Home Blog TX Auto Dealers Under Cyber Siege

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →

In June 2024, CDK Global — headquartered in Austin, Texas — paid $25 million in Bitcoin to ransomware operators. The company's 15,000 dealer clients, including major Texas operations, lost more than $1 billion in 14 days. 100,000 fewer cars were sold in June 2024 compared to the prior year. Here's what that means for every Texas dealer.

$25M
CDK ransom paid (Jun 2024 — WSJ confirmed)
15,000
dealers offline 2–3 weeks during CDK outage
5.6M
consumers exposed via 700Credit (Oct 2025)

The CDK Precedent — What a Texas DMS Vendor Attack Actually Costs

CDK Global isn't a random target. It's the dominant DMS platform for franchised auto dealers in North America, handling everything from sales and F&I to service write-ups and parts management. When CDK goes dark, the entire dealer operation goes dark — not because of anything the dealer did, but because of a single vendor's infrastructure failure.

The June 2024 attack happened in two waves. First wave: CDK detected the intrusion and shut down to contain it, taking all connected dealers offline. Second wave: the attackers re-entered during the recovery period before CDK had fully restored operations. CDK reportedly paid approximately $25 million to the BlackSuit ransomware operators to accelerate the recovery.

The dealer impact was catastrophic and asymmetric:

The critical lesson is that the CDK outage was not a technology problem — it was a supply chain risk management failure. Every dealer that assumed CDK's infrastructure was being monitored had a false sense of security. The dealers who survived the outage most effectively were those who already had independent network monitoring and DMS-independent backup workflows. Most did not.

Two More Incidents — Both Dealer-Vendor Supply Chain Hits

The CDK outage wasn't isolated. Two additional incidents in late 2025 show the pattern is not CDK-specific — it's the DMS vendor supply chain model itself that creates catastrophic dealer exposure.

Motility Software / Reynolds & Reynolds — August 2025

Pear Ransomware — 4.3 TB Data Exfiltrated

What happened: Pear ransomware hit Motility Software, a DMS provider serving approximately 7,000 independent and buy-here-pay-here dealers. 4.3 terabytes of data was exfiltrated before encryption was deployed. 766,670 individuals' data was confirmed compromised.

Impact: Specialty dealers — including subprime and independent operators — who rely on Motility for F&I, inventory, and customer records were hit with both data exfiltration and system encryption simultaneously. The double-extortion model (data stolen + systems encrypted) meant dealers couldn't just restore from backup and ignore the breach — they faced both remediation costs and regulatory notification obligations.

TX relevance: Independent and BHPH dealers across Texas use Motility and Reynolds-adjacent platforms. The F&I data concentration in these platforms includes SSN, income verification, employment history, and vehicle information — the complete credit profile needed for synthetic identity fraud.

4.3 TB exfiltrated 766,670 individuals Double-extortion model 7,000 specialty dealers affected

700Credit — October 2025

F&I Credit Application PII Breach — 18,000 Dealerships

What happened: 700Credit, a credit application data provider serving 18,000+ dealership locations, suffered a PII breach exposing complete consumer credit application records. Exfiltrated data included SSN, date of birth, income, employment history, and financing terms for an estimated 5.6 million consumers.

Why this matters for dealers: Credit application data is the highest-value identity theft package available. A complete financial profile — SSN + DOB + income + employment + vehicle + financing terms — enables synthetic identity fraud, account takeover, and credit application fraud that can take years to detect. Dealers who used 700Credit as part of their F&I process are the covered financial institution under FTC Safeguards Rule — not 700Credit. The dealer holds the breach notification obligations, even though the breach was a vendor's failure.

The liability transfer: FTC Safeguards Rule 16 CFR 314.4(9) requires covered institutions to "monitor service provider access to customer information" — meaning the dealer is responsible for monitoring 700Credit's security posture, not just relying on 700Credit's contractual representations.

5.6M consumers exposed SSN + DOB + income + employment FTC Safeguards QI obligation triggered 18,000 dealership locations

The 7-Obligation Regulatory Stack — TX Auto Dealers Are Not Exempt

Every franchised auto dealer in Texas that handles customer financing is simultaneously subject to multiple regulatory frameworks — all active, all enforced, all creating liability exposure that most dealers haven't mapped.

FTC Safeguards Rule — 16 CFR Part 314

Full enforcement since June 2023. Every dealer holding customer financial information is a "covered financial institution." 8 operational requirements: written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, penetration testing.

Enforcement actions against auto dealers specifically

FTC has pursued dealers for: no written ISP, no QI designation, no service provider monitoring. CDK = vendor oversight failure.

TX Bus & Com §521 — TDPSA Breach Notification

Texas breach notification law. AG notification required for breaches affecting 250+ Texas residents. Civil penalty up to $100/day per individual up to $250K. "Reasonable time" notification standard — typically interpreted as 30–60 days from discovery.

$7,500/violation — AG enforcement

A CDK or 700Credit-style breach at a TX dealer easily exceeds the 250-resident threshold.

GLBA — Captive Finance & BHPH Operations

Dealers with in-house financing or BHPH operations are treated as financial institutions. Privacy notice requirements, data handling restrictions, and a safeguards program that goes beyond the FTC Safeguards baseline.

BHPH dealers face additional CFPB fair lending oversight that intersects with data security governance.

PCI DSS v4.0.1 — F&I Credit Card Processing

Any dealer accepting credit cards for deposits, service, or parts is in scope. Most franchised dealers process under SAQ A or SAQ B-IP. Non-compliance = card brand fines and forensic investigation costs after a breach.

SAQ completion and quarterly scanning are the minimum for most dealers.

The key insight most dealers miss: When a DMS vendor or F&I data provider is breached, the dealer — not the vendor — holds the FTC Safeguards and TDPSA breach notification obligations. The FTC explicitly requires dealers to "monitor service provider access to customer information." That means a documented vendor risk program for CDK, Reynolds, Motivity, and 700Credit is not optional — it's a compliance requirement. Most dealers have no such program.

5 Threat Vectors Every Texas Dealer Faces

DMS Supply Chain Lockout

CDK, Reynolds, Dealertrack, Dominion — any DMS compromise propagates to every connected dealer simultaneously. No dealer control over vendor security posture. CDK proved this: 15,000 dealers offline regardless of individual security hygiene. Recovery path is entirely dependent on the DMS vendor's response speed.

F&I PII Exfiltration

Every credit application generates complete identity packages: SSN, DOB, income, employment, financing terms. 700Credit exposed 5.6M consumers. Dealers hold the breach notification obligations for data they don't directly control. Double-extortion means even backup restoration doesn't eliminate regulatory exposure.

Floor Plan & OEM Wire BEC

FBI IC3: automotive sector BEC losses up 34% YoY. Floor plan curtailments to Ally, NextGear, and captive finance companies are high-value, time-sensitive wire transfers. Single incident can exceed $500K. OEM rebate fraud — impersonating manufacturer representatives to redirect incentive payments — is documented against Ford, GM, and Toyota dealer groups.

Month-End Ransomware Timing

Dealer month-end close creates predictable peak activity windows. Ransomware groups actively time attacks for these windows — maximum operational pressure, maximum financial leverage. A month-end attack on a high-volume store means simultaneous revenue loss + manual workaround chaos + regulatory notification obligations.

Service Bay OT Exposure

Shop management systems (CDK Service, Reynolds Service, DealerSocket) share network infrastructure with DMS sales/F&I systems. IoT-connected service equipment — alignment racks, EV charger management, tire pressure systems — adds OT attack surface that standard IT monitoring doesn't cover. For EV-focused dealerships, OEM franchise agreements increasingly require documented charger network security.

8 Controls Every TX Auto Dealer Needs Now

The 8-Point Action Checklist

Written ISP with designated Qualified Individual (FTC 16 CFR 314.4(a)). Outside vCISO satisfies the QI requirement under FTC guidance.
DMS Air-Gapped Backup + Quarterly Recovery Testing. Off-site immutable backups for DMS configs and F&I databases. Tested recovery path is the difference between 3 weeks and 48 hours.
FTC Safeguards Rule Compliance Audit — all 8 requirements mapped to your current posture with a prioritized remediation roadmap.
Third-Party Vendor Risk Program for CDK, Reynolds, Motility, 700Credit, and any F&I tool vendor. Documented security requirements, breach notification clauses, access monitoring.
30-Day FTC Breach Notification Drill. Annual tabletop exercise simulating the CDK/700Credit scenario: FTC notification, TX AG notification, customer letters, incident documentation. Pre-built templates ready to deploy within the required timeframe.
BEC / Wire Fraud Controls on floor plan and OEM payment flows. MFA on controller and dealer principal email. Dual-authorization for wires exceeding threshold. OEM portal credential monitoring.
DMS-Specific Incident Response Plan with playbooks for: DMS ransomware + offline isolation, F&I data breach + FTC notification, BEC on floor plan/OEM rebate flows.
TX TDPSA + FTC Safeguards Dual Compliance Mapping. One engagement covers both — TDPSA AG notification ($250K max penalty) and FTC 30-day customer notification simultaneously.

Find Out if Your DMS Network Has CDK Breach Window Exposure

30-minute call. Map your DMS attack surface, FTC Safeguards compliance gaps, BEC vulnerability on floor plan flows, and vendor risk for CDK/Reynolds/700Credit. Free assessment — no obligation.

Get Free Assessment →

SDVOSB Certified  ·  30-Min SLA  ·  TX-Based Team  ·  CDK-Aware Monitoring

TX Auto Dealer Security → Breach Cost Calculator → BEC Impact Calculator → Gated PDF Brief →
Sources & Citations Reuters: CDK Global cyberattack coverage (Jun 2024) • Wall Street Journal: CDK $25M ransom payment (Jun 2024) • SEC 8-K filings: AutoNation, Group 1 Automotive (Houston HQ), Sonic Automotive CDK impact disclosures • NADA: CDK outage dealer impact estimates (Jun–Jul 2024) • Cox Automotive: US vehicle sales data June 2024 (-7.2% YoY) • FBI IC3 2025 Annual Report ($20.877B losses, 1,008,597 complaints) • FBI IC3 2024: automotive sector BEC +34% YoY • IBM Cost of Data Breach Report 2025 (241-day dwell time, $10.22M US avg, 17 industries) • FTC 16 CFR Part 314: Safeguards Rule requirements (enforced since Jun 2023) • FTC enforcement actions against auto dealers (2023–2025) • TX Bus & Com Code §521: TDPSA breach notification • GLBA 15 USC 6801: Financial institution safeguards • PCI SSC: PCI DSS v4.0.1 • CFPB supervisory guidance on data governance (2024) • ICO UK: Arnold Clark breach investigation (Dec 2022, 1M+ records) • CoreRecon threat intelligence: Motility Software, 700Credit (2025)