CDK Cybersecurity Attack: Business Implications and Regulatory Compliance
On June 19, 2024, CDK Global reported it experienced a “cyber incident” that caused it to shut down all systems.
On June 24, it was reported that the cybercrime group Blacksuit, a group of Russian and Eastern European hackers, has demanded an extortion fee in the tens of millions of dollars from CDK, which plans to make the payment.
To date, CDK has not advised whether there has been any unauthorized acquisition of unencrypted customer information. CDK has advised dealerships that restoration of its systems will occur over the next several days and not weeks for its major applications. CDK also provided a link to resources and forms for dealer use available at: Dealer Resource Center (cdkglobal.com).
Business Interruption Insurance
Dealers whose operations are impacted by the CDK systems being down might consider exploring whether they have business interruption coverage under any of their insurance policies that could provide relief for expenses and losses arising from the interruption in business resulting from the outage. Each insurance policy is different and historically business interruption coverage was associated with physical casualties (e.g., fire damage), but in recent years some cyber insurance policies have included business interruption coverage. Dealers who have a cyber insurance policy should contact their carrier immediately and potentially file a claim.
Continuing Vehicle Sale Transactions
There are a variety of potential solutions for the issues that can arise when attempting to continue to conduct business while the CDK systems are shut down. In addition to the forms available through
CDK’s Dealer Resource Center, the Pennsylvania Automotive Association (PAA) created the links below, which were sent via email blasts to dealers, to help provide some guidance to continue vehicle sales
transactions while CDK is down.
New Vehicle Sale Transactions:
https://apps.paa.org/files/cdk/
NewVehicleSalesPacketCDKIncident.pdf
Used Vehicle Sale Transactions
https://apps.paa.org/files/cdk/
UsedVehicleSalesPacketCDKIncident.pdf
SPOA-LPOA Completion
https://apps.paa.org/files/cdk/
SPOALPOACDKIncident.pdf
CVR DLDV Memo From PennDOT
Due to CDK Global’s / CVR cyber event, PennDOT will allow Pennsylvania CVR clients only to use the pre-DLDV process and registration transactions manually. The pre-DLDV process includes the requirements that
during the completion of motor vehicle applications, agents examine and analyze the identification credential for purposes of validation. While the CVR DLDV system is down and verifications cannot be run, dealerships using CVR should complete the paperwork, and hold it until the system comes back up.
Once the system is operational, run the DLDV verification and complete the transaction through the Online Registration Program’s online process. If the customer’s DLDV verification fails when the system is operational, the Pennsylvania CVR client must immediately scan and send the paperwork to the DLDV Helpdesk for further assistance at [[email protected]][email protected].
Lien Verification through PAA
CVR customers can perform lien verifications through PAA. The form is available online at: https://apps.paa.org/Files/Title/LienVerification.pdf and the member cost is $17.50. After the dealership receives lien verification, the vehicle may be sold without the title present; however, the dealership must still provide paperwork to PennDOT within 20 days of the sale.
InTransit Tags
PennDOT Form MV-120, “Temporary Registration Plate or Temporary Registration Transfer Card”can be used for InTransit Tags, in conjunction with required paperwork and will be required to be uploaded once the CVR system is restored.
Dealers have questioned what case number/authorization number to write at the top as this information is provided by CVR. While CVR systems are down, CVR dealers must contact [email protected] to get an authorization number.
The titlework must be held and uploaded once the system is restored and must include the following:
• Title, MCO or SPOA
• Insurance
• Photo ID, copy of the front and back of the out
of state license.
• No DLDV/driver verification required for out of state customers.
• Limited or SPOA, if utilized.
Process online once the CVR system is functioning.
FTC Safeguards Rule
Dealers have questioned their obligations under the FTC Safeguards Rule as it relates to the CDK attack. It is required to notify the FTC as soon as possible, and no later than 30 days after discovery,
of a security breach involving the unencrypted information of at least 500 consumers. Until CDK provides additional information regarding which systems were compromised and whose customer data was possibly exposed, PAA is not recommending dealers report the information on the FTC’s website. Any report you make could be made public. PAA will provide additional information on this as it becomes available over the next several days.
Dealers should, however, review their compliance with the FTC Safeguards Rule, which is set forth in NADA’s Driven Guide on the topic available at https://apps.paa.org/files/2022SafeguardsRule.pdf.
Dealers should pay particular attention to the following requirements contained in the amended Safeguards Rule:
• The numerous technological requirements including the need to encrypt all customer information held or transmitted by the dealer when in transit over external networks and when at rest;
• The establishment of a written incident response plan that is designed to help a dealer promptly respond to, and recover from, any security event materially affecting the confidentiality,integrity, or availability of customer information in the dealership’s control; and
• The abovementioned need to report “notification events” involving at least 500 consumers to the FTC when there has been an “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.”
• If applicable, reporting must take place if the incident occurred in dealer controlled systems, including those maintained by vendors.
• The notification requirement requires reporting to the FTC only, not to customers.
• This is separate from customer notification, or other requirements imposed under state data breach notification laws.
Recommended Cybersecurity Measures
Dealers are responsible for their data even when it is processed elsewhere and/or by a service provider. Dealerships are the state and federal regulated entity under relevant federal and state law, and dealers need to take action to ensure that they are meeting their obligations.
In the event of a cybersecurity incident that could impact dealer data, dealers should:
1. Request a detailed incident report from the vendor. While the dealer may not be able to obtain a detailed incident report right away, it is important that the dealership request this information, and that they do so as soon as practical.
2. Seek to determine what dealership data may have been compromised.
3. Evaluate potential risks to customers, employees, and business operations. Additional critical steps all dealers should take to protect against potential threats posed by cyber-attacks include the following:
1. Endpoint Detection and Response (EDR): EDR solutions act like a security camera to provide real-time monitoring, detection, and response capabilities to identify and mitigate potential security breaches on your dealership’s devices and networks.
2. Penetration Testing: Regularly conducting penetration testing allows you to proactively identify vulnerabilities in your systems and networks before they can be exploited by bad actors. This practice helps strengthen your overall cybersecurity posture.
3. Phishing Simulations: Phishing attacks remain one of the most common methods used by cybercriminals to gain unauthorized access to sensitive data. Conducting phishing simulations trains your employees to recognize and report suspicious emails, reducing the risk of successful phishing attempts.
4. Multi-Factor Authentication (MFA): Implementing MFA adds an extra layer of security to your dealership’s user accounts. By requiring users to provide additional verification factors, such as a smartphone app or hardware token, MFA significantly reduces the risk of unauthorized access, even if passwords are compromised.
5. Vulnerability Scanning: Regular vulnerability scanning helps identify potential weaknesses in your dealership’s systems, applications, and networks. By proactively detecting vulnerabilities, you can prioritize and address them before they can be exploited by malicious actors.
6. Service Provider Oversight: The Safeguards Rule requires you to take certain specific actions with respect to your service providers’ contracts and cybersecurity tools to ensure that all your systems are enacting appropriate tools to protect your data.
PAA has partnered with ComplyAuto, who offers a comprehensive suite of cybersecurity tools that specifically address these steps. For more information about their services, pricing, or their industry-leading Compliance Guarantee, go to https://complyauto.com or email [email protected].