• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Auto Dealer Latest Target of Ransomware

June 17, 2023 Posted by Nick Reed Cybersecurity, IT Security, News

On June 13, 2023, ransomware group 8Base exposed evidence of a significant data breach targeting a large Midwestern automotive group. The ransomware group claims to have executed a successful campaign that resulted in the theft of 350 gigabytes of data, including 8,000 lines of customer and employee social security numbers, as well as other sensitive data including financial statements, driver’s licenses, and addresses.

8Base has been active since April 2022 and has already victimized a total of 67 organizations. The victims tend to be in the Professional/Scientific/Technical sector and are small to midsized companies. Additional information about 8Base can be found on Malwarebytes’ June 2023 Ransomware review[1].

This breach occurred just after the FTC Safeguards June 9, 2023 deadline[2]. This deadline mandates nonbanking financial institutions (including auto dealers) to implement measures to safeguard customer information. Despite the passing of the deadline, the FTC has not yet made any public statements, so it is not yet clear whether enforcement action is on the horizon.

According to 8Base, the automotive group was notified about the attack and is being given the opportunity to cooperate and protect its sensitive data until June 18, 2023. If the ransom is paid, 8Base alleges that they will not expose the breached data. If the ransom is not paid soon, 8Base plans to publicly release the victim’s data. Below, the full message posted on 8Base’s darkweb site provides more detailed information about the attack and their claims.

OCD TECH 8BASE

This incident serves as a reminder to the automotive industry that it is quickly becoming a prime target of ransomware groups because of the sensitive customer data that is maintained.  Implementing best practice cyber security measures to protect customer data, especially measures that are in line with the FTC Safeguards requirements, are a critical step in lowering the risk of a data breach.


[1] https://www.malwarebytes.com/blog/threat-intelligence/2023/06/ransomware-review-june-2023

[2] https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314

Tags: Autodealersdata breach
Share
0

About Nick Reed

Nick Reed is Security Analyst at OCD Tech. He has a Masters Degree in Cybersecurity: Policy & Governance from Boston College. Previously, he received his Bachelor's Degree in Criminal and Social Justice from Boston College.

You also might be interested in

Scraping Social Security Numbers on the Web

Scraping Social Security Numbers on the Web

Oct 1, 2018

One of the most accredited forms of validation for a citizen's identity is a Social Security Number.

Identity Management Day OCD Tech

Identity Management Day

Apr 11, 2023

Identity Management Day aims to inform about the dangers of[...]

Why SMBs Need Specialized Cybersecurity

Why SMBs Need Specialized Cybersecurity

Nov 25, 2024

In today’s digital landscape, small and medium-sized businesses (SMBs) face[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next