Phishing Campaigns Are Essential After the CDK Cyberattack
Key takeaways
- Finley experienced a cyberattack that began with a phishing scenario in which an employee opened a malicious email or file.
- Phishing is one of the biggest ways hackers gain access to a dealership's systems because doctored emails can look familiar and legitimate.
- Dealerships without a good phishing campaign are not compliant and are at risk of getting in trouble.
- Hackers have realized they can get into auto dealer systems in the United States, so further attacks are only a matter of time.
- ARMP has developed its own phishing campaign that can be adjusted and customized with a dealership's management team to reflect realistic, store-specific scenarios.
Summary
Phishing attacks remain one of the most common ways hackers break into dealership systems, and having an active phishing campaign in place is treated as a baseline compliance requirement, not an option. The video points to the recent CDK Global outage and the related attack on Fenley as a real-world example: a phishing email got opened, and that single click gave attackers a way into the store's systems. The point made is that these emails are designed to look familiar, with only small details altered, which is why ongoing testing and training matter more than a one-time policy.
For a dealership, this means reviewing whatever phishing training or simulated-email program is currently running and confirming it actually holds up, rather than assuming it's adequate. Terry Dortch notes that ARMP has built its own phishing campaign that can be customized and adjusted with a dealership's management team, using topics relevant to that specific store to make the tests more realistic. The message to dealers is direct: assess your current program now, because hackers have shown they can get into US auto dealer systems, and it is only a matter of time before more stores are targeted.
Transcript
Introduction to the CDK attack situation
Hi, my name is Terry Dortch. I'm with Automotive Risk Management Partners. I want to talk to you today in relationship to the events that happened over the course of the last few weeks with CDK. And really, what I want to talk to you about is that you, as dealers, need to have programs in place.
How the Finley phishing attack occurred
Finley, Finley got attacked from a phishing scenario, a phishing campaign that went into their store, and somebody obviously opened up something, and it opened their system up to whoever was hacking them. You need a phishing campaign. You need a company that provides you with that. Whether it's right now as a result of the CDK, it's going to continue. Phishing is probably one of the biggest ways that someone gets into your system, and it's because we look at it, an email or something like that, and it looks familiar, we open it up, and they've just doctored one or two things here or there to make it appear as though it's real.
Compliance risk of lacking a phishing campaign
Bottom line here is, if you don't have a good phishing campaign, you're not compliant, you're not going to stay out of trouble, you will get in trouble. It's going to happen. Now that the hackers have realized they can get into the systems here in the United States, into these auto dealers, it's only a matter of time.
ARMP's customizable phishing campaign offering
So my bottom, what I'm telling you is, we have a campaign, we've developed our own. We can change topics, we can adjust it, we can sit down with your management team and send things in that are pertinent just to your store, things that make it more realistic, things like that. So whatever you're doing right now, you need to assess it, make sure it's going to satisfy whatever you need to make sure you're covered, you're protected. If you're not, give us a call. Information's here on the screen. Thanks, take care.
Questions this video answers
Why do dealerships need a phishing campaign after the CDK attack?
Because CDK's attack started with a phishing scenario where someone opened a doctored email that let hackers into the system. Since hackers now know they can breach US auto dealer systems, phishing attacks will continue, making a phishing campaign necessary to stay protected and compliant.
What happens if a dealership does not have a phishing campaign in place?
If a dealership does not have a good phishing campaign, it is not compliant, will not stay out of trouble, and will eventually get in trouble since hackers have realized they can breach auto dealer systems in the United States.
What kind of phishing campaign does ARMP offer dealerships?
ARMP has developed its own phishing campaign that can be changed and adjusted, including sitting down with a dealership's management team to send realistic, store-specific content to make the campaign more effective and relevant.
Read more on this
-
Dealership Cybersecurity Requirements
A US auto dealership's cybersecurity requirements come primarily from the FTC Safeguards Rule, which mandates multi-factor authentication, encryption of custome...
Covered in this video
- Phishing campaigns
- CDK cyberattack
- Dealership cybersecurity compliance