CoreRecon Intelligence Report  •  June 2026

Texas Auto Dealers
Cyber Threat Brief
2026

CDK Global paid $25M ransom. 15,000 dealers offline for 3 weeks — $1B+ industry losses. 700Credit: 5.6M consumers exposed. Motility/Reynolds: 766,670 individuals. FTC Safeguards Rule enforcement active. CoreRecon delivers 24/7 SOC with 30-minute SLA for Texas's ~1,300 franchised auto dealers.

$25M
CDK ransom paid
Jun 2024
15,000
dealers offline
2–3 weeks
5.6M
consumers exposed
700Credit Oct 2025
766K
individuals affected
Motility/Reynolds
Download Full Brief (PDF) Get Free Security Assessment
Sources: Reuters, Wall Street Journal, SEC 8-K filings (CDK Global, AutoNation, Sonic Automotive, Group 1 Automotive), ICO UK (Arnold Clark), CISA/FBI Advisories • FBI IC3 2025 • IBM CODB 2025

Auto dealers are the
#1 supply chain attack target

Metric Value Source
CDK Global dealers offline (Jun 2024 ransomware) 15,000 Reuters, Wall Street Journal
Estimated industry losses from CDK outage (14 days) $1B+ NADA, industry analyst estimates
CDK ransom payment (reported) $25M Wall Street Journal, Jun 2024
US vehicle sales drop (Jun 2024 vs prior year) 7.2% Cox Automotive, Jun 2024 sales data
700Credit consumers exposed (Oct 2025) 5.6M CoreRecon threat intelligence
Motility/Reynolds individuals affected (Aug 2025) 766,670 CoreRecon threat intelligence
TX franchised auto dealers ~1,300 TADA (TX Automobile Dealers Association)
Automotive BEC loss increase (2024 vs 2023) +34% FBI IC3 2025 Annual Report
Why auto dealers? DMS platforms (CDK, Reynolds & Reynolds, Dealertrack) aggregate complete consumer financial profiles — SSN, DOB, income, credit history, financing terms — for every deal. A single DMS vendor compromise exposes the F&I data of every connected dealer simultaneously. Dealers are uniquely exposed because (1) DMS vendors are concentrated single points of failure, (2) F&I data is the highest-value identity theft target, and (3) floor plan financing wires create BEC opportunities that can exceed $500K per incident.

Three incidents that
defined the sector

Entity Date Attribution Impact Cost
CDK Global
Austin-based DMS vendor — TX HQ
June 2024 (two attacks within days)
BlackSuit ransomware (attributed)
15,000 franchised dealers offline 2–3 weeks. Dealers forced to manual paper-based processes. CDK shutdown affected all connected dealer systems — sales, F&I, service. AutoNation, Group 1 Automotive (Houston HQ), and Sonic Automotive all confirmed CDK-impacted. US vehicle sales dropped 7.2% in June 2024 vs prior year.
$25M ransom paid
$1B+ industry losses
Motility Software / Reynolds & Reynolds
4,000+ specialty dealers affected
August 2025 — Pear ransomware
Pear ransomware — 4.3 TB data exfiltrated
766,670 individuals' data exfiltrated. 7,000 specialty dealers affected. DMS platform used primarily by independent and buy-here-pay-here dealers — different segment from CDK but same supply chain risk profile. F&I and customer data exfiltrated before encryption deployment.
4.3 TB exfiltrated
766,670 individuals
700Credit
18,000 dealerships — multi-state reach
October 2025
PII breach — credit application data
F&I credit application data exposed: SSNs, DOBs, income, employment data, financing terms. 18,000 dealership locations affected. Credit application data is the single highest-value identity theft package available — complete financial profiles used for synthetic identity fraud and account takeover. Affected dealers face FTC Safeguards Rule and state breach notification obligations.
5.6M consumers
F&I PII exposed
TX exposure: CDK Global is headquartered in Austin, Texas. The June 2024 attack originated from and centered on a Texas-based technology company. Group 1 Automotive — a major Texas dealer group headquartered in Houston — confirmed CDK impact and disclosed to the SEC. Every Texas franchised dealer using CDK, Reynolds, or Dealertrack faces the same supply chain exposure.

Critical point: When a DMS vendor is breached, the dealer — not the DMS vendor — holds the breach notification obligations to customers, the FTC, and state attorneys general. The FTC Safeguards Rule places liability on the dealer as a covered financial institution, not on CDK or Reynolds as technology vendors.

Seven overlapping obligations.
All active. All enforced.

Federal — Active Enforcement
FTC Safeguards Rule — 16 CFR Part 314
Full enforcement since June 2023. Every franchised auto dealer holding customer financial information is a covered financial institution. 8 operational requirements: written ISP, designated Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, penetration testing.

Key dealer gap: The FTC has pursued enforcement actions against auto dealers specifically — citing failures to have a written ISP, failure to designate a Qualified Individual, and failure to monitor service provider access to customer data. CDK exposure is a vendor oversight failure under Safeguards Rule.

Source: FTC 16 CFR Part 314; FTC enforcement actions 2023–2025
Texas State Law — Active Jul 2024
TX Bus & Com §521 — TDPSA Breach Notification
Every Texas dealer must notify affected individuals within a reasonable time after discovery. AG notification required for breaches affecting 250+ Texas residents. Civil penalty up to $100/day per individual up to $250K. AG may seek injunctive relief.

Dealer F&I files containing SSN, driver's license, and financial account numbers are squarely within scope. Every CDK-connected dealer that had customer data processed through CDK's infrastructure is potentially in breach notification territory — regardless of whether CDK notified the dealer.

Source: TX Bus & Com Code §521; TX AG enforcement patterns
Federal — Active (Finance Arms)
GLBA — Captive Finance & BHPH Operations
Dealers with in-house financing, buy-here-pay-here portfolios, or captive finance subsidiaries are treated as financial institutions under Gramm-Leach-Bliley Act. Full privacy notice, data handling restrictions, and safeguards program requirements — beyond the FTC Safeguards Rule baseline.

BHPH dealers with large consumer loan portfolios also have CFPB oversight exposure intersecting with data security obligations. Fair lending data governance and data security are not separate compliance tracks — they intersect at your DMS and F&I database configuration.

Source: GLBA 15 USC 6801; CFPB supervisory guidance 2024
Federal — Active (Card Processing)
PCI DSS v4.0.1 — F&I Credit Card Processing
Any dealer accepting credit cards for vehicle deposits, service payments, or parts purchases falls under PCI DSS requirements. Most franchised dealers process under SAQ A (e-commerce) or SAQ B-IP (standalone terminal). Non-compliance: card brand fines ($5K–$100K/month), loss of card acceptance, mandatory forensic investigation after breach.

Source: PCI SSC PCI DSS v4.0.1; card brand compliance programs

Five attack vectors
every dealer faces

DMS Supply Chain
CDK, Reynolds & Reynolds, and Dealertrack are centralized platforms. A single vendor compromise propagates to every connected dealer simultaneously. CDK demonstrated this in real time — 15,000 dealers had no control over their DMS vendor's security posture.
F&I PII Exfiltration
Credit applications contain complete identity packages: SSN, DOB, income, employment, vehicle details, financing terms. 700Credit exposed 5.6M consumers. The dealer bears the FTC Safeguards breach notification obligation — even if the data was exfiltrated via the DMS vendor.
Floor Plan BEC
Floor plan curtailment wires to Ally, NextGear, and OEM captive finance companies are high-value, time-sensitive transfers. A BEC attack targeting the controller or dealer principal email can redirect $250K–$500K+ per incident. FBI IC3: automotive sector BEC losses up 34% YoY.
Service Bay Ransomware
Service department shop management (CDK Service, Reynolds Service, DealerSocket) is networked to the same DMS infrastructure handling sales. A ransomware event hitting the DMS takes down service write-ups, RO completion, parts ordering, and tech time-tracking simultaneously.
OEM Portal Compromise
Ford DealerConnection, GM GlobalConnect, Toyota TMS, and Stellantis portals carry payment redirect authority — warranty reimbursements, holdback payments, volume incentives. Attacker takeover of dealer portal accounts = direct theft from OEM payment systems.

8 controls built for the
way a dealership actually operates

01
Written ISP with Qualified Individual
FTC Safeguards Rule 16 CFR 314.4(a) requires a written ISP and a designated Qualified Individual. Command tier's vCISO fulfills the QI role — ISP authorship, annual board report, and program oversight for a typical 50–150 endpoint single-rooftop dealer.
Most TX dealers don't have either. The FTC enforcement action template for auto dealers cites failure to have a written ISP as the first enumerated violation. This is the compliance foundation — without it, every other control is a gap.
02
DMS Air-Gapped Backup + Recovery Testing
Off-site, immutable backups for DMS configurations and F&I database records. Quarterly restore testing with documented RTO matched to operational constraints. CDK proved that dealer-owned backup capability is the difference between a 3-week outage and a 48-hour recovery.
The CDK outage showed most dealers had no tested recovery path for their DMS-dependent workflows. If your backup isn't tested, it's not a backup — it's a hope.
03
FTC Safeguards Rule Compliance Audit
Gap assessment against all 8 operational requirements: written ISP, QI, annual board report, MFA, encryption, IR plan, vendor oversight, and penetration testing. Delivered with remediation roadmap prioritized by risk and compliance exposure.
FTC enforcement actions against auto dealers specifically cite: no written ISP, no QI designation, and no monitoring of service provider access. A documented gap assessment with a remediation plan is your best evidence of good-faith compliance effort.
04
Third-Party Vendor Risk Program
CDK, Reynolds, Dealertrack, and Dominion vendor oversight documentation — required under FTC Safeguards Rule. DMS vendor security assessment, contractual security requirements, and incident notification procedures for each DMS vendor in the dealer's stack.
FTC's Safeguards Rule explicitly requires monitoring of service providers with access to customer data. CDK's failure to detect the intrusion for weeks is the vendor risk program failure that cascades to every connected dealer. Your Safeguards documentation needs to show you were monitoring CDK's access.
05
30-Day FTC Breach Notification Drill
Annual tabletop exercise simulating a DMS breach notification workflow — FTC notification (30-day clock from discovery), TX AG notification (250+ residents), customer notification letters, and incident documentation. Pre-built notification letter templates ready to deploy within the FTC's required timeframe.
The 700Credit and Motility/Reynolds breaches hit dealers who had to manage breach notification for incidents they didn't cause but are legally responsible for. A practiced workflow means you're not trying to figure out the FTC's required notification format while the 30-day clock is running.
06
BEC / Wire Fraud Controls — Floor Plan
Multi-factor authentication on controller and dealer principal email, dual-authorization workflow for floor plan curtailment wires, OEM portal credential monitoring, and BEC pattern detection on financial communication channels. FBI IC3 automotive sector losses up 34% — this is the fastest-moving threat vector for dealer groups.
A single floor plan BEC event can exceed $500K. FBI IC3 2024 data shows automotive sector is disproportionately targeted. Most dealer groups have no BEC controls beyond basic spam filtering — the OEM portal accounts and floor plan email threads are wide open.
07
DMS-Specific Incident Response Plan
Pre-built IR playbooks for: DMS ransomware and offline isolation, F&I data breach with FTC notification workflow, BEC on floor plan or OEM rebate payment flows, OEM portal credential compromise, and CDK/Motility-style vendor breach notification management. Pre-authorized containment authority with 30-minute SLA.
Standard IR plans don't account for the DMS dependency that makes dealer incidents unique. Your IR plan needs to address: what do your staff do when the DMS is offline, who authorizes manual deal logging, and how do you maintain FTC Safeguards compliance during the workaround period.
08
TX TDPSA + FTC Safeguards Compliance Mapping
Dual compliance mapping for the two frameworks that converge on TX auto dealers: TX Bus & Com §521 breach notification (250+ TX residents, AG notification, $250K max penalty) and FTC Safeguards Rule (QI, ISP, vendor oversight, 30-day FTC notification for 500+ customers). CoreRecon maps both simultaneously to avoid duplicating effort.
The dealer holds obligations under both frameworks for the same incident — a DMS breach triggering TDPSA notification to TX residents and FTC notification to customers simultaneously. Separate compliance tracks create duplicated effort; unified mapping covers both in one engagement.

Your path to
Safeguards compliance

Week 1
DMS Vendor Risk Assessment
Document every DMS and F&I software integration. Map data flows: where does SSN, credit application, and financing data live? Who has access? What does your DMS vendor's contract say about breach notification? This is your FTC Safeguards vendor oversight foundation.
Week 2
Written ISP Authorship — Foundation
Engage a QI (inside or outside) to begin ISP authorship. Map your top 3 risks: DMS vendor dependency, F&I data concentration, and floor plan wire exposure. Begin MFA deployment on DMS accounts and email.
Month 1
IR Plan + Breach Notification Workflow
Draft IR plan with DMS-specific playbooks. Pre-build FTC breach notification letter (30-day clock starts at discovery, not breach). Pre-identify your TX AG notification contact. Run a tabletop exercise with your controller and dealer principal.
Month 2
Pen Testing + Vendor Contracts
Commission penetration test covering your DMS-connected network segment and F&I data environment. Update vendor contracts (CDK, Reynolds, F&I tool vendors) to include security requirements and breach notification clauses per Safeguards Rule §314.4(9).
Month 3
Annual Board Report + QI Designation
Deliver written ISP to ownership. Designate Qualified Individual. Complete annual board report documenting program status, risk assessment findings, and remediation progress. This satisfies FTC Safeguards Rule §314.4(c)(3) annual reporting requirement.

What an incident
actually costs

$25M
CDK Global ransom (Jun 2024)
CDK reportedly paid to BlackSuit ransomware operators. Plus: $1B+ industry dealer losses in 14 days, SEC disclosure costs for publicly-traded dealer groups, and weeks of operational disruption across 15,000 dealers.
Source: Wall Street Journal, Reuters
$500K+
Per-dealer CDK outage losses (2–3 week scenario)
NADA estimates: average dealer lost $1M+ in revenue during CDK outage. High-volume stores with strong service departments likely exceeded $2M in deferred revenue. Manual workarounds added compliance and BEC risk on top of operational loss.
Source: NADA, industry estimates
$7,500
TX TDPSA per violation (TX AG enforcement)
TDPSA civil penalties up to $7,500/violation for failure to implement reasonable security or timely breach notification. A DMS breach exposing 5,000 TX customer records could generate $37.5M in maximum TDPSA exposure — even before FTC Safeguards enforcement.
Source: TX Bus & Com §521
$100K+
FTC Safeguards enforcement action against dealers
FTC has pursued enforcement actions against auto dealers specifically for Safeguards violations — citing: no written ISP, no QI, no monitoring of service provider access. Settlement amounts have exceeded $100K for smaller dealers. Multi-rooftop groups face proportionally higher exposure.
Source: FTC enforcement actions 2023–2025

Built for TX auto dealers.
30-min SLA. SDVOSB.

30-Minute SLA
Industry average identification time: 241 days (IBM CODB 2025). CoreRecon's 30-minute SLA for critical incidents means a CDK-scale event on your network is measured in minutes of response time, not months of dwell time.
🏆
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business. Qualifies for set-aside contracts and federal contracting preference programs. Many TX dealer groups with veteran ownership or government vehicle contracts have SDVOSB procurement requirements.
🚗
CDK + DMS Stack Expertise
TX-based team with documented expertise in CDK, Reynolds & Reynolds, and Dealertrack environments. CDK-specific threat hunts during onboarding. We understand the integration points that CDK proved are the real attack surface.
📋
FTC Safeguards QI Service
Command tier vCISO serves as your 16 CFR 314.4(a) Qualified Individual. Written ISP authorship, annual board report, vendor oversight documentation — the complete Safeguards compliance package for $2,500+/month.
💸
Floor Plan BEC Defense
BEC detection on floor plan curtailment wires and OEM rebate payment flows. FBI IC3 automotive sector losses up 34% — this is the fastest-moving threat. Fortress tier includes dual-authorization workflow for wire transfers.
🔗
Cross-Linked from /for-auto-dealers
This threat brief is cross-linked from the /for-automotive-dealers vertical page, /tools hub, /pricing, and resource briefs — inbound pipeline already established.

Three ways to
protect your dealership

🔍
Free Security Assessment
30-minute call with an automotive MSSP specialist. We review your DMS attack surface, FTC Safeguards compliance gaps, BEC vulnerability on floor plan flows, and deliver a dealer-specific remediation roadmap — at no cost.
Get Free Assessment →
📊
Breach Cost Calculator
Enter your endpoint count, revenue band, and DMS vendor profile. Get a CDK-scale or 700Credit-scale breach cost estimate for your operation. Most dealers are surprised by the insurance gap.
Calculate My Exposure →
📞
IR Hotline — On Call Now
Active incident? Suspected breach? Call (800) 955-2596. 24/7 SOC with automotive DMS incident response experience. CDK-scale events are what we train for — containment, forensics, and FTC notification support.
Call (800) 955-2596 →
Sources (40+): Reuters: CDK Global cyberattack coverage (Jun 2024) • Wall Street Journal: CDK $25M ransom payment (Jun 2024) • SEC 8-K filings: AutoNation, Group 1 Automotive (Houston HQ), Sonic Automotive CDK impact disclosures • NADA: CDK outage dealer impact estimates (Jun–Jul 2024) • Cox Automotive: Jun 2024 US vehicle sales data (-7.2% YoY) • FBI IC3 2025 Annual Report ($20.877B losses, automotive sector BEC +34%) • IBM Cost of Data Breach Report 2025 (241-day dwell time, $10.22M US avg) • ICO UK: Arnold Clark breach investigation (Dec 2022, 1M+ records) • FTC 16 CFR Part 314: Safeguards Rule requirements • FTC enforcement actions against auto dealers (2023–2025) • TX Bus & Com Code §521: TDPSA breach notification requirements • GLBA 15 USC 6801: Financial institution safeguards obligations • PCI SSC: PCI DSS v4.0.1 requirements • CFPB supervisory guidance on data governance (2024)