
Ransomware accounted for 44% of publicly reported cyber incidents across the automotive sector in 2025, according to security firm Halcyon — attacks on automotive organizations more than doubled that year, and 67% of incidents exploited telematics systems, cloud platforms, or APIs. For a dealer group, dealership ransomware exposure isn’t the showroom: it’s the DMS, the shared vendor platforms, and the customer data FTC Safeguards already makes you responsible for.
What the 2026 data actually says
In September 2026, ransomware research firm Halcyon published 44% and Rising, its analysis of ransomware across the automotive industry. Four numbers from that report are worth pinning to the wall in any dealer group’s IT meeting.
| What Halcyon measured (2025) | The finding |
|---|---|
| Share of publicly reported automotive-sector cyber incidents that were ransomware | 44% — the sector’s fastest-growing and most disruptive threat |
| Year-over-year change in ransomware attacks on automotive organizations | More than doubled |
| Incidents that exploited telematics systems, cloud platforms, or APIs | 67% |
| Drivers Halcyon names | Rapid adoption of connected technology, growing cloud reliance, a sprawling third-party supplier network |
Read the 44% carefully. It covers the automotive sector — carmakers, parts and service suppliers, and dealers together — not dealerships in isolation. Nobody publishes a clean, dealership-only ransomware rate, and we’re not going to invent one. What the number does tell you is the direction of travel: within a sector your store is economically wired into, ransomware went from one threat among several to the single largest category of reported incident in a year.
The 67% figure is the one that should change what you do on Monday. Two-thirds of these intrusions did not start with someone walking into your building. They started in an integration.
Why are dealerships such a target?
Dealership ransomware isn’t bad luck, and it isn’t random. Ransomware crews pick targets on three criteria: how much the data is worth, how badly downtime hurts, and how likely the victim is to pay quickly. A dealer group scores high on all three.
- The F&I file is a data goldmine. Credit applications, Social Security numbers, driver’s licenses, bank details, proof of insurance — concentrated, structured, and sitting in systems a salesperson can reach from a desk on the floor.
- Downtime is immediately expensive and publicly visible. You can’t write a deal, close an RO, order a part, or pay a tech. Every hour is measurable lost gross, which is exactly the leverage an extortion crew is buying.
- The third-party surface is enormous. DMS, CRM, desking and F&I tools, lender portals, OEM systems, parts catalogs, payment processors, telematics and connected-car platforms — each one an account, an API key, or a remote-access path into your environment.
- IT is thin and spread across rooftops. Most groups run several stores on one small internal team, often with inconsistent configurations store to store. We see this constantly, and it’s why standardizing IT across multiple locations is usually the first real security win available to a group.
Halcyon’s own explanation lines up with what we see in dealership environments: connected technology adoption outpaced the security around it, cloud reliance grew faster than cloud governance, and the supplier network sprawled without anyone owning the whole map.
How does dealership ransomware actually get in?
Because 67% of 2025’s automotive incidents ran through telematics, cloud platforms, or APIs, the realistic dealership ransomware entry points are mostly the ones nobody owns by name:
- Vendor and API integrations. A third-party tool holds a token into your DMS or CRM. The vendor gets compromised; the token still works. Nothing on your network was “hacked.”
- Cloud platform accounts without MFA. A single-factor login to a cloud console, a lender portal, or a shared marketing platform is a password away from being someone else’s.
- Standing remote access. Vendor support accounts, an old RMM agent, an open RDP path left behind after a project. These outlive the projects that created them.
- Credential theft and social engineering. Attackers increasingly phone the service drive or the BDC rather than emailing it — and the pretexts are getting better. We covered how that’s changing in AI attack vectors at car dealerships.
- Telematics and connected systems. Anything with a network path and a vendor-managed update channel is a path in, whether or not anyone at the store thinks of it as “IT.”
The groups doing this work are organized and repeatable. If you want a concrete picture of how one operates end to end — initial access, double extortion, who they hit — our Qilin ransomware threat profile walks through a crew whose playbook maps almost exactly onto a dealer group’s weak points.
What does a ransomware hit cost a dealer group?
The automotive industry already has its reference event. In June 2024, the BlackSuit group — a rebrand of the Royal ransomware crew — hit the leading dealer management software provider in North America.
| CDK Global ransomware attack (June 2024) | Scale |
|---|---|
| Dealerships with operations taken down | ~15,000 |
| Duration of the disruption | About two weeks |
| Estimated collective dealer losses | ~$1 billion |
| Attributed to | BlackSuit (a rebrand of Royal) |
One important distinction, because it changes who can help you. CDK was someone else’s ransomware incident. Your stores went dark, but your network was fine, and no control you could have bought would have prevented it — that’s a continuity problem, and we wrote it up separately in what to do when your DMS goes down.
This post is about the other scenario: ransomware that lands in your environment — your servers, your identities, your endpoints, your backups. That one you can prevent, and that one is on you. The cost profile is different, too. Alongside lost gross, a dealership ransomware event on your own systems adds forensic investigation, legal counsel, customer notification, credit monitoring, regulator attention, and an insurance claim that will be read very closely against the controls you attested to.
Which controls actually stop dealership ransomware?
Here is the short, unglamorous list. These are the controls we deploy and maintain in real environments — not a maturity model, and not everything a vendor will try to sell you. Work top to bottom; the order reflects what actually blocks dealership ransomware most often.
- MFA on everything, starting with DMS logins and all remote access. Not “most users.” Every account, including vendor and service accounts, including the GM’s. This single control kills the majority of credential-driven intrusions.
- Govern every vendor, API, and telematics integration. Inventory them. Know who holds a token into your DMS, what it can reach, who approved it, and when it was last reviewed. That 67% figure lives here.
- Segment vendor connections from the rest of the network. A compromised integration should reach the one system it needs and nothing else — not the file server, not the domain controller, not the backup target.
- EDR/MDR with someone actually watching. Detection without a human responding at 2 a.m. is a log file you’ll read after the encryption finishes.
- Immutable backups that are restore-tested on a schedule. Modern crews hunt backups before they encrypt anything. If a backup can be deleted with an admin credential, assume it will be. And an untested backup is a hypothesis, not a recovery plan.
- Phishing-resistant authentication where it counts. Push-approval fatigue is a known bypass; hardware keys or device-bound passkeys on admin and finance accounts close it.
- A written incident runbook with names against roles. Who declares an incident, who calls the insurer, who calls counsel, who talks to the OEM, who decides to go to paper on the service drive. Decided in advance, in writing.
Notice what’s not on the list: no threat-intel feed, no dark-web monitoring subscription, no “AI-powered” anything. Those aren’t fraudulent, but at a dealer group’s budget they are a poor trade against MFA coverage and a tested restore.
If you’re past prevention and dealing with an active event, don’t improvise from this page — we’ve documented the first-24-hours sequence in what to do after a ransomware attack. The controls above are what you build before you need that post.
Where this meets FTC Safeguards
Dealerships are financial institutions under the FTC Safeguards Rule, which means several items on the list above aren’t optional best practice — they’re regulatory expectations attached to the customer information you already hold. MFA, access controls, oversight of service providers, and a written incident response plan all appear in both places.
That’s the useful overlap: the work that reduces dealership ransomware risk is largely the same work Safeguards already expects of you. We’re not going to re-explain the rule here — the scope, the required elements, and the qualified-individual question are covered in our plain-English guide to the FTC Safeguards Rule for car dealerships. Whether a specific incident triggers a notification obligation is a legal determination, and that call belongs to your counsel, not your IT provider.
What QOS MSP owns — and what we don’t
QOS MSP has been delivering IT since 2007 — nearly two decades of running other people’s environments — and we’re direct about where our lane ends, because dealership ransomware is a problem with several owners.
What we own. Your own IT: identity and MFA, network segmentation, endpoints and EDR/MDR, patching, backup architecture and restore testing, monitoring and alert response, the integration inventory, and running the recovery when something lands. That’s the work described on our security administration page, and the control evidence side of it feeds directly into compliance.
What we don’t own, plainly. We do not secure your DMS vendor’s platform. CDK, Reynolds and Reynolds, and their peers run their own infrastructure, and no MSP contract changes that. We don’t secure OEM systems or manufacturer portals. We don’t secure vehicle telematics. What we can do with all three is control how they connect to you — segmenting them, governing their credentials, and limiting what a compromise on their side can reach on yours.
We’re also not breach counsel, and we’re not a digital-forensics or ransom-negotiation firm. When an incident needs those, we say so and help you engage them — we don’t pretend the roles are interchangeable.
When you don’t need us. If you’re a single rooftop with a capable IT manager who already has MFA everywhere, a tested immutable backup, and a written integration inventory, you have the hard parts done. Hire an outside review, not a full managed contract. Managed IT earns its keep at the point where multiple rooftops, inconsistent configurations, and a dozen vendor integrations have outgrown the person holding it all together — which, in our experience, is most groups past the second store.
If you want a straight answer about where your group actually stands, talk to us. We’ll start with the integration inventory and your restore test, because that’s where the honest answers usually are.
Frequently asked questions
What percentage of automotive cyberattacks are ransomware?
Ransomware accounted for 44% of publicly reported cyber incidents across the automotive sector in 2025, according to Halcyon’s report 44% and Rising. That figure covers the automotive sector broadly, including manufacturers and suppliers as well as dealers, not dealerships alone. Halcyon also found that ransomware attacks on automotive organizations more than doubled during 2025.
How does dealership ransomware usually get into a dealer group?
Mostly through integrations rather than the front door. Halcyon found that 67% of 2025 automotive incidents exploited telematics systems, cloud platforms, or APIs. In practice that means compromised vendor or API connections into the DMS and CRM, cloud platform accounts without multi-factor authentication, standing remote-access paths left over from old projects, and credential theft through phishing or phone-based social engineering.
What happened in the CDK Global ransomware attack?
In June 2024 the BlackSuit ransomware group, a rebrand of the Royal crew, attacked CDK Global, the leading dealer management software provider in North America. The attack took down operations at roughly 15,000 dealerships for about two weeks, with collective dealer losses estimated at around $1 billion. Importantly, that was the vendor’s incident, not the dealers’ own networks, which makes it a business-continuity problem rather than something a dealership security control could have prevented.
Does the FTC Safeguards Rule require dealerships to prevent ransomware?
The rule does not name ransomware, but it requires dealerships to maintain a written information security program covering multi-factor authentication, access controls, oversight of service providers, and a written incident response plan. Those are the same controls that block most dealership ransomware. So the compliance work and the ransomware work overlap heavily, though whether a specific incident triggers a notification obligation is a legal determination for your counsel.
What is the single most effective control against dealership ransomware?
Multi-factor authentication applied to every account, with no exceptions, starting with DMS logins and all remote access. Most ransomware intrusions in this sector begin with a working credential rather than an exploit, and MFA breaks that path. The close second is an immutable backup that is restore-tested on a schedule, because modern ransomware crews delete backups before they encrypt anything.
Can an MSP protect our DMS from ransomware?
Not the DMS platform itself. CDK, Reynolds and Reynolds, and similar providers run their own infrastructure, and no managed IT contract gives a provider control over it. What QOS MSP does is secure everything on the dealership side of that connection: identity and MFA, network segmentation around vendor links, endpoints, backups, and monitoring, plus running the recovery. We also govern the credentials and API tokens those platforms hold, so a compromise on the vendor’s side reaches as little of your network as possible.