auto dealer in black and red logo
MenuMENU
SearchSEARCH

Island Hopping Is a Compliance Concern

Hackers are using weak links in vendor and supply chains to target more secure networks. Here’s what agents and dealers need to know.

by Robert J. Wilson, Esq.
February 28, 2020
Island Hopping Is a Compliance Concern

Hackers are using weak links in vendor and supply chains to target more secure networks. Here’s what agents and dealers need to know. 

4 min to read


The phrase “island hopping” conjures up pleasant visages of sunset cruises, swaying palm trees, cool trade wind breezes and icy cold tropical beverages, right? Island hopping in the compliance space creates a significantly less appealing scenario.

Your dealers must be doubly sure that the “islands” connected to their business, their supply chain, and access vectors are just as secure as the dealership.

Ad Loading...

Island hopping is a term for a cyberattack in which the target (“island”) is not the ultimate goal, but just a steppingstone (or an island “hop”) on the way toward the ultimate target. 

Hackers focus their attack on the ultimate target’s partner network and look for smaller more vulnerable affiliates of the ultimate partner, frequently in the ultimate target’s supply chain. Once they gain access to the affiliate’s computer network they “island hop” into the ultimate target’s network. This is the modern day version of an attack against the “weakest link in the chain.” Recently published reports indicate that island hopping is present in 50% of all attacks.

It Was Our Contractor

One of the most well-known island hopping attacks involved Target. There, the cybercriminals hacked into Fazio Mechanical’s computer network with an email malware attack. Fazio was Target’s HVAC contractor. 

According to some reports the only security deployed by Fazio was a free antivirus program. Once in the Fazio’s computer network, the hackers were able to gain access to Target’s vendor payment portal and from there they were able to hack into Target’s network containing point-of-sale data and obtain credit card and personal data on more than 40 million ­consumers.

Ad Loading...

The Safeguards rule requires the maintenance of “physical, electronic and procedural safeguards to protect the confidentiality and security” of collected information. Some businesses ignore this clear mandate and take no action to protect their client data and to protect their own business. 

Some businesses take moderate action to secure their own facility but no action outside the “four walls” of their business. The problem with this approach, is that the digital marketplace exponentially expands the areas, which must be safeguarded.

If you consider your dealer clients’ customer records as the “target island,” what other “islands” are available for hackers to exploit on their way toward that valuable data? Consider the following diagram:

Each of the listed vectors potentially have access to your customer data. What steps have your dealers taken to prevent an island hopping attack on their businesses? As part of your duty to safeguard client data, have they done due diligence on their vendors, do they have access controls on their network, and are employees trained to detect phishing and social engineering attacks? 

All businesses suffer “compliance fatigue.” The headlines seem to be a relentless parade of data breaches, hacking exploits, and episodes of ransomware being deployed against municipalities, hospitals, and businesses. Your dealers must be proactive and fight compliance fatigue with a compliance management system. In Target’s case, the failure to safeguard client data resulted in an $18.5 million payment to resolve state-level investigations conducted in 47 states and the District of ­Columbia. 

Ad Loading...

Be sure to enjoy scenic island hopping on your next vacation. But know your dealers must be doubly sure that the “islands” connected to their business, their supply chain, and access vectors are just as secure as the dealership — or be prepared, like Target, to write a very large check!

DISCLAIMER: Content provided in this article is intended for informational purposes only and should not be construed as legal advice and should not be relied upon or acted upon without retaining counsel to provide specific legal advice based upon your particular situation, jurisdiction and circumstances. No duties are assumed, intended or created by this communication. No attorney/client relationship is being created by your review or use of this ­material.

© 2019 Robert J. Wilson, All Rights Reserved

Robert J. Wilson, Esquire (Bob) is a Philadelphia lawyer and is General Counsel for ARMD Resource Group. Bob is the principal of Wilson Law Firm and has over 30 years of experience both as a counselor and as a litigator in State and Federal Courts. Risk management, problem solving and dispute resolution are his core competencies. Bob’s practice is largely in the consumer finance space and he regularly consults with Lenders and contributes articles on various compliance related issues.

Read: The $2.5 Million Dollar Hard Pull

Originally posted on Agent Entrepreneur

Subscribe to Our Newsletter

More Industry

Dealer Debrief, 04/23/2026, with Lauren Lawrence, Auto Dealer Today
Industryby Lauren LawrenceApril 23, 2026

Dealer Debrief: Ford HQ and Mercedes Studios

In this week's debrief, host Lauren Lawrence covers Ford HQ renovations, new Mercedes studios, and the state of auto loans in March.

Read More →
Dealer Debrief 04/15/2026 with Lauren Lawrence
Industryby Lauren LawrenceApril 17, 2026

Dealer Debrief: Exploding Airbags & Risk Management

In this week's Dealer Debrief, host Lauren Lawrence covers a potential air bag ban and reinsurance and risk management.

Read More →
Sue Bai and Brian Bautsch standing on a road
Industryby Lauren LawrenceApril 17, 2026

Pilot Program Meant to Improve Roadway Safety

Honda and the Ohio Department of Transportation achieved highly accurate results with their pilot project the Honda Proactive Roadway Maintenance System that concluded this year.

Read More →
Ad Loading...
Line graphic showing Cox Automotive's March Credit Availability Index status
Industryby Hannah MitchellApril 13, 2026

Auto Lending Opens Up in March

Lenders loosened access for subprime borrowers, and consumers with negative equity reached a record high, Cox Automotive reported.

Read More →
Photo of the facade of one of Mercedes' new city studios, with a vehicle displayed in the window
Industryby Hannah MitchellApril 13, 2026

Mercedes Opens ‘Studios’ in Select Cities

The shops help mark the automaker’s beginnings 140 years ago and are to designed to offer major urban center consumers ‘exclusive’ experiences.

Read More →
rendering of outside of Ford's World Headquarters South connection to the new World Headquarters complex
Industryby Lauren LawrenceApril 10, 2026

Ford Expands HQ Facility Renovations

The automaker's renovated Product Development Center, World Headquarters South, will be connected to the World Headquarters complex it opened in November.

Read More →
Ad Loading...
Photo of white 2026 Ford Bronco on a sandy beach
Industryby Hannah MitchellApril 10, 2026

March New-Vehicle Sales Don’t Reflect War

Cox Automotive data shows Americans doubled down on big-is-better despite price increases. Slightly higher incentives helped fuel the demand.

Read More →
Dealer Debrief 04/08/2026 with Lauren Lawrence. Auto Dealer Today logo
Industryby Lauren LawrenceApril 8, 2026

Dealer Debrief: Loan Terms & Service Drives

In this week's Dealer Debrief, host Lauren Lawrence covers extended loan terms, a service technician initiative, and the DOWC Fix it Forward Program.

Read More →
front of Porsche Des Moines car dealership
Industryby Lauren LawrenceApril 2, 2026

Auto Group Acquires Porsche Rooftop

Family-owned and operated Ed Morse Automotive Group has added Porsche Des Moines to its Iowa locations.

Read More →
Ad Loading...
Photo of Lexus of Warwick car dealership exterior
Industryby Hannah MitchellMarch 27, 2026

Lexus Dealership Changes Hands

The addition of a coveted brand, picked up from Penske Automotive, makes 15 total stores for a family-owned auto group in the Northeast.

Read More →