April 26, 2025
6
min read
Nick Reed

Auto Dealer Latest Target of Ransomware

Editor
Nick Reed
Category
Cybersecurity
Date
April 26, 2025

On June 13, 2023, ransomware group 8Base exposed evidence of a significant data breach targeting a large Midwestern automotive group. The ransomware group claims to have executed a successful campaign that resulted in the theft of 350 gigabytes of data, including 8,000 lines of customer and employee social security numbers, as well as other sensitive data including financial statements, driver’s licenses, and addresses.

8Base has been active since April 2022 and has already victimized a total of 67 organizations. The victims tend to be in the Professional/Scientific/Technical sector and are small to midsized companies. Additional information about 8Base can be found on Malwarebytes’ June 2023 Ransomware review[1].

This breach occurred just after the FTC Safeguards June 9, 2023 deadline[2]. This deadline mandates nonbanking financial institutions (including auto dealers) to implement measures to safeguard customer information. Despite the passing of the deadline, the FTC has not yet made any public statements, so it is not yet clear whether enforcement action is on the horizon.

According to 8Base, the automotive group was notified about the attack and is being given the opportunity to cooperate and protect its sensitive data until June 18, 2023. If the ransom is paid, 8Base alleges that they will not expose the breached data. If the ransom is not paid soon, 8Base plans to publicly release the victim’s data. Below, the full message posted on 8Base's darkweb site provides more detailed information about the attack and their claims.

OCD TECH 8BASE

This incident serves as a reminder to the automotive industry that it is quickly becoming a prime target of ransomware groups because of the sensitive customer data that is maintained.  Implementing best practice cyber security measures to protect customer data, especially measures that are in line with the FTC Safeguards requirements, are a critical step in lowering the risk of a data breach.

[1] https://www.malwarebytes.com/blog/threat-intelligence/2023/06/ransomware-review-june-2023

[2] https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314

Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

OCD Tech

25 BHOP, Suite 407, Braintree MA, 02184

844-623-8324

https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
SOC 2 ® Readiness Assessment
SOC 2 ®
SOC 3 ®
SOC for Cybersecurity ®
IT Advisory Services
IT Vulnerability Assessment
Penetration Testing
Privileged Access Management
Social Engineering
WISP
General IT Controls Review
IT Government Compliance Services
CMMC
DFARS Compliance
FTC Safeguards vCISO

Industries

Financial Services
Government
Enterprise
Auto Dealerships

Auto Dealer Latest Target of Ransomware

By  
Nick Reed
June 17, 2023
6
min read
Share this post

On June 13, 2023, ransomware group 8Base exposed evidence of a significant data breach targeting a large Midwestern automotive group. The ransomware group claims to have executed a successful campaign that resulted in the theft of 350 gigabytes of data, including 8,000 lines of customer and employee social security numbers, as well as other sensitive data including financial statements, driver’s licenses, and addresses.

8Base has been active since April 2022 and has already victimized a total of 67 organizations. The victims tend to be in the Professional/Scientific/Technical sector and are small to midsized companies. Additional information about 8Base can be found on Malwarebytes’ June 2023 Ransomware review[1].

This breach occurred just after the FTC Safeguards June 9, 2023 deadline[2]. This deadline mandates nonbanking financial institutions (including auto dealers) to implement measures to safeguard customer information. Despite the passing of the deadline, the FTC has not yet made any public statements, so it is not yet clear whether enforcement action is on the horizon.

According to 8Base, the automotive group was notified about the attack and is being given the opportunity to cooperate and protect its sensitive data until June 18, 2023. If the ransom is paid, 8Base alleges that they will not expose the breached data. If the ransom is not paid soon, 8Base plans to publicly release the victim’s data. Below, the full message posted on 8Base's darkweb site provides more detailed information about the attack and their claims.

OCD TECH 8BASE

This incident serves as a reminder to the automotive industry that it is quickly becoming a prime target of ransomware groups because of the sensitive customer data that is maintained.  Implementing best practice cyber security measures to protect customer data, especially measures that are in line with the FTC Safeguards requirements, are a critical step in lowering the risk of a data breach.

[1] https://www.malwarebytes.com/blog/threat-intelligence/2023/06/ransomware-review-june-2023

[2] https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314

Share this post
Nick Reed