Supply chain β›“ Supply Chain

AutoNation Third-Party Breach (July 2024)

πŸ“… 2024-07-01 🏒 CDK Global
Primary Source β†—

Incident Details

Car dealership company AutoNation says CDK ransomware incident cut into quarterly earnings. AutoNation alerted investors that earnings per share would be down about a one-third from projections for the second quarter of 2024, due to the effects of a cyberattack on software provider CDK Global. One of the largest car dealership companies in the U.S. said its profits took a hit last quarter due to outages caused by a recent ransomware attack on a major software provider. AutoNation warned investors on Monday that its quarterly earnings report β€” pegged for release on July 31 β€” will show a negative impact from the incident of about $1.50 per share, or about one-third less than forecast. The company is now projecting earnings in the $3 range for the quarter ending June 30, according to financial news services. Third-party company: CDK Global.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
CDK Global
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-07-01 Breach occurred
  2. 2024-07-15 Publicly disclosed