• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
CDK SECURITY RISKS

Guard Against CDK-Related Security Risks

June 20, 2024 Posted by Robbie Harriman disaster recovery, FTC, vCISO

By Nick Reed, Dave Cantor-Adams, Jeff Harms and Robbie Harriman.

Heightened Vigilance Advised

As you may be aware, CDK systems have recently been affected by a cyberattack. This is a “shields up” advisory to be on alert for any suspicious activity that may be related to the attack or activity deriving from attackers seeking to take advantage of the uncertainty. 

To contain the situation, CDK has shut down some of its systems starting on the morning of June 19, which is impacting service. CDK customers should have received a notice, and may note a disruption during this time. If you are a CDK client, your primary concerns will likely include the protection of customer information in compliance with FTC Safeguards, as well as the continuity of service. CDK has set up an automated message line for updates on the situation: 1(855) 356-3270. 

It is recommended that users refrain from using CDK systems until CDK confirms services have been restored and are safe to use. Attackers may exploit this situation to conduct a “supply chain” attack, further spreading the impact of access they have gained within CDK’s systems. They might also target auto dealers who are desperate to restore operations, tempting them to bypass security measures or overlook suspicious activities. 

Be vigilant for phishing attempts, as attackers may pose as “CDK support.” Watch for red flags in emails, such as unusual requests, a sense of urgency, threats, suspicious attachments, and links. Verify any unexpected communication through secondary channels, such as calling a known CDK number or directly contacting your service representative. 

Utilize system monitoring tools to detect any anomalies and take action accordingly. Ensure your environment is properly updated with the latest security patches to protect against the exploitation of vulnerabilities. 

As far as next steps, we recommend confirming the details of the incident with CDK to understand how it might affect you as further details are made available. If you haven’t already, contact your service representative at CDK and look for any official bulletins released by CDK via email (be sure to verify the identity of any sender).  We advise also monitoring incoming calls from anyone claiming to be a CDK representative, especially requests to share screens or other forms of remote network access. 

Don’t hesitate to reach out to OCD Tech for assistance with any security concerns you may have: [email protected] 

Tags: Autodealersdata breach
Share
0
Avatar photo

About Robbie Harriman

Robbie is the Senior IT Audit Manager at OCD Tech.  Robbie joined the firm in May of 2016. Prior to working at O’Connor & Drew, P.C., Robbie worked in IT for other companies, including the heavily regulated casino industry.  He currently travels locally and internationally working on some of OCD’s largest financial services companies.  He has a diverse range of experience in the IT field, with a deep background in IT systems administration and control areas.

You also might be interested in

OCDTECH.BLOG.CREDENTIALSCAN

Credential Scan

Jan 21, 2024

Opting for a credential scan is a proactive step toward[...]

Identity Management Day OCD Tech

Identity Management Day

Apr 11, 2023

Identity Management Day aims to inform about the dangers of[...]

RFID Cloning: How to Protect Your Business from Physical Infiltration

RFID Cloning: How to Protect Your Business from Physical Infiltration

Jun 26, 2018

If you can gain access to your office building, school,[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next