How did the auto dealer outage end? CDK almost certainly paid a $25 million ransom | CNN Business (2024)

How did the auto dealer outage end? CDK almost certainly paid a $25 million ransom | CNN Business (1)

Vehicles sit in a row outside a car dealership, June 2, 2024, in Lone Tree, Colo. CDK Global, a company that provides software for thousands of auto dealers in the US and Canada, was hit by a cyberattack in June.

CNN

CDK Global, a software firm serving car dealerships across the US that was roiled by a cyberattack last month, appears to have paid a $25 million ransom to the hackers, multiple sources familiar with the matter told CNN.

The company has declined to discuss the matter. Pinpointing exactly who sends a cryptocurrency payment can be complicated by the relative anonymity that some crypto services offer. But data on the blockchain that underpins cryptocurrency payments also tells its own story.

On June 21, about 387 bitcoin —then the equivalent of roughly $25 million —was sent to a cryptocurrency account controlled by hackers affiliated with a type of ransomware called BlackSuit, Chris Janczewski, head of global investigations at crypto-tracking firm TRM Labs, told CNN.

A week after the payment was made, CDK said that it was bringing car dealers back online to its software platform. Cryptocurrency allows for the exchange of digital assets outside of the traditional banking system, but a record of those transactions is accessible on the blockchain.

Janczewski did not identify who sent the payment, but threeother sources closely tracking the incident confirmed that a roughly $25 million payment had been made to BlackSuit affiliates and that CDK was very likely the source of that payment.Those sources spoke on the condition of anonymity because of the sensitive nature of the investigation.

The cryptocurrency account that sent the ransom payment is affiliated with a firm that helps victims respond to ransom attacks, one of the sources said, declining to identify the firm.

CDK spokesperson Lisa Finney did not respond to multiple requests for comment on Wednesday and Thursday on the apparent payment. Finney previously declined to answer questions on the subject.CDK CEO Brian MacDonald did not respond to email and LinkedIn messages seeking comment.

The ransom payment of $25 million hasn’t been previously reported. Bloombergreported that the hackers had made a multimillion-dollar ransom demand and that the company planned to pay.

The ransomware attack that hit CDK in mid-June disrupted thousands of auto dealerships that use the company’s software to manage everything from scheduling to sales and orders.CDKreferred to it as a “cyber incident” in statements to reporters. In a note to clients cited byCBS, CDK referred to it as a “cyber ransom event.”

CDK said last week that “substantially all” of the nearly 15,000 car dealerships that use its software across North America were back online to its core management system.

Federal officials generally discourage paying a ransom to cybercriminals because payments can fuel future attacks. But some companies feel they have no choice but to pay off hackers to try to recover sensitive customer data or get their systems back online.

The payment would be a windfall for arelatively new brandof ransomware criminals that emerged last year and has claimed numerous victims in the education and construction sectors, among others. BlackSuit’s malicious software is similar to that previously used by other Russian-speaking criminal groups,accordingto the US Department of Health and Human Services.

“The gang’s leadership has been conducting ransomware extortion operations since 2019 under other ransomware brand names,” said Jon DiMaggio, chief security strategist at cybersecurity firm Analyst1 who closely studies ransomware gangs.

“This is one of many examples I have seen over the years where a group is either shut down by law enforcement or decides to terminate its operation to rebrand under a new name and continue attacking and extorting organizations,” DiMaggio told CNN, adding that most of BlackSuit’s victims have been in the US.

Cybercriminals, in general, extorted a record $1.1 billion in ransom payments from victim organizations around the world last year despite US government efforts to cut off their money flows, Chainalysis, another crypto-tracking firm,said in a reportin February.

A $25 million ransom payment is certainly large but not unheard of in the lucrative ransomware economy. UnitedHealth Group, the health care conglomerate whose subsidiary suffered a ransomware attack in February that hobbled pharmacies across the US, paid a $22 million ransom to a different criminal group.

But the average ransom payment in the fourth quarter of 2023 was significantly lower: $568,705,accordingto cybersecurity firm Coveware.

How did the auto dealer outage end? CDK almost certainly paid a $25 million ransom | CNN Business (2024)

FAQs

How did the auto dealer outage end? CDK almost certainly paid a $25 million ransom | CNN Business? ›

CDK

CDK
CDK Global Inc. is an American multinational corporation based in Austin, Texas, providing data and technology to the automotive, heavy truck, recreation, and heavy equipment industries.
https://en.wikipedia.org › wiki › CDK_Global
Almost Certainly Paid a $25 Million Ransom. CDK Global, a software firm serving car dealerships across the US that was roiled by a cyberattack last month, appears to have paid a $25 million ransom to the hackers, multiple sources familiar with the matter told CNN. The company has declined to discuss the matter.

How much did CDK pay in ransom? ›

According to a published report, the price tag that CDK Global paid to cyber terrorists is believed to $25 million.

How many dealerships use CDK? ›

Creating Connections That Move Automotive Retail. Trusted by nearly 15,000 dealer locations, CDK Global connects you to world-class dealership software solutions that work together to help you reach your potential.

How much is CDK worth? ›

Market cap: $6.39 Billion

On September 7, 2022 CDK Global had a market cap of $6.39 Billion. The market capitalization, commonly called market cap, is the total market value of a publicly traded company's outstanding shares and is commonly used to measure how much a company is worth.

How much did CDK sell for? ›

Last April it was announced that CDK Global, Inc., was being acquired by Brookfield Business Partners for $8.3 billion. Under merger agreement terms, CDK shareholders were said to receive $54.87 per share in cash upon completion of the transaction.

What company owns the most dealerships? ›

In comparison, Lithia Motors has continuously expanded its dealership network without falter since 2014, acquiring 32 locations in 2022 alone. With over 290 storefronts, it now claims to have surpassed AutoNation in size, making it the biggest dealer group in the U.S.

Where is the CDK headquarters located? ›

Who owns CDK software? ›

On April 7, 2022, CDK Global agreed to be acquired by Brookfield Business Partners and institutional partners for a total enterprise value of $8.3 billion.

How much did CDK pay for Roadster? ›

CDK Global acquires digital retailing provider Roadster for $360M.

Should the ransom to restore computer systems be paid? ›

You will need to restore your files from a backup, or determine if a decryption tool can be used. That is the recommended response: restore your data internally, so you don't have to pay the ransom. Attackers may threaten to release your data publicly if you do not pay, but this is often a bluff.

Who bought CDK digital? ›

Brookfield completed the deal on July 6, 2022.

What does CDK stand for? ›

Cyclin-dependent kinase, a major class of enzymes involved in the regulation of the cell cycle.

References

Top Articles
Latest Posts
Article information

Author: Geoffrey Lueilwitz

Last Updated:

Views: 6519

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Geoffrey Lueilwitz

Birthday: 1997-03-23

Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

Phone: +13408645881558

Job: Global Representative

Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.