Car Dealerships in North America Revert to Pens and Paper after Cyberattacks on Software Provider

Car dealerships in North America continue to wrestle with major disruptions that started last week with cyberattacks on a software company used widely in the auto retail (File/AFP)
Car dealerships in North America continue to wrestle with major disruptions that started last week with cyberattacks on a software company used widely in the auto retail (File/AFP)
TT

Car Dealerships in North America Revert to Pens and Paper after Cyberattacks on Software Provider

Car dealerships in North America continue to wrestle with major disruptions that started last week with cyberattacks on a software company used widely in the auto retail (File/AFP)
Car dealerships in North America continue to wrestle with major disruptions that started last week with cyberattacks on a software company used widely in the auto retail (File/AFP)

Car dealerships in North America continue to wrestle with major disruptions that started last week with cyberattacks on a software company used widely in the auto retail sales sector.

CDK Global, a company that provides software for thousands of auto dealers in the US and Canada, was hit by back-to-back cyberattacks Wednesday. That led to an outage that has continued to impact operations, according to The AP.

For prospective car buyers, that's meant delays at dealerships or vehicle orders written up by hand. There's no immediate end in sight, with CDK saying it expects the restoration process to take “several days” to complete.

On Monday, Group 1 Automotive Inc., a $4 billion automotive retailers, said that it continued to use “alternative processes” to sell cars to its customers.

Here is what you need to know.

What is CDK Global? CDK Global is a major player in the auto sales industry. The company, based just outside of Chicago in Hoffman Estates, Illinois, provides software technology to dealers that helps with day-today operations — like facilitating vehicle sales, financing, insurance and repairs.

CDK serves more than 15,000 retail locations across North America, according to the company.

What happened last week? CDK experienced back-to-back cyberattacks on Wednesday. The company shut down all of its systems out of an abundance of caution, spokesperson Lisa Finney said last week.

“We have begun the restoration process," Finney said in an update over the weekend — noting that the company had launched an investigation into the “cyber incident” with third-party experts and notified law enforcement.

“Based on the information we have at this time, we anticipate that the process will take several days to complete, and in the interim we are continuing to actively engage with our customers and provide them with alternate ways to conduct business,” she added.

In messages to its customers, the company has also warned of “bad actors” posing as members or affiliates of CDK to try to obtain system access by contacting customers. It urged them to be cautious of any attempted phishing.

The incident bore all the hallmarks of a ransomware attack, in which in which targets are asked to pay a ransom to access encrypted files. But CDK declined to comment directly — neither confirming or denying if it had received a ransom demand.

Are impacted dealerships still selling cars? Several major auto companies — including Stellantis, Ford and BMW — confirmed to The Associated Press last week that the CDK outage had impacted some of their dealers, but that sales operations continue.

In light of the ongoing situation, a spokesperson for Stellantis said Friday that many dealerships had switched to manual processes to serve customers. That includes writing up orders by hand.

A Ford spokesperson added that the outage may cause “some delays and inconveniences at some dealers and for some customers.” However, many Ford and Lincoln customers are still getting sales and service support through alternative routes being used at dealerships.

Group 1 Automotive Inc., which owns 202 automotive dealerships, 264 franchises, and 42 collision centers in the US and the United Kingdom, said Monday that the incident has disrupted its business applications and processes in its US operations that rely on CDK’s dealers’ systems. The company said that it took measures to protect and isolate its systems from CDK’s platform.

All Group 1 US dealerships will continue to conduct business using alternative processes until CDK’s dealers’ systems are available, the company said Monday. Group 1’s dealerships in the UK don't use CDK’s dealers’ systems and are not impacted by the incident.

With many details of the cyberattacks still unclear, customer privacy is also at top of mind — especially with little known about what information may have been compromised this week.

In a statement sent to the AP on Friday, Mike Stanton, president and CEO of the National Automobile Dealers Association said that “dealers are very committed to protecting their customer information and are actively seeking information from CDK to determine the nature and scope of the cyber incident so they can respond appropriately."



Mozilla Hit with Privacy Complaint Over Firefox User Tracking

FILE PHOTO: The Firefox logo is seen at a Mozilla stand during the Mobile World Congress in Barcelona, February 28, 2013. REUTERS/Albert Gea/File Photo
FILE PHOTO: The Firefox logo is seen at a Mozilla stand during the Mobile World Congress in Barcelona, February 28, 2013. REUTERS/Albert Gea/File Photo
TT

Mozilla Hit with Privacy Complaint Over Firefox User Tracking

FILE PHOTO: The Firefox logo is seen at a Mozilla stand during the Mobile World Congress in Barcelona, February 28, 2013. REUTERS/Albert Gea/File Photo
FILE PHOTO: The Firefox logo is seen at a Mozilla stand during the Mobile World Congress in Barcelona, February 28, 2013. REUTERS/Albert Gea/File Photo

Vienna-based advocacy group NOYB on Wednesday said it has filed a complaint with the Austrian data protection authority against Mozilla accusing the Firefox browser maker of tracking user behavior on websites without consent.
NOYB (None Of Your Business), the digital rights group founded by privacy activist Max Schrems, said Mozilla has enabled a so-called “privacy preserving attribution” feature that turned the browser into a tracking tool for websites without directly telling its users, Reuters reported.
Mozilla had defended the feature, saying it wanted to help websites understand how their ads perform without collecting data about individual people. By offering what it called a non-invasive alternative to cross-site tracking, it hoped to significantly reduce collecting individual information.
While this may be less invasive than unlimited tracking, it still interferes with user rights under the EU’s privacy laws, NOYB said, adding that Firefox has turned on the feature by default.
“It’s a shame that an organization like Mozilla believes that users are too dumb to say yes or no,” said Felix Mikolasch, data protection lawyer at NOYB. “Users should be able to make a choice and the feature should have been turned off by default.”
Open-source Firefox was once a top browser choice among users due to its privacy features but now lags market leader Google’s Chrome, Apple’s Safari and Microsoft’s Edge with a low single-digit market share.
NOYB wants Mozilla to inform users about its data processing activities, switch to an opt-in system and delete all unlawfully processed data of millions of affected users.
NOYB, which in June filed a complaint against Alphabet for allegedly tracking users of its Chrome browser, had also filed hundreds of complaints against big tech companies, some leading to big fines.