CDK Global cyber incident

https://www.instagram.com/p/C8fKPg6ObGd/?igsh=MTE4NGY4bXp6MnZwaw==

They probably use Reynolds & Reynolds or similar

Don’t know what R&R is, but Rodo doesn’t own any cars, so all deals still go through the actual dealers.

Rey Rey is probably the largest dealer SaaS

Are you saying Rey Rey is their main dealer?

No it’s a software service

2 Likes

From car dealership guy

Curious - could this CDK outage cause a pricing issue?

But my point is they can’t do their own deals even with a different software provider since they don’t own any cars. Am I missing something? lol

I got my own in-house Google Sheets DMS if anyone wants for the low low of $500/day

5 Likes

Do you actually? Intriguing if so and if useful. Once upon a time, when I had a smaller business, I relied exclusively on my excel sheets.

There’s different software platforms. CDK is one. Reynolds and Reynolds (otherwise referred to as Rey Rey) is another. RODO certainly has CDK dealers. They certainly have Reynolds dealers, and other non-CDK dealers. I’m assuming they will just route customers to dealers of whatever brand which uses non-CDK software

2 Likes

Now we’ll be able to tell if those GSMs that claim they’re “one of a few in the country that can calculate a lease by hand” are full of shit or not :joy:

4 Likes

I’m in the business of data protection and disaster recovery, and let me tell you that nobody(there are exceptions) has a sound strategy. It’s like that saying “everyone is a tough guy until they get punched in the face.” To have backup off-site and fail over, requires resources, manpower, time and effort that requires cost at the end of the day that customers are not investing into.

2 Likes

I totally believe this.

I think my own personal data is likely better protected than some of these multi-million dollar companies, I have two on-site, one off-site, and anything really important is also in Google Drive.

1 Like

Redundancy is expensive but it’s better than nothing

It’s Rodo… not like any of their deals exist anyway.

8 Likes

Even if they did: once you’ve had an intrusion, your backups becomes suspect, and probably your prod/non-prod environments. If this threat actor was any good, they would’ve planted this thing in the past and set it lock on a timer.

I recovered from one of these about 18 months ago for a client, the system had multiple daily backups in multiple places. Two of us worked for 2 1/2 days straight recovering multiple backups into multiple environments until we found one that wasn’t tainted, turned hamburger back into cow, and had to ignore the massive cloud hosting bill it generated. The footprint was much smaller than CDK.

If you’re trying to recover around it, you need 2x infrastructure and you need to quarantine the old one for forensics.

Good stuff,.glad you found a clean recovery point. Yeah this stuff gets dismissed until the business needs it and then they ask all the tough questions. Why wasn’t this protected and detected and etc.

If it stays down, they will need this soon.

3 Likes