackSuit name.

In November 2023, the FBI and CISA revealed in a joint advisory that Royal and BlackSuit share similar tactics and coding overlaps in their encryptors.

The advisory also linked the Royal ransomware gang to attacks on at least 350 organizations worldwide since September 2022 and more than $275 million in ransom demands.
 
Posts: 24341 | Location: Gunshine State | Registered: November 07, 2008Reply With QuoteReport This Post
Member
Picture of sourdough44
posted Hide Post
Been on the news with hospitals and health care providers this Spring also. It seemed rather widespread.
 
Posts: 6423 | Location: WI | Registered: February 29, 2012Reply With QuoteReport This Post
Member
posted Hide Post
quote:
Originally posted by V-Tail:
I have often thought that we should have a remote island, with no means of escape. The sentence for certain criminal activities should be banishment to this island. Maybe give the criminals some seeds to grow food and tell them "Live or die, it's up to you. 'Bye-bye."


Australia?


____________________________
"Fear is a Reaction - Courage is a Decision.” - Winston Spencer Churchill
NRA Life Member - Adorable Deplorable
 
Posts: 930 | Location: SE-PA | Registered: August 09, 2006Reply With QuoteReport This Post
Member
Picture of sourdough44
posted Hide Post
What’s old, can be new again. I think you are talking about a ‘penal colony’.
 
Posts: 6423 | Location: WI | Registered: February 29, 2012Reply With QuoteReport This Post
Shall Not Be Infringed
Picture of nhracecraft
posted Hide Post
quote:
Originally posted by Cassandra:
quote:
Originally posted by V-Tail:
I have often thought that we should have a remote island, with no means of escape. The sentence for certain criminal activities should be banishment to this island. Maybe give the criminals some seeds to grow food and tell them "Live or die, it's up to you. 'Bye-bye."

Australia?

Perhaps Manhattan... Wink


____________________________________________________________

If Some is Good, and More is Better.....then Too Much, is Just Enough !!
Trump 2024....Save America!
"May Almighty God bless the United States of America" - parabellum 7/26/20
Live Free or Die!
 
Posts: 9442 | Location: New Hampshire | Registered: October 29, 2011Reply With QuoteReport This Post
  Powered by Social Strata Page 1 2 3  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    Cyberattack idles 1,000s of Car Dealers Today

© SIGforum 2024