Massive car dealer ransom attack is mostly over after 2 weeks of work-arounds
After “cyber incidents” on June 19 and 20 took down CDK Global, a software-as-a-service vendor for more than 15,000 car dealerships, forum and Reddit comments by service tech workers and dealers advised their compatriots to prepare for weeks, not days, before service was restored.
That sentiment proved accurate, as CDK Global last expected to have “all dealers’ connections” working by either July 3 or 4, roughly two weeks’ time. Posts across various dealer-related subreddits today suggest CDK’s main services are mostly restored, if not entirely. Restoration of services is a mixed blessing for some workers, as huge backlogs of paperwork now need entering into digital systems.
Bloomberg reported on June 21 that a ransomware gang, BlackSuit, had demanded “tens of millions of dollars” from CDK and that the company was planning to pay that amount, according to a source familiar with the matter. CDK later told its clients on June 25 that the attack was a “cyber ransom event,” and that restoring services would take “several days and not weeks.” Allan Liska, with analyst Recorded Future, told Bloomberg that BlackSuit was responsible for at least 95 other recorded ransomware breaches around the world.