Supply chain
[SC] Supply Chain
AutoNation Third-Party Breach (July 2024)
Primary Source ↗Incident Details
Car dealership company AutoNation says CDK ransomware incident cut into quarterly earnings. AutoNation alerted investors that earnings per share would be down about a one-third from projections for the second quarter of 2024, due to the effects of a cyberattack on software provider CDK Global. One of the largest car dealership companies in the U.S. said its profits took a hit last quarter due to outages caused by a recent ransomware attack on a major software provider. AutoNation warned investors on Monday that its quarterly earnings report — pegged for release on July 31 — will show a negative impact from the incident of about $1.50 per share, or about one-third less than forecast. The company is now projecting earnings in the $3 range for the quarter ending June 30, according to financial news services. Third-party company: CDK Global.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- CDK Global
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-07-01 Breach occurred
- 2024-07-15 Publicly disclosed