Just as dealers were preparing for a busy tax season of shoppers, a record number of cyberattacks on dealerships were attempted in March.

A study by Proton Dealership IT and Cybersecurity found nearly a 1,000% spike in March compared to activity before June 2024, along with an increase in attempted attacks on the auto industry.

Driving the news: Cybercriminals target auto dealers for consumer data and with scams designed to collect money.

With this in mind, the FTC updated its Safeguards Rule in 2021 and 2023, requiring (in part) that dealers implement and maintain security programs to keep customers’ information secure, or risk heavy fines for incidents.

Fast forward: Starting in March, Proton noticed an increase in attempted attacks via software that would allow third-party vendors access to troubleshoot software.

  • Proton explained that other industries were impacted a year earlier by the vulnerability.

  • And Sean Syeda, Chief Information Security Officer for Proton Dealership IT, who has more than 25 years in technology and information security, even told CDG News they were able to block the attempts with protections put in place ahead of time.

“Basically, a third-party software was compromised that a lot of businesses use, and we just happened to detect it… We actually found it before the attack started,” Syeda said.

Picking back up: Activity dropped after March but picked back up in June and is more than triple activity from two years ago.

  • In short, attackers are relying on old tricks to gain access, sending malicious emails and phishing scams, both of which AI has made more convincing, to fool unsuspecting users.

  • Syeda points out that AI has eliminated some of the previous tells on phishing emails and helped criminals scrape additional information to write more convincing texts to fool recipients.

“Now, it’s not like you’re going to look at bad grammar in an email and find, ‘oh, clearly some Nigerian prince doesn’t want to give me money anymore.’ They’re not doing those kinds of phishing emails. They’re now, ‘I can target you a lot more efficiently. I can actually scrape open-source data about you and your business and actually phish you more directly because I know you’re a salesperson at a dealership.’”

Sean Syeda
Proton Dealership IT
Chief Information Security Officer

MFA is not a deterrent: Proton found that 97% of the time, multi-factor authentication was being used when credentials were compromised.

  • Syeda also explained that text MFA is better than email MFA, and urged clients to use phishing-resistant MFA, which uses biometrics or physical interaction. 

“A lot of these scams now will basically try to capture you putting in your MFA code,” Syeda said. “...You’re basically giving them, the bad guys, the keys after you put your MFA code in. And they’re just pretending and impersonating you from that point forward.”

OUTSMART THE CAR MARKET IN 5 MINUTES A WEEK

Get insights trusted by 55,000+ car dealers. Free, fast, and built for automotive leaders.

Increasing costs: The number of attempts by cybercriminals has not only increased, but so has the cost of recovery from an attack. 

  • The average cost of recovering from a ransomware attack is now $1.7 million, an increase of $200,000 in the past year. 

  • That total does not include any ransom paid to restore accounts.

  • Syeda said those increasing costs are due to rising insurance premiums, labor costs, hardware, software, and firewalls. 

“All those costs have gone up, and I expect them to go up again next year,” he said. 

Bottom line: Dealers must follow the FTC Safeguards Rule and have a plan in place, including appointing a point person.

“You need to have your protections in place, and you need to be working on implementing the controls that your security tools give you, because a lot of businesses won't go to that extra effort,” Syeda said. “They buy the tool and think they're protected. And it's not that simple. You need your expertise and knowledge. So whether that's your internal teams or your third party to help you do that. Training your associates is a key piece because they’ve got to spot those new phishing emails.” 

A quick word from our partner

A script can't tell when a shopper's about to walk.

Other AI fires the same canned reply at every shopper. Impel Sales AI reads sentiment, tone, and intent, then adjusts in real time, the way your best salesperson would.

It knows when to push, when to ease off, and when to book. Every conversation sounds like your store, not a bot.

Dealers report a 33% lift in appointment set rates.