CDK Global BlackSuit Ransomware Incident
Key Facts
- Legal Status: ALLEGED in U.S. District Court for the Northern District of Illinois.
- Primary Target Sector: Information Technology, Retail, Automotive.
- Documented Financial Loss: $1.0 billion.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversaries gained initial ingress to CDK Global internal network infrastructure via compromised administrative credentials, subsequently establishing an undetected command foothold.
Operational & Financial Fallout
Shutdown of CDK dealer management systems utilized by approximately 15,000 car dealerships in the United States and Canada. Dealerships were unable to process new vehicle purchases, register titles, order replacement parts, or service vehicles for nearly two weeks. Industry sales losses estimated in the billions, with an estimated $25M ransom payment.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversaries gained initial ingress to CDK Global internal network infrastructure via compromised administrative credentials, subsequently establishing an undetected command foothold.
Adversary Kill Chain Flow
4 Documented PhasesBlackSuit ransomware affiliates authenticated to internal CDK management subnets using valid administrator credentials that lacked second-factor validation.
Attackers executed vssadmin commands to destroy local Volume Shadow Copies and attempted to disable host monitoring agents across hypervisor hosts.
Adversaries unleashed the BlackSuit encryption binary across both Windows server clusters and VMware ESXi hypervisors, encrypting database virtual disks (.vmdk) simultaneously.
As CDK engineering teams attempted to bring backup systems online, the ransomware detonated a second time across newly exposed environments, forcing an extended blackout.
Shutdown of CDK dealer management systems utilized by approximately 15,000 car dealerships in the United States and Canada. Dealerships were unable to process new vehicle purchases, register titles, order replacement parts, or service vehicles for nearly two weeks. Industry sales losses estimated in the billions, with an estimated $25M ransom payment.
Procedural & Incident Timeline
CDK Global detects BlackSuit ransomware executing across core servers and shuts down systems.
A second encryption wave triggers during restoration efforts, shutting down dealership services again.
CDK Global transfers 387 Bitcoin (approx. $25M) to a BlackSuit extortion address to obtain decryptor.
Core dealer management system services are restored to nearly all 15,000 dealerships.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Attackers gained access to CDK enterprise networks using compromised administrator credentials, bypassing secondary verification checks." | Class Action Complaint: 1:24-cv-05231 (N.D. Ill.) | reviewed |
| T1486 | Data Encrypted for Impact Impact | "BlackSuit ransomware payloads encrypted virtualized database instances, dealer inventory feeds, and customer relationship management clusters." | CISA & FBI Joint Advisory AA24-220A (BlackSuit) | reviewed |
| T1490 | Inhibit System Recovery Impact | "The ransomware deleted Volume Shadow Copies and backup catalogues, crippling initial automated recovery attempts and forcing a secondary blackout." | CISA Advisory AA24-220A Technical Details | reviewed |