Findlay Automotive via CDK Global: Supply Chain
Findlay had just survived an alleged direct breach two weeks earlier when their software vendor was ransomed. Two attacks, two threat actors, same business: offline twice in one month. Read Case 03 →
CDK Global is a software-as-a-service platform that runs the sales, financing, parts, and service systems for roughly 15,000 dealerships across the United States and Canada, Findlay included. On June 18 and 19, 2024, CDK was hit by two waves of ransomware, widely reported to be the BlackSuit crew (an evolution of the Royal / Conti ransomware lineage). CDK took its systems offline to contain the attack and the entire dealer industry went dark with it.
For most of the next two weeks, Findlay's showrooms across the Las Vegas Valley operated on pen and paper. Salespeople wrote contracts by hand. Service writers tracked repair orders on legal pads. Parts looked up by phone and manufacturer book. Customers waited longer for everything.
According to Bloomberg, corroborated by blockchain analysis from TRM Labs, CDK paid approximately $25 million to BlackSuit to recover. Recovery of full functionality stretched into early July for many dealers.
Findlay's own systems were not the target in this incident. They were collateral damage through a shared vendor every dealership depends on. That is the supply-chain lesson: your security perimeter ends at the worst-defended company you rely on: your accounting platform, your payment processor, your scheduling app, your phone system. Pick one of those today and ask them: “what happens to us if you go offline for two weeks?”
Bloomberg, CyberScoop, TRM Labs blockchain analysis, CDK Global public statements, Reuters. BlackSuit attribution is based on widely reported industry analysis and blockchain tracing and has not been officially confirmed by CDK Global.
Same playbook, different victim.
MGM Resorts
A 10-minute phone call to the IT help desk shut down slot machines, hotel keys, and booking systems for more than 36 hours. ~$100M in operational losses.
Caesars
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars reportedly paid ~$15M of a ~$30M ransom demand to keep operations running.
Findlay Direct
Henderson-headquartered dealership chain breached directly. 30+ dealerships across 5 states. Customer + employee PII exposed. Class-action lawsuits in Clark County.
Want to know if your business survives this playbook?
Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.
Book a free consultation