The June 2024 CDK Global cyberattack crippled ~15,000 franchised dealers for nearly three weeks — estimated $1B+ in industry losses. DMS vendors are your biggest third-party risk. CoreRecon delivers 24/7 SOC + 30-minute SLA for dealerships that can't afford another CDK — with FTC Safeguards Rule compliance built in. Texas has ~1,300 franchised dealers. Most are not ready.
Auto dealers run a uniquely target-rich environment: DMS platforms holding every customer's SSN and credit data, F&I desks processing finance apps, service bays on connected shop management systems, and floor plan wire transfers moving millions. Each layer is a separate attack surface with its own adversary profile.
Auto dealers face a tighter compliance stack than most SMBs realize. The FTC Safeguards Rule alone has eight operational requirements that most dealers are not meeting. Add state breach notification, PCI DSS for F&I credit card processing, and GLBA for finance arms — and the compliance picture is genuinely complex.
| Framework | Applies To | Enforcement / Deadline | CoreRecon Coverage |
|---|---|---|---|
| FTC Safeguards Rule 16 CFR Part 314 — written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, penetration testing |
All franchised dealers and independent dealers holding customer financial information — defined broadly to include any credit application, financing record, or insurance data. Applies to every auto dealer with F&I operations regardless of size | Full requirements effective June 2023; FTC has pursued enforcement actions; no size exemption below 5,000 customer records for the written ISP and Qualified Individual requirements; 30-day breach notification trigger at 500+ affected customers | Sentinel MFA deployment, encryption verification, IR plan template, basic ISP framework. Fortress Vendor oversight program for DMS/F&I vendors, annual penetration testing, encrypted backup. Command Qualified Individual service, written ISP authorship, annual board report, full Safeguards program ownership |
| TX Bus & Com Code §521 Texas breach notification law — covers SSN, driver's license, financial account numbers |
All Texas dealers holding customer PII — virtually every franchised dealer in Texas given F&I credit applications, motor vehicle title records, and service records containing driver's license numbers | Must notify affected individuals within a "reasonable time" after discovery; AG notification required for breaches affecting 250+ Texas residents; civil penalty up to $100/day per individual up to $250K; AG may seek injunctive relief | Sentinel Breach detection and documentation. Fortress Forensic investigation support, breach scope determination. Command Full breach notification management, AG reporting coordination, legal notification letter support |
| PCI DSS 4.0.1 Payment card security for F&I credit card processing and service department payments |
Dealerships accepting credit cards for vehicle deposits, service payments, or parts purchases — which includes virtually every dealership with a service department or that accepts any credit card at point of sale | PCI DSS 4.0.1 requirements in full effect 2025; non-compliance can result in card brand fines ($5K–$100K/month), loss of card acceptance, and mandatory forensic investigation costs after a breach; most dealers process under SAQ A or SAQ B-IP | Sentinel Network segmentation to isolate cardholder data environment, log monitoring for payment system anomalies. Fortress Annual SAQ completion support, quarterly vulnerability scanning, penetration testing for PCI scope systems |
| GLBA — Finance Arms Gramm-Leach-Bliley Act for dealers with captive finance or in-house financing operations |
Dealers with in-house financing, buy-here-pay-here operations, or captive finance subsidiaries — treated as financial institutions under GLBA with full privacy notice, data handling, and safeguards obligations beyond the FTC Safeguards Rule | GLBA requirements continuous — no sunset; state AG enforcement in Texas; dealers with BHPH portfolios face additional CFPB oversight under fair lending requirements that intersect with data security obligations | Command GLBA compliance mapping for captive finance operations, data handling controls for consumer financial records, privacy notice accuracy review, integration with CFPB-relevant data governance requirements |
Ransomware groups that target dealers now have documented playbooks built from multiple real-world dealer attacks. The CDK outage gave them their first look at how much leverage a DMS compromise provides. Arnold Clark showed what F&I data exfiltration looks like at scale.
In June 2024, CDK Global — the DMS platform used by approximately 15,000 franchised auto dealers across North America — suffered two consecutive cyberattacks within days of each other. The BlackSuit ransomware group is attributed. CDK shut down all systems to contain the breach, taking every CDK-dependent dealer offline simultaneously.
The outage lasted approximately 2–3 weeks for most dealers. Dealers were forced to manual paper-based processes for deals, financing, and service. Industry estimates placed total dealer losses at $1B+. CDK reportedly paid approximately $25M in ransom to accelerate recovery. The attack demonstrated the catastrophic supply chain risk of DMS dependency — a single vendor compromise affects every connected dealer simultaneously, regardless of the individual dealer's own security posture.
Source: Reuters, Wall Street Journal reporting June–July 2024; SEC 8-K filings. CoreRecon had no involvement in this incident.
Arnold Clark — the UK's largest privately-owned car dealer group with 200+ outlets — was breached in December 2022 by the Play ransomware group. The attackers exfiltrated data on over 1 million customers before Arnold Clark detected the intrusion in January 2023. Exfiltrated data included names, dates of birth, addresses, contact details, National Insurance numbers (UK equivalent of SSN), passport information, and driver's license data.
The breach demonstrated what F&I data exfiltration looks like at scale: a single dealer group's customer database contains enough PII to enable identity theft for every customer who ever financed a vehicle with them. Texas dealer groups with 50,000–500,000 customer records face identical data concentration risk. The Arnold Clark attackers used data exfiltration as leverage — threatening to publish records publicly if ransom was not paid.
Source: Arnold Clark official statements; ICO (UK data protection authority) investigation 2023. CoreRecon had no involvement in this incident.
Most MSSPs treat a dealership like any other SMB. CoreRecon maps the specific attack surfaces of the dealer technology stack — DMS, F&I document platforms, OEM portals, and service management systems — and monitors the integration points that CDK proved are the real risk.
Average franchised dealership runs 50–150 endpoints: sales writers, F&I desks, service advisors, parts counter, management, and admin. Month-to-month. No long-term contracts. 10-endpoint minimum.
Endpoint guidance for Texas dealers: Single-point franchised dealer (new vehicles only): 50–80 endpoints. Full-line dealer with service and parts: 80–120 endpoints. High-volume group store: 100–150+ endpoints. Multiply by $89 (Sentinel) or $129 (Fortress) for your monthly estimate. Command tier is fixed-fee custom scope — typical single-rooftop dealer starts at $2,500/mo.
We map your DMS-connected endpoints, identify FTC Safeguards compliance gaps, check BEC vulnerability on your floor plan and OEM payment flows, and deliver a dealer-specific remediation roadmap. No credit card. No commitment. Delivered in 14 days.
Request your free $2,500 assessment →Delivered within 14 days • No credit card • SDVOSB-certified team
Yes. CoreRecon monitors the network layer around CDK-connected environments — endpoint telemetry, authentication anomalies, and network behavior between CDK-connected workstations and your internal infrastructure. We don't replace CDK; we provide the security monitoring layer that CDK's own infrastructure cannot provide. Critically, we conduct CDK-specific threat hunts during onboarding to identify any persistent access that may have been established during the June 2024 outage window. The BlackSuit ransomware group that hit CDK maintained access inside CDK's network for weeks before executing — your dealer network may have been exposed during that period. Our onboarding hunt addresses that specific risk.
CoreRecon monitoring runs on your endpoint and network infrastructure independently of CDK availability. We don't lose visibility when your DMS goes offline. In fact, DMS outage scenarios require more monitoring attention — not less. Manual fallback processes (paper deals, offline service write-ups) introduce social engineering opportunities and manual override risks that digital workflows prevent. Fortress tier includes specific detection for the manual workflow patterns that activate during DMS outages, such as unusual export activity as staff try to pull data offline, and BEC attempts targeting staff who are managing deals manually and are more susceptible to phone-based fraud.
Command tier's vCISO service fulfills the 16 CFR 314.4(a) Qualified Individual requirement. The FTC Safeguards Rule requires a designated Qualified Individual to oversee your ISP — someone with relevant experience who coordinates implementation, reports to ownership annually, and maintains the program. The FTC's own guidance explicitly permits an outside party to serve in this role. Command tier includes: ISP authorship and maintenance, annual risk assessment, annual written report to owner or board, vendor oversight program coordination (CDK, Reynolds, Dealertrack), and IR plan maintenance. This covers all eight operational requirements under 16 CFR 314.4 for a single-point dealer. Multi-rooftop groups are covered under the same engagement at consolidated pricing.
Multi-rooftop groups get a single consolidated security program under Command tier — one ISP covering all rooftops, centralized SIEM with per-location visibility, and one vCISO who understands the full group's DMS and F&I stack. Pricing scales by total endpoint count across all rooftops; you don't pay per-location overhead. A 5-rooftop group averaging 80 endpoints per location (400 total endpoints) is a standard Command engagement. We've handled mixed-make groups with CDK at some rooftops and Reynolds at others — heterogeneous DMS environments are not a problem. The consolidated ISP satisfies FTC Safeguards requirements for the entire group under one Qualified Individual designation.
Yes — significantly. Dealers with captive finance operations, BHPH portfolios, or in-house financing subsidiaries are treated as financial institutions under both GLBA and the FTC Safeguards Rule, with the full set of obligations that entails — including annual privacy notices, consumer data handling restrictions, and safeguards program requirements that are more stringent than those applied to dealers that only accept third-party financing. BHPH dealers with large consumer loan portfolios also have CFPB oversight exposure that intersects with data security obligations. Command tier includes GLBA compliance mapping for captive finance operations and coordinates data handling controls for consumer financing records with your DMS configuration.
Command tier at $2,500+/month includes IR retainer services with pre-authorized containment authority and 30-minute SLA. Pre-built playbooks cover the specific scenarios dealers face: DMS ransomware and offline isolation, F&I data breach with FTC breach notification workflow, BEC on floor plan or OEM rebate payment flows, and OEM portal credential compromise. A ransomware event on a CDK-connected dealership environment typically requires 2–4 weeks of IR engagement to fully contain, remediate, document, and satisfy FTC Safeguards breach notification obligations (30-day clock from discovery for incidents affecting 500+ customers). The monthly retainer cost is a fraction of what an unretained emergency IR engagement costs — market rates for forensic IR firms responding to dealer ransomware events run $25K–$150K+ for the full engagement, plus legal and notification costs.
Texas dealers are the most financially exposed sector in the SMB market — SSN and credit data on every customer, floor plan wires moving daily, and DMS vendors that proved they can take you down for weeks. Our free assessment maps your DMS attack surface, checks FTC Safeguards compliance gaps, and delivers a dealer-specific remediation roadmap. No credit card. No commitment.
Request your free $2,500 assessment →Delivered within 14 days • No credit card • SDVOSB-certified team