Article 6P2HJ Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds

Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds

by
Kevin Purdy
from Ars Technica - All content on (#6P2HJ)
GettyImages-2158517771-800x532.jpg

Enlarge / Vehicles for sale at an AutoNation Honda dealership in Fremont, California, US, on Monday, June 24, 2024. (credit: Getty Images)

After "cyber incidents" on June 19 and 20 took down CDK Global, a software-as-a-service vendor for more than 15,000 car dealerships, forum and Reddit comments by service tech workers and dealers advised their compatriots to prepare for weeks, not days, before service was restored.

That sentiment proved accurate, as CDK Global last expected to have "all dealers' connections" working by either July 3 or 4, roughly two weeks' time. Posts across various dealer-related subreddits today suggest CDK's main services are mostly restored, if not entirely. Restoration of services is a mixed blessing for some workers, as huge backlogs of paperwork now need entering into digital systems.

Bloomberg reported on June 21 that a ransomware gang, BlackSuit, had demanded "tens of millions of dollars" from CDKand that the company was planning to pay that amount, according to a source familiar with the matter. CDK later told its clients on June 25 that the attack was a "cyber ransom event," and that restoring services would take "several days and not weeks." Allan Liska, with analyst Recorded Future, told Bloomberg that BlackSuit was responsible for at least 95 other recorded ransomware breaches around the world.

Read 4 remaining paragraphs | Comments

External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments