TSLA381.6308.83%
GM76.8900.27%
F12.080-0.16%
RIVN16.4000.34%
CYD41.2101.13%
HMC24.3400.34%
TM192.6201.36%
CVNA395.995-0.595%
PAG171.520-0.14%
LAD290.120-0.88%
AN212.3806.69%
GPI356.8707.66%
ABG203.6902.3%
SAH78.7505.44%
TSLA381.6308.83%
GM76.8900.27%
F12.080-0.16%
RIVN16.4000.34%
CYD41.2101.13%
HMC24.3400.34%
TM192.6201.36%
CVNA395.995-0.595%
PAG171.520-0.14%
LAD290.120-0.88%
AN212.3806.69%
GPI356.8707.66%
ABG203.6902.3%
SAH78.7505.44%
TSLA381.6308.83%
GM76.8900.27%
F12.080-0.16%
RIVN16.4000.34%
CYD41.2101.13%
HMC24.3400.34%
TM192.6201.36%
CVNA395.995-0.595%
PAG171.520-0.14%
LAD290.120-0.88%
AN212.3806.69%
GPI356.8707.66%
ABG203.6902.3%
SAH78.7505.44%

Ransomware attacks are on the rise — is your auto dealership secure?

The invasion of Ukraine by neighboring Russia could trickle into the US in a different kind of warfare: cyberattacks. An initiative called “Shields Up” has been enacted to defend against cyberattacks on critical infrastructure as intelligence believes Russia could begin targeting the US for assisting in Ukraine and speaking against the Kremlin. 

While Shields Up is focused on protecting systems of national security and interest, the threat of Russian hackers – or any hackers of that matter – can illuminate risk closer to home. A recent survey of 1,200 small and medium-sized businesses (SMBs) conducted by CyberCatch revealed that only one in four could survive a ransomware attack for longer than seven days. Barely more than half could make it more than three days.

The demographic did not specifically identify dealerships, although they would fit within sectors like retail or transportation, both with similar response rates. Less than half of the companies surveyed in those areas test for phishing among employees. Less than two-thirds of SMBs in these sectors have a written Incident Response Plan for ransomware attacks. 

Sai Huda is the founder, chairman, and CEO of CyberCatch. He said, “Ransomware is an existential threat to SMBs who are a critical part of the supply chain. Foreign adversaries and criminal gangs will increasingly attack SMBs with ransomware to not only extort ransom payments but also use as the entry point upstream to the eventual target, a large company, critical infrastructure, government agency, healthcare organization or other high value target. The SMBRS is a wake-up call for proper cybersecurity controls.”

Dealerships are being targeted

The CDK Global 2018 Dealership Cybersecurity Study found that 85% of IT staff say their dealership had experienced a cybersecurity incident within the previous two years. In 2021, the CDK Global 2021 State of Cybersecurity in the Dealership Report reflected that the average ransomware payout had increased seventeen-fold in two years, up to $220,298 per incident. That’s an average, though, and the individual demand could range into the millions.

Dealerships have tightened their defenses since the 2018 report, but there continue to be areas that can be improved. 

Shift of mindset

The 2021 State of Cybersecurity in the Dealership Report also identifies a 16-day downtime due to ransomware attacks, essentially grinding a dealership’s operations to a halt for a half-month. It’s no wonder that most SMBs can only last from three to seven days with their financial revenues shut off or scrambling to implement a stopgap. 

It’s crucial to have the infrastructure in place to combat the effects of a cyberattack, including offline backups and monitoring software that help employees identify when an email or website isn’t secure. But there’s more to dealership cybersecurity. 

An overarching thought is that dealers are in the car business, but that’s hardly the case anymore. They’re now in the customer service business primarily, and an increasing part of the business is software-related as cars become more connected. The CDK Global report says that “84% of consumers said they would not go back to buy another vehicle after their data had been compromised”. If dealerships are targeted, there’s a high likelihood that many customers will never return. 

Cyberattacks are increasing in frequency in the US, and they’re coming from new sources all the time. Protecting your dealership from the disruption and potentially costly payout or a ransomware attack could keep you in business while other less protected companies are put out of business.


dealersDid you enjoy this article from Chanell Turner? Please share your thoughts, comments, or questions regarding this topic by submitting a letter to the editor here, or connect with us at newsroom@cbtnews.com.

Be sure to follow us on Facebook, LinkedIn, and TikTok to stay up to date.

While you’re here, don’t forget to subscribe to our email newsletter for all the latest auto industry news from CBT News.

More from Management & Leadership
Walser Automotive Group

How Walser Automotive Group is building a people-first culture through inclusion, engagement

- April 28, 2026
Dayna Kleve, Director of Diversity, Engagement, and Foundation at Walser Automotive Group, is helping embed inclusion into the company’s culture to drive stronger employee engagement, retention, and customer experience. Kleve...
leadership standards, Dave Anderson

Why leadership standards must exceed employee expectations

- March 4, 2026
Accountability collapses the moment leaders believe it applies to everyone but themselves. On today's episode of Lessons in Leadership, leadership expert and LearnToLead Founder Dave Anderson explains why leaders must...
Brooke Guy

Brooke Guy’s turnaround strategy for scaling dealership growth

- February 17, 2026
Winning requires discipline, clarity, and the willingness to outwork yesterday’s version of yourself. On today's episode of Training Camp, Coastal Chevrolet Cadillac Nissan General Manager Brooke Guy shares how she...
Dave Anderson explains why meritocracy and earn-and-deserve cultures reward performance, prevent entitlement, and strengthen accountability.

Why earn-and-deserve cultures keeps top performers engaged — Dave Anderson

- February 11, 2026
The most successful businesses with high-performance cultures reward and promote employees based on results, not urgency. On today's episode of Lessons in Leadership, leadership expert and LearnToLead Founder Dave Anderson...
CBT News
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.