The SOC Labs

CDK Cyberattack Explained: Timeline, Impact and What’s Next?

CDK Cyberattack Summary

CDK cyberattack is one of the recent cyber incidents that shook the North American automotive industry. In June 2024, when CDK Global noticed a cyber incident, it proactively shut down the operations that impacted over 15,000 car dealerships across the US and Canada. CDK Global is a major software-as-a-service provider in the US and Canada. The attack temporarily paralyzed the normal business operations, including sales, financing, inventory, service, and back-office functions of over 15,000 car dealerships.

CDK Cyberattack Timeline

Late June 19, 2024:

June 20-24, 2024:

June 25, 2024:

June 26 – June 30, 2024:

July 1, 2024 (and beyond):

According to the latest update, the company anticipates that all dealers’ connections will be live by late Wednesday, July 3, or early morning Thursday, July 4.

What is BlackSuit Ransomware?

The cybercrime group behind Blacksuit ransomware, which first showed up in early 2023, is going after businesses and organizations with a motive of financial extortion and double extortion (extortion, exfiltrate and public shaming of victims). The attackers operate on the ransomware-as-a-service (RAAS) model, encrypting data and demanding a ransom or the promise of leaking it online. Like Emotet, Blacksuit is multifaceted: while their multi-threaded Go-written ransomware encrypts files, it also steals data from target computer systems before encryption. After disabling antivirus software, the malware appends the ‘.blacksuit’ filename extension to files it has encrypted. Blacksuit is bilingual ransomware that displays instructions in English and Chinese.

Researchers claimed that Blacksuit shares a number of similarities with Royal ransomware, hinting that the two groups might be connected. They both target a similar array of targets: Blacksuit’s victims include hospitals, universities, and government institutions.

Typical Ransom note of Blacksuit Ransomware that Claimed CDK Cyberattack
Figure: Typical Ransom note of Blacksuit Ransomware that Claimed CDK Cyberattack | Source: TrendMicro

A joint advisory issued by the FBI and CISA in November 2023 reveals that Royal and BlackSuit’s encryptors have overlapping coding and practices. The advisory alleged that the Royal ransomware team has been behind’ at least 350 criminal ransomware victim organizations’ in nearly 50 countries since September 2022 and has made ransom demands totalling more than $275 million since December 2021.

Blacksuit Ransomware IOCs

Here are some of the Blacksuit ransomware IoCs that can help you take proactive measures to detect and prevent cyberattacks:

Impact of CDK Cyberattack on the Automotive Industry

As per the online reports, the estimated financial losses from the CDK cyberattack on the auto sales industry are significant, reaching up to $944 million. The attack has exposed the automotive sector’s vulnerability to cyberattacks, raising concerns about cybersecurity measures. These losses are the result of potentially extensive downtime, brand loyalty diminishing as profitability shrinks, frustration from both customers and staff and shrinking staff morale.

Cyberattacks can severely disrupt business operations, leading to significant financial losses, damaged reputations, and loss of customer trust. In recent times, the Nissan cyberattack by the Akira ransomware group compromised over 100 GB of data.

In the case of CDK Global, the cyberattack crippled the primary platform used by car dealerships for essential functions such as sales, CRM, financing, payroll, support and service, inventory management, and back-office operations. Consequently, dealerships had to revert to manual processes like pen and paper, slowing down operations, creating inefficiencies, and frustrating customers. The disruption extended beyond sales to affect maintenance services, making it difficult for customers to receive timely support for their vehicles.

The importance of SaaS platforms becomes glaringly apparent when disruptions occur. The automotive industry relies on these technologies for real-time data, predictive analytics, and customer insights, driving modern business strategies. Therefore, ensuring robust cybersecurity measures and contingency plans for service continuity is imperative for SaaS providers to minimize the impact of cyberattacks and maintain business operations.

For more cybersecurity news and updates, follow us on Cybersecurity – The SOC Labs.


Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The SOC Labs assumes no liability for the accuracy or consequences of using this information.

Join thousands of cybersecurity professionals who trust The SOC Labs Newsletter to keep them informed, prepared, and ahead of the curve.

Exit mobile version