Findlay Automotive Group: Direct Breach
Findlay Automotive Group, headquartered on West Sunset Road in Henderson, runs more than thirty dealerships across Nevada, Utah, Arizona, Washington, and Idaho. Around June 7, 2024, attackers gained access to Findlay's internal systems. The intrusion was discovered on or around June 10 and disclosed shortly after.
IT systems were disrupted across all dealership locations. Sales and service operations were severely restricted while Findlay's team worked to contain the incident and restore systems. The breach exposed employee and customer personally identifiable information: names, Social Security numbers, driver's license numbers, and financial information.
Multiple class-action lawsuits were subsequently filed in Clark County District Court, alleging that Findlay failed to implement adequate cybersecurity measures to protect customer data. Public reporting has attributed the breach to Scattered Spider, applying the same social-engineering playbook used against MGM nine months earlier, but no official law-enforcement confirmation has been published as of this writing.
The Findlay incident is the local story this page exists to tell. The same kind of phone call that ran the Strip dark in 2023 allegedly ran a Henderson dealership chain dark in 2024. The attack happened in our backyard.
Two weeks later, Findlay went offline again. This time without anyone touching their systems. A separate ransomware attack on their software vendor, CDK Global, knocked their dealerships offline along with roughly 15,000 others nationwide. Read Case 04 →
Las Vegas Review-Journal, News3LV, Clark County District Court filings, Findlay Automotive Group disclosures. Scattered Spider attribution is alleged and has not been officially confirmed by law enforcement as of this writing. Individuals named in court filings are presumed innocent until proven guilty.
Same playbook, different victim.
MGM Resorts
A 10-minute phone call to the IT help desk shut down slot machines, hotel keys, and booking systems for more than 36 hours. ~$100M in operational losses.
Caesars
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars reportedly paid ~$15M of a ~$30M ransom demand to keep operations running.
Findlay via CDK
Two weeks after the direct breach, Findlay's software vendor CDK Global was ransomed. ~15,000 dealers nationwide reverted to pen and paper for ~2 weeks.
Want to know if your business survives this playbook?
Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.
Book a free consultation