For a car dealership, the cyberattack that actually stops business isn't an abstract "data breach" — it's ransomware that takes down the dealer management system (DMS) the entire store runs on. Sales, service, parts, financing — all of it flows through that platform, and when it goes dark, the dealership effectively can't operate. The 2024 CDK Global attack made the point at industry scale: a ransomware incident at a single DMS vendor disrupted operations at roughly 15,000 North American dealerships for about two weeks, with dealership losses estimated at $1.02 billion (Anderson Economic Group).
This is the threat companion to the regulatory picture. If you want the compliance side — why the FTC Safeguards Rule treats dealers as financial institutions — start with Do Auto Dealers Have to Comply With the FTC Safeguards Rule?. This guide is about the attacks themselves.
Two exposures, one store
A dealership carries two distinct cyber risks, and they need different defenses:
- Downtime on the DMS. The store's nervous system. Whether the outage comes from ransomware on your own network or an attack on your DMS vendor, the result is the same: deals can't close, ROs can't be written, parts can't be looked up.
- The identity data in F&I. The finance-and-insurance office collects Social Security numbers, driver's licenses, dates of birth, and complete credit applications — a clean identity-theft kit for every customer who finances a vehicle.
The CDK lesson: your vendors are your risk
The most important takeaway from 2024 is that a dealership's attack surface includes its vendors. The dealers caught in the CDK outage mostly hadn't been breached themselves — their critical platform had. For an industry where one or two vendors run the core of the business, that concentration is a genuine exposure.
That doesn't mean abandoning your DMS. It means two things at once: harden your own environment so you aren't the entry point, and have a written plan to keep selling and servicing when a critical vendor is down. The dealers who recovered fastest from CDK were the ones who could fall back to a manual process without losing the week.
What actually protects a dealership
Mapped to the two exposures:
- Managed detection and response on every endpoint and server. A 24/7 SOC so ransomware on your own network is caught and contained before it spreads to the systems that run the floor.
- MFA everywhere — especially the DMS and email. The F&I and email accounts are the doors to both the identity data and the wire/payment fraud that follows. MFA closes the most common one.
- Immutable, tested backups. So an attack on your own systems is a recoverable event, not a closed store.
- A vendor-outage continuity plan. The CDK-specific lesson: know, in writing, how you operate when the DMS is gone.
These are the same controls a cyber-insurance questionnaire scores — and given the F&I data you hold, the same controls the FTC Safeguards Rule already expects.
What to do next
Start with the two questions that decide how bad an incident gets: would ransomware on your own network spread unchecked, and could you operate if the DMS went down tomorrow? The Cyber Insurance Readiness Sprint maps your dealership against both — the controls that contain an attack and the continuity gaps that turn it into a closed store — in a fixed-scope, seven-business-day engagement. See the Auto Dealerships security page for how the program runs in a store.
The bottom line
Compliance and attacks point at the same place: the DMS that runs the store and the F&I data that funds identity theft. The 2024 CDK outage proved the downtime case at scale and proved that your vendors are part of your risk. Put managed detection on every endpoint, MFA on the DMS and email, keep tested backups, and write down how you operate when a critical vendor is dark. An attack — yours or theirs — should cost you an afternoon, not a week.
Want to know how your dealership would weather a DMS outage? Book a dealership security assessment.
Last updated
June 17, 2026. We refresh this content as the threat landscape and tools evolve.