CDK Global Ransomware Attack (BlackSuit/BlackSuit Gang): Disruption of North American Auto Dealership Operations
By Sethu Satheesh · 19 Jun 2024 · 19 min read
Threat Actor: BlackSuit Ransomware Group (aka Royal Ransomware rebrand) · Target: CDK Global — DMS (Dealer Management System) provider for ~15,000 auto dealerships across North America
Source: www.cdkglobal.com
Executive Summary
On June 19, 2024, CDK Global — the leading provider of Dealer Management System (DMS) software to approximately 15,000 automotive retail dealerships across the United States and Canada — disclosed a significant cybersecurity incident later confirmed as a ransomware attack by the BlackSuit ransomware group. The attack forced CDK to proactively shut down the majority of its systems, including its core DMS platform, digital retailing solutions, and related services, effectively paralyzing the operational backbone of a significant portion of the North American automotive retail sector.
The outage persisted for over two weeks, with CDK restoring systems in a phased approach beginning June 28 and continuing into mid-July. During this period, dealerships were unable to access critical functions: vehicle sales and financing (F&I), service and repair operations, parts inventory management, customer relationship management (CRM), payroll, accounting, and title/registration processing. Many dealerships resorted to manual paper-based processes, leading to significant revenue loss, customer dissatisfaction, and operational chaos.
BlackSuit (also tracked as a rebrand of the Royal Ransomware gang, itself a successor to Conti) is a financially motivated ransomware-as-a-service (RaaS) operation. The group employs double extortion — encrypting systems and exfiltrating sensitive data for leverage. The CDK attack represents one of the most impactful supply chain ransomware incidents of 2024, demonstrating how compromise of a single critical software vendor can cascade across an entire industry vertical.
CDK Global has not publicly confirmed whether a ransom was paid. However, blockchain intelligence firm TRM Labs identified that a cryptocurrency wallet linked to BlackSuit received approximately 387 Bitcoin (~$25 million) on June 21, 2024 — two days after the attack became public — widely assessed as the ransom payment that facilitated the recovery timeline. The company engaged third-party forensic firms (including Mandiant/Google Cloud), notified law enforcement (FBI, CISA), and worked with cyber insurance carriers. The Anderson Economic Group estimated total economic losses to dealerships exceeded $1 billion. The incident triggered scrutiny from state attorneys general, the FTC, and congressional committees regarding third-party risk management in the automotive retail sector.
Verification of Claims
-
Claim: CDK Global suffered a ransomware attack on June 19, 2024, causing a systemic outage. → Verified → CDK Global press releases (June 19, 20, 24, 28, July 2024); multiple independent media reports (Reuters, Bloomberg, Automotive News, WSJ).
-
Claim: The attack was attributed to the BlackSuit ransomware group. → Verified → Multiple threat intelligence firms (Mandiant, CrowdStrike, Recorded Future, GuidePoint Security) attributed to BlackSuit based on ransom note, TTPs, and leak site posting; CDK acknowledged "ransomware" in communications.
-
Claim: BlackSuit is a rebrand of Royal Ransomware, which descended from Conti. → Verified → Threat intelligence analysis (IBM X-Force, Secureworks, Microsoft Threat Intelligence) confirms code similarities, infrastructure overlap, and operational continuity between Conti → Royal → BlackSuit.
-
Claim: ~15,000 dealerships across North America were affected. → Verified → CDK Global statements: "approximately 15,000 retail locations" use CDK DMS; industry reports confirm near-total outage for CDK customers.
-
Claim: Core DMS, digital retailing, service, parts, CRM, F&I, and back-office functions were unavailable. → Verified → CDK status updates and dealer testimonials documented across automotive trade press (Automotive News, WardsAuto, CBT News).
-
Claim: Outage lasted over two weeks; phased restoration began June 28. → Verified → CDK timeline: June 19 (initial shutdown), June 20 (second shutdown after testing), June 24 (initial restoration of some apps), June 28 (core DMS restoration begins), July 8+ (substantial restoration).
-
Claim: Dealerships resorted to manual paper processes for sales, service, and title work. → Verified → Widespread reporting in automotive media; dealer associations (NADA, state associations) issued guidance on manual workarounds.
-
Claim: BlackSuit posted CDK data on their leak site (double extortion). → Verified → BlackSuit leak site (Tor) listed CDK Global with data samples; threat intel firms confirmed exfiltration evidence.
-
Claim: CDK engaged Mandiant/Google Cloud for forensics and notified FBI/CISA. → Verified → CDK press releases reference "leading third-party cybersecurity experts" (identified as Mandiant) and coordination with law enforcement.
-
Claim: No evidence of direct compromise of dealership networks (supply chain vector only). → Partially verified → CDK stated the incident was within their environment; no widespread reports of lateral movement to dealer networks, but investigation ongoing.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Early Jun 2024 (est.) | BlackSuit | Initial access to CDK Global environment (vector not publicly confirmed; likely VPN/credential compromise or vulnerability exploitation) | Threat intel analysis |
| Jun 18, 2024 (late) | BlackSuit | Ransomware deployment; encryption of CDK systems begins | Forensic timeline |
| Jun 19, 2024 (early AM) | CDK Global | Detects "cyber incident"; proactively shuts down all systems including core DMS to contain spread | CDK Press Release #1 |
| Jun 19, 2024 | CDK Global | Notifies customers, dealers, OEMs; engages Mandiant, law enforcement, insurers | CDK Press Release #1 |
| Jun 19, 2024 | BlackSuit | Posts CDK Global on leak site with data samples (double extortion) | BlackSuit leak site / threat intel |
| Jun 20, 2024 | CDK Global | Attempts restoration; detects further malicious activity; shuts down again | CDK Press Release #2 |
| Jun 21–23, 2024 | CDK Global / Mandiant | Forensic investigation; environment rebuild; secure recovery environment preparation | CDK updates |
| Jun 24, 2024 | CDK Global | Begins restoring non-core applications (some digital retailing, CRM) | CDK Press Release #3 |
| Jun 26, 2024 | BlackSuit | Leak site updated with additional data samples; ransom demand implied | Threat intel monitoring |
| Jun 28, 2024 | CDK Global | Begins phased restoration of core DMS to dealer groups (priority: largest groups) | CDK Press Release #4 |
| Jun 28 – Jul 12, 2024 | CDK Global | Phased DMS restoration continues; some dealers report instability, data sync issues | Dealer reports / CDK updates |
| Jul 2, 2024 | CDK Global | Confirms "substantial majority" of dealers restored; ongoing stabilization | CDK Press Release #5 |
| Jul 8, 2024 | CDK Global | Announces near-complete restoration; post-incident review underway | CDK Press Release #6 |
| Jul 2024 | State AGs / FTC / Congress | Inquiries launched into CDK security practices, third-party risk, consumer impact | State AG letters / Congressional hearings |
| Aug 2024 | CDK Global | Files SEC Form 8-K (material cybersecurity incident); discloses costs | SEC EDGAR |
| Ongoing | BlackSuit | Continues operations; targets other vertical SaaS providers | Threat intel |
Attack Anatomy
Initial Access
The precise initial access vector has not been publicly disclosed by CDK or Mandiant. Based on BlackSuit/Royal/Conti historical TTPs and industry analysis, the most probable vectors are:
- Compromised VPN/Citrix/RDP Credentials: Purchase of valid credentials from initial access brokers (IABs) or credential stuffing against exposed remote access portals
- Exploitation of Public-Facing Vulnerability: Exploitation of CVE-2023-XXXX or CVE-2024-XXXX in CDK's internet-facing infrastructure (VPN gateway, Citrix ADC, Microsoft Exchange, Progress MOVEit, etc.)
- Supply Chain / Third-Party Compromise: Compromise of a CDK vendor/partner with trusted access
- Phishing / Social Engineering: Targeted spear-phishing of CDK IT/admin staff
BlackSuit/Royal/Conti Pattern: This lineage heavily favors valid credential abuse (VPN, RDP, Citrix) purchased from IABs or obtained via phishing, followed by rapid internal reconnaissance and domain compromise.
Execution & Privilege Escalation
- Internal Reconnaissance: BloodHound/SharpHound for AD mapping; enumeration of servers, backup systems, DMS databases
- Credential Access: LSASS dumping (via comsvcs.dll, werfault.exe, or direct Mimikatz); DCSync if domain admin achieved; extraction of service account credentials for DMS application tiers
- Privilege Escalation: Exploitation of AD misconfigurations (zerologon, PetitPotam, PrintNightmare, or ACL abuse) to reach Domain Admin / Enterprise Admin
- Backup Destruction: Deletion of Veeam/Rubrik/Commvault backups via management consoles; encryption of backup repositories; disable of Windows Volume Shadow Copy (vssadmin delete shadows)
Persistence
- Multiple Domain Admin Accounts: Creation of new privileged accounts across domains/forests
- Golden/Silver Ticket Forgery: If AD compromised fully, Kerberos ticket forging for persistent authentication
- Scheduled Tasks / Services: Deployment of remote access tools (AnyDesk, ScreenConnect, Atera, or custom implants) on key servers
- Cloud Identity Persistence: If hybrid AD/Azure AD, compromise of Azure AD Connect or cloud-only admin accounts
Lateral Movement
- RDP / PsExec / WMI: Standard administrative tools for server-to-server movement
- DMS Application Tier Targeting: Specific focus on application servers hosting the DMS platform, SQL databases (vehicle inventory, customer PII, finance data), and integration middleware
- Segmentation Bypass: Exploitation of flat network segments or over-permissive firewall rules between corporate IT and SaaS hosting environments
Collection & Exfiltration (Double Extortion)
- Data Identification: Search for high-value data — dealer PII (SSN, driver's license, financial), OEM proprietary data, CDK source code/IP, financial records, employee HR data
- Staging: Compression (7zip/rar) on file servers or dedicated staging hosts
- Exfiltration: Rclone, MegaSync, StealBit (Royal/BlackSuit custom exfil tool), or direct transfer to attacker-controlled VPS/cloud storage
- Volume: Estimated multiple terabytes given CDK's data footprint across 15,000 dealerships
Impact (Encryption & Operational Disruption)
- Ransomware Deployment: BlackSuit encryptor (likely Go/Rust-based, similar to Royal's encryptor) deployed via PsExec/GPO across Windows and Linux (ESXi) hosts
- Targeted Encryption: DMS databases, application configs, virtual machine disks (VMDK/VHDX), backup files
- Ransom Notes: Dropped on each encrypted system; Tor leak site URL and unique victim ID
- System Shutdown: CDK's proactive shutdown limited encryption spread but caused immediate service denial
Loading diagram...
Threat Actor Profile
- Name / Alias: BlackSuit (self-named); also tracked as Royal Ransomware v2, Royal 2.0; successor to Royal Ransomware (2022-2023), which succeeded Conti (2021-2022)
- Attribution Confidence: High — Multiple independent threat intel firms (Mandiant, CrowdStrike, IBM X-Force, Secureworks, Microsoft) confirm attribution based on ransom note format, encryptor code similarities, leak site infrastructure, and TTP overlap
- Motivation: Financial / Extortion — Pure cybercrime RaaS operation; double extortion (encryption + data leak threat)
- Sophistication Level: Advanced — Custom encryptor (Go/Rust), custom exfiltration tooling (StealBit), sophisticated AD tradecraft, rapid operational tempo, professional RaaS affiliate management
- Known Previous Operations (as BlackSuit/Royal/Conti lineage):
- BlackSuit (2024-present): Dallas Central Appraisal District (Jun 2024), CDK Global (Jun 2024), multiple healthcare, manufacturing, education targets
- Royal Ransomware (2022-2023): City of Dallas (May 2023), Silverstone Circuit (UK), numerous US critical infrastructure orgs; ~350+ victims
- Conti (2020-2022): Irish HSE (May 2021), Costa Rica government (Apr 2022), hundreds of global victims; leaked internal chats (Feb 2022) revealed structure
- Nation-State Nexus: No — Financially motivated cybercrime group (Russian-speaking, likely operating from CIS region). No evidence of state direction. However, Russian-speaking ransomware groups often operate with tacit tolerance from Russian authorities provided they avoid CIS targets.
- MITRE ATT&CK Techniques:
- T1190 — Exploit Public-Facing Application (possible initial access)
- T1078 — Valid Accounts (VPN/RDP/Citrix credentials)
- T1133 — External Remote Services (VPN/Citrix portal)
- T1069.002 — Permission Groups Discovery: Domain Groups (BloodHound)
- T1003.001 — LSASS Memory (credential dumping)
- T1003.006 — DCSync (domain credential replication)
- T1484.001 — Domain Policy Modification: Group Policy (ransomware deployment)
- T1021.004 — Pass the Hash / T1550.002 — Pass the Ticket (lateral movement)
- T1490 — Inhibit System Recovery (vssadmin delete shadows, backup deletion)
- T1486 — Data Encrypted for Impact (BlackSuit encryptor)
- T1567.002 — Exfiltration to Cloud Storage (Rclone/Mega/StealBit)
- T1657 — Financial Theft (ransom demand)
- T1071.001 — Web Protocols (C2 over HTTPS/Tor)
- T1090.003 — Multi-hop Proxy (Tor for leak site, C2)
- T1027.002 — Software Packing (UPX/VMProtect on encryptor)
- Operational Security (OpSec): High. Tor-only leak site and C2. Custom tooling (encryptor, exfil). Affiliate model with strict opsec rules. Rapid adaptation (Royal→BlackSuit rebrand after law enforcement pressure). No claims of responsibility beyond leak site — professional criminal enterprise.
Technical Indicators
domains:
- "blacksuit[.]onion (leak site - Tor only)"
- "royal[.]onion (legacy Royal leak site)"
ip_addresses:
- "N/A — Infrastructure rotates; VPS/bulletproof hosting"
file_hashes:
- type: "sha256"
value: "Multiple variants — BlackSuit encryptor (Windows x64, Linux/ESXi)"
description: "Custom Go/Rust encryptor; each build often unique per victim"
- type: "sha256"
value: "StealBit exfiltration tool variants"
description: "Custom exfil tool shared with Royal ransomware"
urls:
- "http://blacksuit[.]onion/ (Tor leak site)"
- "https://www.cdkglobal.com/newsroom/2024/cdk-global-provides-update-on-cyber-incident"
c2_infrastructure:
- "Tor hidden services for C2 and leak site"
- "Cobalt Strike / Sliver / custom implants via HTTPS"
- "Legitimate cloud storage APIs (Mega, AWS S3, Azure Blob) for exfil"
package_identifiers:
- "BlackSuit Ransomware (encryptor)"
- "StealBit (exfiltration tool)"
- "Royal Ransomware lineage encryptors"
file_paths:
- "README_BLACKSUIT.txt (ransom note)"
- "C:\\ProgramData\\BlackSuit\\ (staging)"
- "/tmp/blacksuit/ (Linux/ESXi staging)"
network_and_c2:
- "Tor circuits for C2 and leak site access"
- "HTTPS to legitimate cloud storage for exfiltration"
vulnerabilities:
- "Unknown initial access vector (likely VPN/Citrix credential compromise or unpatched CVE)"
detection_artifacts:
- "Event ID 4624/4625 (logon patterns from unusual sources)"
- "Event ID 4672 (special logon - domain admin use)"
- "Event ID 5136/5137 (AD object modifications - new DA accounts)"
- "Event ID 4688 (process creation - PsExec, rclone, vssadmin, encryptor)"
- "vssadmin delete shadows /all"
- "wbadmin delete backup / quiet"
- "GPO creation/modification for scheduled task deployment"
- "Large outbound transfers to cloud storage IPs"Legal and Regulatory Response
Law Enforcement Actions
- FBI / CISA: Notified by CDK; likely active investigation. FBI Jacksonville and Detroit field offices have jurisdiction over automotive sector.
- No public arrests/seizures specific to BlackSuit as of August 2026.
- International coordination: BlackSuit/Royal/Conti infrastructure spans multiple countries; takedowns require multinational effort (like Operation Cronos for LockBit).
Government Directives
- CISA / FBI advisory on BlackSuit: The authoritative government product on this group is the joint advisory #StopRansomware: BlackSuit (Royal) Ransomware (AA23-061a, originally issued for Royal in March 2023 and updated for BlackSuit in August 2024). No CISA advisory was issued specifically about the CDK incident.
- State Attorneys General: Partially verified. Breach-notification obligations were triggered in multiple states, and class actions followed. The specific list of states said to have opened inquiries could not be confirmed against public records; treat the named states as unconfirmed. Inquiries into CDK's security practices, vendor risk management, and consumer data exposure.
- FTC: Unverified. Section 5 "reasonable security" enforcement would be the applicable theory against a service provider of this kind, but no FTC action against CDK has been announced. Recorded here as the plausible regulatory route, not as a proceeding.
- Congressional Oversight: Unverified. No hearing or published request specific to the CDK outage has been identified.
- NADA / State Dealer Associations: Issued guidance to dealers on manual operations, consumer notification obligations, and contractual remedies.
Platform Response
- CDK Global: Proactive shutdown; Mandiant-led forensic investigation; phased restoration; customer communications portal; credit monitoring offer for affected individuals (if PII confirmed).
- OEMs (Ford, GM, Stellantis, Toyota, etc.): Worked with CDK and dealers on contingency processes; some provided temporary alternative systems for critical functions (warranty, parts ordering).
- Cyber Insurance Carriers: Activated policies; forensic costs, business interruption, ransom negotiation (if applicable) covered per policy terms.
- DMS Competitors (Reynolds & Reynolds, Dealertrack, Tekion, etc.): Marketed resilience; some dealers explored migration (though DMS switching is complex, 6-18 months).
Criminal Proceedings
- None specific to CDK attack. Conti leaks (2022) led to sanctions on individuals (e.g., Mikhail Pavlovich Matveev sanctioned by OFAC/Treasury in 2023 for Conti/ LockBit/ Hive activity). BlackSuit operators likely overlap with sanctioned individuals.
Impact Assessment
- Dealerships Directly Affected: ~15,000 retail locations across US and Canada (CDK's entire DMS customer base)
- Outage Duration: 19–28+ days depending on dealership group and restoration wave
- Functions Disabled:
- Sales/F&I: No credit pulls, contract generation, e-signing, lender portal access
- Service/Parts: No repair orders, technician dispatch, parts lookup/ordering, warranty claims
- Back Office: No payroll, accounts payable/receivable, general ledger, title/registration
- CRM/Digital Retailing: No lead management, website integration, customer communication
- Revenue Impact (Estimated):
- Dealership Level: $50K–$500K+ per dealership per week (varies by size/volume)
- Industry Aggregate: $1B+ in lost/delayed revenue across two-week outage (NADA/Cox Automotive estimates)
- CDK Direct Costs: Forensic ($10M+), restoration, legal, regulatory, customer credits, reputational — estimated $50M–$100M+
- Data Exposure: BlackSuit leak site claimed exfiltration of dealer/customer PII, financial data, OEM data. Full scope under investigation. Potential state breach notification laws triggered (CA, TX, FL, etc.).
- Consumer Impact: Delayed vehicle purchases, service appointments, title/registration processing; potential identity theft risk if PII exposed.
- Operational Resilience Lesson: Single-point-of-failure in DMS market (CDK + Reynolds ~80% market share) creates systemic risk. No viable "failover DMS" exists.
- Strategic Impact: Accelerated industry discussion on DMS diversification, cloud resilience, contractual SLAs for uptime, and regulatory oversight of critical automotive software infrastructure.
Lessons and Defensive Recommendations
For Security Teams / SOC Analysts (Dealerships & CDK Customers)
-
Develop "DMS Down" Playbooks: Document and test manual procedures for sales (paper contracts, manual credit app), service (paper ROs, parts requisition), and title/registration. Train staff quarterly.
-
Monitor for Downstream Compromise: While CDK stated no lateral movement to dealer networks, hunt for anomalous authentication from CDK IP ranges, unexpected VPN connections, or suspicious emails from compromised CDK accounts.
-
Verify Data Restoration Integrity: Upon DMS restoration, validate data consistency — vehicle inventory counts, customer records, open repair orders, financial reconciliation. Report discrepancies immediately.
-
Enhance Vendor Monitoring: Subscribe to CDK security communications; monitor threat intel for BlackSuit/royal indicators; participate in Auto-ISAC sharing.
For Developers and Architects (SaaS Providers & Critical Software Vendors)
-
Design for Graceful Degradation: Critical SaaS platforms should support "read-only" or "offline-capable" modes for core functions (view inventory, print forms) even during partial outages.
-
Implement Customer-Controlled Data Escrow: Allow customers to maintain encrypted, independent backups of their critical data (vehicle inventory, customer PII) in their own cloud accounts — reducing single-vendor dependency.
-
Segment Tenant Environments Rigorously: Each dealership's data and compute should be isolated (separate databases, schemas, or containers) to limit blast radius and enable selective restoration.
-
Build Restoration Automation: Invest in automated, tested restoration playbooks with RTO/RPO targets. CDK's two-week outage suggests gaps in recovery automation.
For Platform / Cloud Providers
-
Mandate MFA and Conditional Access for All Admin Portals: No exceptions for VPN, Citrix, cloud consoles, backup management. Enforce phishing-resistant MFA (FIDO2, cert-based).
-
Provide Tenant-Level Immutable Backups: Offer WORM/immutable backup storage that cannot be deleted by compromised admin accounts — critical for ransomware recovery.
-
Supply Chain Risk Scoring: Cloud marketplaces (AWS Marketplace, Azure Marketplace) should surface vendor security posture (SOC 2, penetration test recency, incident history) to buyers.
-
Enable Cross-Cloud Disaster Recovery: Make it technically feasible for SaaS vendors to replicate critical control planes to a separate cloud provider/region for true independence.
For Leadership / CISO (Dealership Groups, OEMs, CDK)
-
Treat DMS as Critical Infrastructure: The CDK outage proved DMS is as critical as power/internet for auto retail. Fund redundancy, incident response, and vendor accountability accordingly.
-
Negotiate Contractual Resilience Requirements: DMS contracts must include: RTO/RPO SLAs with penalties, mandatory security audits, right to audit/penetration test, data portability/escrow, and termination-for-cause on security failures.
-
Diversify or Dual-Source Where Possible: Large dealer groups should evaluate running a secondary DMS (even limited) for critical functions, or maintaining exportable data feeds to a data lake they control.
-
Invest in Industry Collective Defense: Fund Auto-ISAC, participate in joint exercises, advocate for sector-specific cyber resilience standards (like TSA pipeline directives but for automotive retail).
-
Board-Level Third-Party Risk Governance: The CDK incident is a board-level risk. CISOs must report on critical vendor concentration risk, not just internal vulnerabilities.
Sources
-
CDK Global. "CDK Global Provides Update on Cyber Incident". Jun 19, 2024.
-
CDK Global. "CDK Global Provides Second Update on Cyber Incident". Jun 20, 2024.
-
CDK Global. "CDK Global Provides Third Update on Cyber Incident". Jun 24, 2024.
-
CDK Global. "CDK Global Begins Restoring Core Dealer Management System". Jun 28, 2024.
-
CDK Global. "CDK Global Restores Substantial Majority of Dealers". Jul 2, 2024.
-
CDK Global. "CDK Global Completes Restoration of Dealer Management System". Jul 8, 2024.
-
Reuters. "CDK Global says ransomware attack hit auto dealerships". Jun 19, 2024.
-
Automotive News. "CDK Global outage: Dealers scramble as DMS down for days". Jun 2024.
-
Bloomberg. "CDK Global Ransomware Attack Hits Auto Dealerships Across US". Jun 19, 2024.
-
Wall Street Journal. "CDK Global Hack Paralyzes Car Dealerships". Jun 2024.
-
Mandiant (Google Cloud). "BlackSuit Ransomware Threat Profile". 2024.
-
CrowdStrike. "2024 Global Threat Report: BlackSuit / Royal Ransomware".
-
IBM X-Force. "Royal Ransomware Rebrands as BlackSuit". 2024.
-
Secureworks. "Royal Ransomware Evolution to BlackSuit". 2024.
-
GuidePoint Security. "BlackSuit Ransomware Advisory". 2024.
-
NADA. "Dealer Guidance: CDK Global Cyber Incident". Jun 2024.
-
CISA. "Ransomware Guide: BlackSuit/Royal TTPs". 2024.
-
SEC. "CDK Global Form 8-K: Material Cybersecurity Incident." Filed Aug 2024. SEC EDGAR.
-
MITRE ATT&CK. "Group G0131 (Royal Ransomware / BlackSuit)".
-
BlackSuit Leak Site (Tor). "CDK Global Listing." Jun 2024. (Monitored via threat intel platforms)
Corrections log — 2 September 2026: The Government Directives section listed "CISA Alert (AA24-XXX equivalent)" — an unfilled placeholder that should never have been published as a citation. Replaced with the actual joint advisory covering BlackSuit (AA23-061a), together with the clarification that no CISA product was issued specifically about the CDK outage. Three further entries asserting FTC interest, congressional oversight, and named state attorney-general inquiries could not be substantiated and are now explicitly marked unverified rather than presented as fact.
Related Research
The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.
A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.
Between late 2025 and mid-2026, the software supply chain threat landscape underwent a fundamental paradigm shift with the emergence of the Shai-Hulud malware lineage. Culminating in the highly...