The June 2024 CDK Global ransomware attack is documented, attributed, and now partly adjudicated — but there is no mass consumer notice, so verifying your own exposure means going to the dealership and your state attorney general, not to a claims website. CDK Global sells dealer management software, the system that runs sales, financing, parts and service records at roughly 15,000 auto dealerships in the U.S. and Canada, and the attack took most of that offline for about two weeks. This guide sets out what the evidence actually establishes: the timeline, the attacker, the single regulator filing that exists, the litigation now consolidated in federal court, and the practical steps that follow from all of it.
Table of Contents
- What happened, and over what dates
- Who carried it out
- The only official notice on file
- What the lawsuits allege, and what remains unproven
- Why the attacker's leak site is no longer a source
- How to verify your own exposure
- Frequently Asked Questions
What happened, and over what dates
The intrusion began on June 18–19, 2024. CDK shut down most of its systems in response, and dealerships across North America reverted to pen-and-paper for vehicle sales, parts ordering and financing until service was largely restored around July 5, 2024, according to Automotive News's coverage of the attack and the resulting litigation. CDK's own account to regulators is slightly tighter and slightly earlier.
Its breach report to the Maine Attorney General puts the incident window at June 14–20, 2024, with discovery on June 19, 2024, and classifies it as external system hacking. The two-week outage was not a minor inconvenience for the industry. Anderson Economic Group calculated direct dealer losses of $1.02 billion over June 19 to July 15, 2024, including roughly 56,200 lost new-vehicle sales alongside parts, service, staffing, IT and floor-plan interest costs. That figure deliberately excludes consumer harm, reputational damage and litigation costs, so it is a floor on the economic footprint, not a total.
Who carried it out
The attack was attributed to BlackSuit, a ransomware group that steals data before encrypting it and then extorts the victim on both fronts. FBI and CISA's joint advisory AA23-061A, updated August 7, 2024, documents that BlackSuit is the rebranded Royal ransomware operation, that it exfiltrates data and extorts before encryption, and that it has demanded more than $500 million in total, with individual demands running from roughly $1 million to $60 million. That exfiltration-first pattern matters for readers assessing their own risk.
It means a BlackSuit incident is a data theft event by design, not only a disruption event — the encryption is leverage layered on top of a copy the attacker already holds. On June 21, 2024, roughly 387 bitcoin — about $25 million — moved to a cryptocurrency account controlled by actors affiliated with BlackSuit, per blockchain-tracing reporting summarized by Bloomberg Law. CDK has never publicly confirmed paying a ransom.
The only official notice on file
One official notification document is publicly attached to this event: CDK's report to the Maine Attorney General. It lists 36 persons affected in total, including a single Maine resident. Maine's registry captures filings that would be invisible elsewhere because state law triggers disclosure at one affected resident. That 36-person figure is the regulator-filed number, and it sits far below the population the lawsuits describe.
Both numbers are real; they answer different questions. The Maine filing reflects what CDK reported as its own directly notifiable population, while the litigation concerns records held across thousands of dealerships that ran on CDK software. The filing, reported in October 2024, names CDK's outside counsel Reena Bajowala of Greenberg Traurig, (312) 456-1018, as the contact for verification — a detail Automotive News pulled from the notification. If you are documenting a claim or a corporate exposure review, that is the contact of record.
What the lawsuits allege, and what remains unproven
More than a dozen federal suits — brought by consumers, dealership employees and non-dealer businesses — were consolidated by the U.S. District Court for the Northern District of Illinois into two umbrella cases. The claims are negligence, breach of contract and state consumer-protection violations, all resting on an alleged failure to maintain reasonable security.
Plaintiffs allege the exposed data included names, addresses, Social Security numbers, driver's license numbers and credit information gathered during vehicle purchases and employment, as summarized by the National Law Review. Read that precisely: it is an allegation in pleadings, not a data inventory CDK has confirmed. That distinction is the evidentiary center of the case. Consolidated discovery is where an alleged data category either becomes an established one or falls away, and a reader deciding whether to monitor credit should treat the plaintiffs' list as the plausible worst case rather than a settled finding.
Why the attacker's leak site is no longer a source
Victims of ransomware sometimes verify exposure by checking what the group published on its own extortion site. That route is closed here.
On July 24, 2025, Operation Checkmate — led by ICE Homeland Security Investigations with partners in eight countries — seized four servers and nine BlackSuit domains, and the Justice Department announced on August 11, 2025 the seizure of $1,091,453 in laundered cryptocurrency. The takedown is good news for disruption and bad news for individual evidence-gathering. With the infrastructure seized, the leak site is no longer available as a source, which pushes verification back onto the dealership that held your file and onto state regulators.
How to verify your own exposure
Because CDK sent no mass consumer notice, the burden of checking falls on the record-holder closest to you. Work down this list in order: A fraud alert lasts a year and asks lenders to take extra steps to confirm identity; a freeze blocks new credit files outright until you lift it. Given that plaintiffs allege Social Security numbers and driver's license numbers were in scope, a freeze is the proportionate response for anyone whose dealership confirms involvement.
- Identify the dealership that held your file — the one that processed your purchase, financing, service or employment — and ask directly whether its CDK-hosted records were involved and whether it issued its own notice.
- Check your state attorney general's breach registry rather than a claim-aggregator site; Maine's is the data security breach program, and most states run an equivalent searchable list.
- If your dealership confirms involvement, or you bought or financed a vehicle during the mid-2024 window and cannot get a clear answer, place a fraud alert or a credit freeze. A freeze is the stronger of the two and is free at each of the three bureaus.
- Keep the Greenberg Traurig contact from the Maine filing on hand if you need a verification route tied to the official notification rather than to a third party.
Frequently Asked Questions
Did CDK Global notify affected consumers directly?
No mass consumer notice was issued. The only official notification publicly attached to the event is CDK's filing with the Maine Attorney General, which listed 36 persons affected including one Maine resident.
Why do the lawsuit figures and the regulator filing differ so much?
They measure different populations. The Maine filing reports CDK's directly notifiable count, while the consolidated federal litigation concerns records held across the roughly 15,000 dealerships that ran CDK's software.
Was the ransom paid?
CDK has never publicly confirmed paying. Blockchain-tracing reporting found that roughly 387 bitcoin, about $25 million, moved on June 21, 2024 to an account controlled by actors affiliated with BlackSuit.
Is BlackSuit still operating?
Its infrastructure was seized in July 2025 by Operation Checkmate, an ICE-led action with partners in eight countries, followed by a DOJ cryptocurrency seizure announced August 11, 2025.
You Might Also Like
- Cybersecurity — UnitedHealth Breach Investigation Guide: Evidence, Notices, and Verification
- Cybersecurity — TransUnion Breach Investigation Guide: Evidence, Notices, and Verification
- Ransomware Attacks Explained for 2026: Who It Affects, Key Evidence, and What to Do Next