In June 2024, CDK Global — headquartered in Austin, Texas — paid $25 million in Bitcoin to ransomware operators. The company's 15,000 dealer clients, including major Texas operations, lost more than $1 billion in 14 days. 100,000 fewer cars were sold in June 2024 compared to the prior year. Here's what that means for every Texas dealer.
The CDK Precedent — What a Texas DMS Vendor Attack Actually Costs
CDK Global isn't a random target. It's the dominant DMS platform for franchised auto dealers in North America, handling everything from sales and F&I to service write-ups and parts management. When CDK goes dark, the entire dealer operation goes dark — not because of anything the dealer did, but because of a single vendor's infrastructure failure.
The June 2024 attack happened in two waves. First wave: CDK detected the intrusion and shut down to contain it, taking all connected dealers offline. Second wave: the attackers re-entered during the recovery period before CDK had fully restored operations. CDK reportedly paid approximately $25 million to the BlackSuit ransomware operators to accelerate the recovery.
The dealer impact was catastrophic and asymmetric:
- NADA estimates: average dealer lost $1M+ in revenue during the CDK outage. High-volume stores with strong service departments likely exceeded $2M.
- Cox Automotive data: US vehicle sales dropped 7.2% in June 2024 compared to June 2023 — the first year-over-year sales decline in nearly two years, driven directly by the CDK-induced inventory bottleneck.
- Public dealer disclosures: AutoNation, Group 1 Automotive (Houston, TX HQ), and Sonic Automotive all confirmed CDK impact in SEC disclosures. Group 1's Houston operations were particularly exposed given its heavy CDK dependency.
- No recourse: Dealer contracts with DMS vendors typically include liability caps that prevent dealers from recovering their operational losses from CDK, Reynolds, or Dealertrack — even when the vendor's security failure is the direct cause of the loss.
The critical lesson is that the CDK outage was not a technology problem — it was a supply chain risk management failure. Every dealer that assumed CDK's infrastructure was being monitored had a false sense of security. The dealers who survived the outage most effectively were those who already had independent network monitoring and DMS-independent backup workflows. Most did not.
Two More Incidents — Both Dealer-Vendor Supply Chain Hits
The CDK outage wasn't isolated. Two additional incidents in late 2025 show the pattern is not CDK-specific — it's the DMS vendor supply chain model itself that creates catastrophic dealer exposure.
Motility Software / Reynolds & Reynolds — August 2025
What happened: Pear ransomware hit Motility Software, a DMS provider serving approximately 7,000 independent and buy-here-pay-here dealers. 4.3 terabytes of data was exfiltrated before encryption was deployed. 766,670 individuals' data was confirmed compromised.
Impact: Specialty dealers — including subprime and independent operators — who rely on Motility for F&I, inventory, and customer records were hit with both data exfiltration and system encryption simultaneously. The double-extortion model (data stolen + systems encrypted) meant dealers couldn't just restore from backup and ignore the breach — they faced both remediation costs and regulatory notification obligations.
TX relevance: Independent and BHPH dealers across Texas use Motility and Reynolds-adjacent platforms. The F&I data concentration in these platforms includes SSN, income verification, employment history, and vehicle information — the complete credit profile needed for synthetic identity fraud.
700Credit — October 2025
What happened: 700Credit, a credit application data provider serving 18,000+ dealership locations, suffered a PII breach exposing complete consumer credit application records. Exfiltrated data included SSN, date of birth, income, employment history, and financing terms for an estimated 5.6 million consumers.
Why this matters for dealers: Credit application data is the highest-value identity theft package available. A complete financial profile — SSN + DOB + income + employment + vehicle + financing terms — enables synthetic identity fraud, account takeover, and credit application fraud that can take years to detect. Dealers who used 700Credit as part of their F&I process are the covered financial institution under FTC Safeguards Rule — not 700Credit. The dealer holds the breach notification obligations, even though the breach was a vendor's failure.
The liability transfer: FTC Safeguards Rule 16 CFR 314.4(9) requires covered institutions to "monitor service provider access to customer information" — meaning the dealer is responsible for monitoring 700Credit's security posture, not just relying on 700Credit's contractual representations.
The 7-Obligation Regulatory Stack — TX Auto Dealers Are Not Exempt
Every franchised auto dealer in Texas that handles customer financing is simultaneously subject to multiple regulatory frameworks — all active, all enforced, all creating liability exposure that most dealers haven't mapped.
FTC Safeguards Rule — 16 CFR Part 314
Full enforcement since June 2023. Every dealer holding customer financial information is a "covered financial institution." 8 operational requirements: written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, penetration testing.
FTC has pursued dealers for: no written ISP, no QI designation, no service provider monitoring. CDK = vendor oversight failure.
TX Bus & Com §521 — TDPSA Breach Notification
Texas breach notification law. AG notification required for breaches affecting 250+ Texas residents. Civil penalty up to $100/day per individual up to $250K. "Reasonable time" notification standard — typically interpreted as 30–60 days from discovery.
A CDK or 700Credit-style breach at a TX dealer easily exceeds the 250-resident threshold.
GLBA — Captive Finance & BHPH Operations
Dealers with in-house financing or BHPH operations are treated as financial institutions. Privacy notice requirements, data handling restrictions, and a safeguards program that goes beyond the FTC Safeguards baseline.
BHPH dealers face additional CFPB fair lending oversight that intersects with data security governance.
PCI DSS v4.0.1 — F&I Credit Card Processing
Any dealer accepting credit cards for deposits, service, or parts is in scope. Most franchised dealers process under SAQ A or SAQ B-IP. Non-compliance = card brand fines and forensic investigation costs after a breach.
SAQ completion and quarterly scanning are the minimum for most dealers.
5 Threat Vectors Every Texas Dealer Faces
DMS Supply Chain Lockout
CDK, Reynolds, Dealertrack, Dominion — any DMS compromise propagates to every connected dealer simultaneously. No dealer control over vendor security posture. CDK proved this: 15,000 dealers offline regardless of individual security hygiene. Recovery path is entirely dependent on the DMS vendor's response speed.
F&I PII Exfiltration
Every credit application generates complete identity packages: SSN, DOB, income, employment, financing terms. 700Credit exposed 5.6M consumers. Dealers hold the breach notification obligations for data they don't directly control. Double-extortion means even backup restoration doesn't eliminate regulatory exposure.
Floor Plan & OEM Wire BEC
FBI IC3: automotive sector BEC losses up 34% YoY. Floor plan curtailments to Ally, NextGear, and captive finance companies are high-value, time-sensitive wire transfers. Single incident can exceed $500K. OEM rebate fraud — impersonating manufacturer representatives to redirect incentive payments — is documented against Ford, GM, and Toyota dealer groups.
Month-End Ransomware Timing
Dealer month-end close creates predictable peak activity windows. Ransomware groups actively time attacks for these windows — maximum operational pressure, maximum financial leverage. A month-end attack on a high-volume store means simultaneous revenue loss + manual workaround chaos + regulatory notification obligations.
Service Bay OT Exposure
Shop management systems (CDK Service, Reynolds Service, DealerSocket) share network infrastructure with DMS sales/F&I systems. IoT-connected service equipment — alignment racks, EV charger management, tire pressure systems — adds OT attack surface that standard IT monitoring doesn't cover. For EV-focused dealerships, OEM franchise agreements increasingly require documented charger network security.
8 Controls Every TX Auto Dealer Needs Now
The 8-Point Action Checklist
Find Out if Your DMS Network Has CDK Breach Window Exposure
30-minute call. Map your DMS attack surface, FTC Safeguards compliance gaps, BEC vulnerability on floor plan flows, and vendor risk for CDK/Reynolds/700Credit. Free assessment — no obligation.
Get Free Assessment →SDVOSB Certified · 30-Min SLA · TX-Based Team · CDK-Aware Monitoring