Cyberattacks on auto dealerships have skyrocketed, thanks to the volume punch of artificial intelligence.
Proton Dealership IT and Cybersecurity, a Reynolds and Reynolds affiliate that provides cybersecurity services for dealers, said malicious attacks on dealerships spiked this past March when bad actors compromised remote-access software used by some dealers’ third-party vendors.
The activity, juiced by AI, put attacks up almost 1,000% above the level seen before the summer of 2024, when a compromise of CDK’s dealership software systems left scores of dealerships without their digital operations backbones.
The CDK incident was followed by waves of similar attacks on auto brand franchises as cyber criminals took advantage of dealers’ exposure, Proton reported last year. That activity, instead of abating, has surged with the help of AI.
Not only can such attacks disrupt dealership operations. They’re also costly. Proton cited an estimate by Sophos that it costs an average of $1.7 million to recover from one, based on a survey of more than 2,000 IT and security leaders in 17 countries.
Proton expects the attacks to continue as AI is used to generate legitimate-seeming phishing emails, though security cracks in software are still potential targets. It said the former scams have become the main conduit for ransomware attackers due to the relative ease they present for gaining log-in credentials.
Though multifactor authentication has become a common defense against cyberattacks, it’s now proving insufficient to stop them, Proton said. The company found that the measure was in place in 97% of incidents when compromised credentials were used to access a system.
Confidence tricks, or social engineering in today’s cybersecurity parlance, are often used on employees to input malicious code into networks, Proton said. AI helps attackers make their scams harder to recognize.
“Gone are the days of misspellings in scam emails – today phishing scams leverage how legitimate they look against unsuspecting human recipients,” Proton said.
The company recommended dealerships employ the following measures to guard against cyberattackers:
- Monitor who logs into your systems using phishing prevention measures, not multifactor authentication alone.
- Regularly update device patches.
- Install and maintain quality email filtering for malware and phishing detection.
- Regularly train employees to guard against phishing and social engineering, including testing their knowledge.
- Put an attack response and recovery plan in place and practice it at least annually.
- Seek round-the-clock monitoring by an expert provider.