Article Details
Scrape Timestamp (UTC): 2024-06-20 15:32:44.944
Original Article Text
Click to Toggle View
CDK Global hacked again while recovering from first cyberattack. Car dealership SaaS platform CDK Global suffered an additional breach Wednesday night as it was starting to restore systems shut down in an previous cyberattack. CDK Global is a software-as-a-service platform that provides a full suite of applications to handle a car dealership's operation, including sales, back office, financing, inventory, and service and support. CDK became aware that they were breached Tuesday night, causing them to shut down their data centers, IT systems, and login systems. The attack led to a massive outage as car dealerships could not conduct their normal operations, including servicing or selling vehicles. Last night, the company had begun to restore services, bringing their Unifi modern login service back online, though other systems were still being restored. Unfortunately, as CDK was restoring its services, they were once again forced to shut down their systems after suffering another breach late yesterday evening. "We are sorry to inform you that we experienced an additional cyber incident late in the evening on June 19th," reads a CDK notification seen by BleepingComputer. "Out of continued caution and to protect our customers, we are once again proactively shutting down most of our systems. We are currently assessing the overall impact and consulting with external 3rd party experts." Brad Holton of Proton Dealership IT told BleepingComputer that all of his customers remain down today, with little information being shared by CDK about the incident with customers. A more recent update from the company, as seen by BleepingComputer, says they aim to bring systems back online on Friday, June 21. However, cybersecurity and IT professionals in the automotive industry have told BleepingComputer that they believe CDK is moving too fast in bringing services back online, potentially increasing the risk to its customers. While the outages are significantly impacting the car sales industry, there is concern that CDK is not properly investigating the scope of the breach before bringing servers back online. Not properly mitigating a breach could lead to further cyberattacks, as evidenced by last night's second breach, and a greater risk of theft of customer data. Car buyers and owners are impacted, too While this is affecting car dealerships, it is also affecting customers who want to purchase a new car or service an existing one. BleepingComputer was contacted by multiple customers yesterday who attempted to purchase a car, only to be told that systems were down and that they could not be helped. As the entire process for purchasing a car, including inventory, vehicle registration, and financing, is handled by CDK's platform, dealerships cannot conduct sales or are forced to manual processes. Similar stories were shared by car owners looking to service their cars, with dealerships warning that there would be delays in receiving parts due to systems being down. BleepingCompuer contacted CDK about the second breach and will update the story with any statement.
Daily Brief Summary
CDK Global, a SaaS provider for car dealerships, experienced a second cyberattack while recovering from an earlier breach.
The initial cyberattack caused CDK to shut down its data centers and IT systems, severely disrupting operations for car dealerships.
Restoration attempts were underway when a subsequent cyber incident prompted another shutdown of most systems.
The company is assessing the impact of the breaches with the help of external cybersecurity experts.
Industry professionals have expressed concerns that CDK may be rushing to restore services, potentially increasing security risks.
The repeated outages have impacted both car dealerships and customers, affecting vehicle sales and servicing capabilities.
CDK is engaging with its customers minimally, with plans to bring systems back online by June 21.
There is ongoing worry that not fully resolving security issues before resuming operations could lead to additional cyberattacks and data theft.