BMW
X1 / X2
forum
BMW Garage BMW Meets Register Today's Posts
BIMMERPOST Universal Forums Off-Topic Discussions Board Car dealerships hit with cyber attack

Post Reply
 
Thread Tools Search this Thread
      06-20-2024, 01:16 PM   #1
cmyx6go
Colonel
cmyx6go's Avatar
16935
Rep
2,091
Posts

Drives: 2022 X6///M Comp
Join Date: Aug 2015
Location: NYC

iTrader: (2)

Garage List
2019 X6 ///M  [10.00]
Car dealerships hit with cyber attack

Car dealerships hit with second day of massive computer system outage.

A second cyber incident at data provider CDK Global, whose software is used at 15,000 auto dealers, continued to slow operations to a near-standstill Thursday at US and Canada dealerships, the company said in a message sent to dealers.

I read yesterday that this brought dealers to a standstill. They couldn't perform service, make appointments and of course couldn't process sales. I hope no one is scheduled to take delivery today.

https://www.yahoo.com/finance/news/c...200629129.html
__________________
I thought I was a good person but the way I react when people drive slowly in the left lane would suggest otherwise
Appreciate 4
vreihen1621619.50
Llarry22050.00
BMWGUYinCO4406.00
Buug95923979.00
      06-20-2024, 01:25 PM   #2
DriveModerately
Banned
No_Country
15
Rep
16
Posts

Drives: 16 F80 / 06 E90 N52
Join Date: Jun 2024
Location: NJ

iTrader: (0)

surely they will pass this cost off to the consumer
Appreciate 2
      06-20-2024, 01:36 PM   #3
dreamingat30fps
Colonel
United_States
5997
Rep
2,039
Posts

Drives: Miata, Cayenne, Model 3, F350
Join Date: Jan 2010
Location: South Florida & NC

iTrader: (1)

This might have been what happened when I picked up my truck yesterday from the Ford dealer. I had an issue with the pricing they were giving me and they claimed their system was down and they couldn't look anything up or change my invoice. Their credit card machine seemed to work just fine though.

They did end up charging me the correct amount, but were unable to change the invoice or anything like that.
Appreciate 4
vreihen1621619.50
cmyx6go16935.00
RickFLM411909.50
wrickem2196.00
      06-20-2024, 01:47 PM   #4
vreihen16
Recovering Perfectionist
vreihen16's Avatar
21620
Rep
1,023
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
Ask me why I'm not going to miss the IT field one bit when my forced retirement begins at the end of the month!

My DW keeps prodding me with IT job postings because I can't afford to retire yet, but I'd rather be a deck hand on a garbage scow than out-numbered 10,000 to 1 by threat actors and scammers coming at me from every direction.....
__________________
Currently BMW-less.
Appreciate 9
cmyx6go16935.00
JeffL01706.00
BMWGUYinCO4406.00
JJ 911SC27563.00
M_Six19524.50
SW111607.00
apptest4615.50
Buug95923979.00
      06-20-2024, 02:02 PM   #5
vreihen16
Recovering Perfectionist
vreihen16's Avatar
21620
Rep
1,023
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
Pizza. If the end user calls to complain, you just ship them another pizza. After 45 minutes, the pizza is digesting and does not require any more customer support.

As for the money part, just open a pizza business near JJ 911SC and you'll be set for life.....
__________________
Currently BMW-less.
Appreciate 9
cmyx6go16935.00
JeffL01706.00
Lady Jane84201.00
JJ 911SC27563.00
M_Six19524.50
BMWGUYinCO4406.00
Buug95923979.00
      06-20-2024, 02:36 PM   #6
CTinline-six
Hoonigan
CTinline-six's Avatar
United_States
6942
Rep
3,018
Posts

Drives: '09 328i, '98 Wrangler
Join Date: Dec 2016
Location: Connecticut

iTrader: (0)

Garage List
Yup, let's make everything streamlined and cheaper by using cloud systems... until something happens and then everything is F'ed at the same time.
__________________
"Yeah, but your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should."

-Dr. Ian Malcolm, Jurassic Park
Appreciate 2
      06-20-2024, 03:09 PM   #7
vreihen16
Recovering Perfectionist
vreihen16's Avatar
21620
Rep
1,023
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
Quote:
Originally Posted by CTinline-six View Post
Yup, let's make everything streamlined and cheaper by using cloud systems... until something happens and then everything is F'ed at the same time.
The onion layer defense model using separate clouds for everything does have a few upsides. The small city where I work just suffered a ransomware attack last week, and their commodity cloud services like email didn't seem to be impacted.

Of course, they probably haven't seen the double-extortion plot twist yet, or the massive DDoS attack against surviving resources to put them further out of business just as they start recovering.....
__________________
Currently BMW-less.
Appreciate 1
      06-20-2024, 03:26 PM   #8
Silence*
Eh?
Silence*'s Avatar
273
Rep
94
Posts

Drives: 2015 435ix
Join Date: Aug 2022
Location: Alberta, Canada

iTrader: (0)

As someone who works in parts at a BMW dealership that uses CDK... I can confirm its pretty much a nightmare right now. Most of our systems are tied into CDK so I have no way of giving quotes with prices, making invoices or even seeing if we have a part in stock right now. We also don't have any kind of back up system to locally switch to so... yeah. Fun times. My vacation next week can't start soon enough lol.
Appreciate 3
cmyx6go16935.00
vreihen1621619.50
Buug95923979.00
      06-20-2024, 03:32 PM   #9
Lady Jane
Cailín gan eagla.
Lady Jane's Avatar
Canada
84201
Rep
1,055
Posts

Drives: 2024 X3 M40i and R1200RT bike.
Join Date: Mar 2020
Location: Atlantic Canada.

iTrader: (0)

Quote:
Originally Posted by vreihen16 View Post

As for the money part, just open a pizza business near JJ 911SC and you'll be set for life.....
Like a bordello next to a Viagra factory. And I'm not into the fruity wine. Yet...
Appreciate 4
JJ 911SC27563.00
vreihen1621619.50
BMWGUYinCO4406.00
Buug95923979.00
      06-20-2024, 07:08 PM   #10
M_Six
Free Thinker
M_Six's Avatar
United_States
19525
Rep
7,556
Posts

Drives: 2016 MB GLC300 4matic
Join Date: Jan 2009
Location: Foothills of Mt Level

iTrader: (0)

I get pissed off when I see these jackass hackers get busted and then they get some slap on the wrist sentence like 3-5 years. Start putting these maggots away for 20-30.
__________________
Mark
markj.pics

"Life is uncertain, eat bacon now."
-UncleWede
Appreciate 6
vreihen1621619.50
cmyx6go16935.00
eliphil2735.00
BMWGUYinCO4406.00
Buug95923979.00
      06-21-2024, 07:04 AM   #11
iminhell1
C2H5OH
iminhell1's Avatar
United_States
4108
Rep
2,150
Posts

Drives: 2010 SG 135i auto
Join Date: May 2015
Location: Darwin, MN

iTrader: (1)

Quote:
Originally Posted by Silence* View Post
As someone who works in parts at a BMW dealership that uses CDK... I can confirm its pretty much a nightmare right now. Most of our systems are tied into CDK so I have no way of giving quotes with prices, making invoices or even seeing if we have a part in stock right now. We also don't have any kind of back up system to locally switch to so... yeah. Fun times. My vacation next week can't start soon enough lol.
I do Agricultural parts, we use CDK for everything also. Ya, it sucks. Today won't be any better.
Appreciate 2
Silence*273.00
BMWGUYinCO4406.00
      06-21-2024, 12:27 PM   #12
XutvJet
Major General
XutvJet's Avatar
6065
Rep
5,609
Posts

Drives: 2011 Cayman Base, 2018 M2
Join Date: Mar 2016
Location: Kansas City

iTrader: (-1)

This is the danger of putting all your eggs in one basket (software company). Russia, China, or Iran are likely behind this given the extent.

My son is going to school for cyber security/computer science. He looks forward to playing cat and mouse with these hackers.
__________________
The forest was shrinking, but the Trees kept voting for the Axe, for the Axe was clever and convinced the Trees that because his handle was made of wood, he was one of them.
Appreciate 3
cmyx6go16935.00
vreihen1621619.50
BMWGUYinCO4406.00
      06-21-2024, 12:34 PM   #13
eliphil
Captain
eliphil's Avatar
2735
Rep
842
Posts

Drives: M550I
Join Date: Dec 2021
Location: East Coast

iTrader: (0)

Quote:
Originally Posted by M_Six View Post
I get pissed off when I see these jackass hackers get busted and then they get some slap on the wrist sentence like 3-5 years. Start putting these maggots away for 20-30.
This is a fundamental problem in our country that has to change
Appreciate 1
BMWGUYinCO4406.00
      06-21-2024, 01:49 PM   #14
vreihen16
Recovering Perfectionist
vreihen16's Avatar
21620
Rep
1,023
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
I read in another forum that Audi advised all of their impacted dealerships to go out and buy manual-punch time clocks for their mechanics to track warranty labor hours, because they are not expecting a quick recovery.....
__________________
Currently BMW-less.
Appreciate 3
cmyx6go16935.00
BMWGUYinCO4406.00
Buug95923979.00
      06-21-2024, 03:02 PM   #15
zx10guy
Brigadier General
5551
Rep
3,349
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by M_Six View Post
I get pissed off when I see these jackass hackers get busted and then they get some slap on the wrist sentence like 3-5 years. Start putting these maggots away for 20-30.
Quote:
Originally Posted by eliphil View Post
This is a fundamental problem in our country that has to change
I get more pissed off that people responsible for implementing security are not punished at all despite gross negligence. To me there needs to be financial penalties and possible jail time for those that shirk their professional responsibilities. Two situations come to mind are the OPM and Equifax breaches. Both of these were entirely preventable as both had notice of a specific vulnerability that required patching which they ignored to address.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 2
eliphil2735.00
M_Six19524.50
      06-21-2024, 03:50 PM   #16
BMWGUYinCO
Second Lieutenant
BMWGUYinCO's Avatar
4406
Rep
284
Posts

Drives: 22 M850 Convertible '23 X3 M40
Join Date: Apr 2020
Location: Colorado

iTrader: (0)

I work in IT and within Healthcare.

Our genius CIO decided 2 years ago to move our critical, non-cloud native EHR system to the Azure cloud...but cheaped out on paying for cloud redundancy (Azure globally redundant storage, or "RA-GZRS" and a recovery environment in another availability zone). "The cloud doesn't ever fail" he told me. We went into Azure....for anyone in the business, you know that cloud is actually staged within geographic regions called an availability zone in order to reduce latency over distance.

And guess what? Our Azure availability zone experienced a 12 hour failure about 8 months ago. Did I tell you I work in critical healthcare?

Of course, everyone rushed me and asked how this could possibly happen...I explained the scenario and produced the emails and documentation I had, that showed I had expressed my opinion that we should absolutely pay for RA-GZRS as well as stage a recovery environment in another availability zone but that didn't matter one bit - I was back-whipped until my team could work with Microsoft to restore services.

But that CIO received a massive bonus payout last year for reducing costs. There is little hope for Corporate America and especially in IT, as the prevailing theory is that we "can do more with less".

Last edited by BMWGUYinCO; 06-21-2024 at 03:58 PM..
Appreciate 5
eliphil2735.00
vreihen1621619.50
Buug95923979.00
M_Six19524.50
      06-21-2024, 05:22 PM   #17
zx10guy
Brigadier General
5551
Rep
3,349
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by BMWGUYinCO View Post
I work in IT and within Healthcare.

Our genius CIO decided 2 years ago to move our critical, non-cloud native EHR system to the Azure cloud...but cheaped out on paying for cloud redundancy (Azure globally redundant storage, or "RA-GZRS" and a recovery environment in another availability zone). "The cloud doesn't ever fail" he told me. We went into Azure....for anyone in the business, you know that cloud is actually staged within geographic regions called an availability zone in order to reduce latency over distance.

And guess what? Our Azure availability zone experienced a 12 hour failure about 8 months ago. Did I tell you I work in critical healthcare?

Of course, everyone rushed me and asked how this could possibly happen...I explained the scenario and produced the emails and documentation I had, that showed I had expressed my opinion that we should absolutely pay for RA-GZRS as well as stage a recovery environment in another availability zone but that didn't matter one bit - I was back-whipped until my team could work with Microsoft to restore services.

But that CIO received a massive bonus payout last year for reducing costs. There is little hope for Corporate America and especially in IT, as the prevailing theory is that we "can do more with less".
I would expand on the "can do more with less" with if we don't see an actual dollar figure on ROI, then it's not worth spending the money. This applies to what you brought up with redundancy and resiliency along with security and backups. This goes back to what I said concerning the people in charge of overseeing critical systems particularly in the realm of security. With my examples in my initial post here, you have people's PII being dumped into the dark web that we have to deal with the ramifications not the ass in charge that made our data vulnerable which we didn't volunteer for them to hold in the first place. And in the case of OPM, the same thing. People that applied for, have, or held high level security clearances now have their deep personal histories held by the CCP. Again, the ass in charge didn't get punished in any way. A contractor was used as a scapegoat in typical government fashion.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 1
vreihen1621619.50
      06-22-2024, 09:05 PM   #18
vreihen16
Recovering Perfectionist
vreihen16's Avatar
21620
Rep
1,023
Posts

Drives: BMW-less :(
Join Date: Jun 2019
Location: Orange County, NY

iTrader: (0)

Garage List
https://www.usatoday.com/story/money...t/74175607007/

A group that says they hacked software company CDK Global is demanding tens of millions of dollars in ransom, Bloomberg reported.

Quote:
CDK, which provides software to car dealerships in North America, intends to pay the ransom but discussions are subject to change, according to Bloomberg's report which cited a person familiar with the situation.

The source said the group behind the hack is believed to be based in eastern Europe, Bloomberg reported.
__________________
Currently BMW-less.
Appreciate 0
      06-23-2024, 12:07 PM   #19
anthon.a
Enlisted Member
11
Rep
45
Posts

Drives: Soon...2024 I4 50M
Join Date: Jun 2013
Location: Montreal, Canada

iTrader: (0)

they are supposed to Deliver my i4-M50 on Thursday, I wonder if it will get pushed back.

Big companies are big targets, we sometime meets SMB customers dealing with BIG outsourced ERP and we are dumbfounded when we see all the missing security... "what no MFA" no "conditional access" , what you can login from anywhere???
__________________
Current: 2024 i4-50M + 2022 Audi E-Tron GT
Past: BMW: 2020 M340, 2017 340M XDrive, 2013 335xi, 2011 328xi, 2004 325xi. Audi/VW: 2023 ID4, 2018 S5 Sportback, 2013 A7, 2008 A3, 2009 VW EOS, 2001 A4, 1999 Jetta 1.8T. Other: 1992 Stealth R/T Turbo, 1995 Probe Gt, 1991 Cavalier RS V6, 1988 K-Car Baby!
Appreciate 1
vreihen1621619.50
      06-23-2024, 03:15 PM   #20
OCRick82
New Member
OCRick82's Avatar
United_States
26
Rep
24
Posts

Drives: 2016 750i G12 aka walletkilla
Join Date: Mar 2024
Location: Orange County Commiefornia

iTrader: (0)

Garage List
2016 BMW 750Li  [10.00]
I stopped by to visit a buddy at the BMW dealer by my house yesterday and they were either still down or experienced a new attack.

Crippled,some customers were ticked but what can you do?
Appreciate 1
vreihen1621619.50
      06-23-2024, 10:24 PM   #21
Our03z4
Captain
1769
Rep
694
Posts

Drives: 2008 BMW Z4 3.0si Coupe,
Join Date: Nov 2016
Location: USA

iTrader: (0)

My BIL works for CDK and they've had him not working since the attack. Still has to be on call but has nothing to do as he can't access anything.
Appreciate 1
vreihen1621619.50
Post Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 06:30 AM.




u11
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST