CDK Global (2024)
On June 18, 2024, CDK Global — the dealer-management-system provider for ~15,000 North American auto dealerships — was attacked by BlackSuit ransomware. A second attack on June 19 disrupted recovery efforts. Most dealerships reverted to paper processes for two weeks. Anderson Economic Group estimated total dealer losses at $1.02B; CDK reportedly paid ~$25M in ransom. The incident is a benchmark for indirect cascade damage from sector-concentrated SaaS compromise.
Details
June 18-19, 2024
BlackSuit ransomware
none documented
Not publicly disclosed
~$25M in bitcoin (per multiple reports)
~$1.02B in dealer losses (Anderson Economic Group); CDK direct costs separate
~15,000 North American auto dealerships disrupted for ~2 weeks; 7.2% decline in June US new-vehicle sales