auto dealer in black and red logo
MenuMENU
SearchSEARCH

Why do Cybercriminals Target Auto Dealerships?

Cyberattacks are happening fairly frequently, and dealerships are prime targets because they have exactly what cybercriminals are looking for, and because their IT systems and policies may not be a top priority. Take the necessary steps to protect your customer data, your bank accounts, and your reputation.

by Erik Nachbahr
August 12, 2020
Why do Cybercriminals Target Auto Dealerships?

Cyberattacks are happening fairly frequently, and dealerships are prime targets because they have exactly what cybercriminals are looking for, and because their IT systems and policies may not be a top priority. Take the necessary steps to protect your customer data, your bank accounts, and your reputation.

Image by Gerd Altmann from Pixabay 

4 min to read


I’m often asked how many dealerships have experienced a data breach, hack, or cyberattack. The answer is, “no one knows for sure.” Because, understandably, most dealers that have experienced this type of attack don’t want to talk about it publicly.

Just because auto dealers are prime targets for cybercriminals, doesn’t mean your dealership has to become their next victim.

Ad Loading...

But whenever I’m speaking somewhere, multiple dealers reach out to me afterwards to tell me their stories about how they have, in fact, experienced a breach or cyber theft. Just recently, I heard about a dealership employee who was scammed into wiring $75,000 to a cybercriminal’s bank account.

My belief is that cyberattacks are happening fairly frequently, and auto dealerships are prime targets because they have exactly what cybercriminals are looking for, and because their information technology (IT) systems and policies tend to be outdated, or not a top priority.

What Do Cybercriminals Want?

Like most criminals, cybercriminals are motivated by money, and go about getting it in one of several ways.

One way is to steal your customer data and sell it on the dark web. Auto dealerships have vast amounts of customer data contained in their technology systems, including credit applications, credit scores, bank account information, and social security numbers.

Ad Loading...

Another common way to steal money is wire fraud. This is most often perpetrated by a sophisticated phishing scheme, where a cybercriminal poses as a senior executive and sends someone in the accounting office a “spoofed” email containing a wire request. To the accounting person, the email and request appear to be legitimate, so they wire the money.

Cyber criminals can also gain access to a dealership’s bank accounts by installing a type of malware that tracks the keystrokes of computer users. If a user has access to your dealership’s bank account, the cybercriminal simply waits until they login and captures the login credentials. Once they have this information, the cybercriminal transfers money out of your account. Fortunately, this type of theft is becoming less common with the increasing usage of two-factor authentication to verify all bank logins.

Outdated IT Systems and Policies

As a whole, auto dealers tend to lag behind other industries when it comes to investing in their IT systems, making them more vulnerable to attacks. According to Total Dealer Compliance, only 30% of dealers employ a network engineer with computer security certifications or training, and more than 70% of dealers are not up to date on their anti-virus software.

Many dealerships also use outdated software, such as the Windows 10 operating system. This makes them incredibly vulnerable to cyberattacks, since Microsoft is no longer issuing security patches for Windows 10, making it easy for hackers to gain access to your network.

Ad Loading...

Since 91% of all data breaches start with a phishing attack, it’s essential for dealers to train their employees on how to identify and avoid phishing emails. Enrolling employees into an automated security awareness training program is by far the most effective way to prevent a data breach.

It’s also critical that every dealership has a set of written policies and standards regarding its IT operations. These include:

  • Incident Response Plan: If a data breach or cyberattack occurs, do you know how to respond? This plan details the steps that should be taken, the people that need to be involved, and what should be communicated to whom.

  • Acceptable Use Policy: This set of rules establishes guidelines for how the IT environment may be used.

  • Minimum Access Policy: This defines the minimum-security requirements for devices and user access to the network, including rules for password complexity, authentication standards, and specifics around patching and anti-virus software.

  • Data Classification Standards: A list of data and assets that are sensitive and critical to the organization (such as customers’ personal and private information, financial data and any trade secrets), where this data resides, how it should be handled, and who requires access.

Additionally, every dealership should purchase some type of cyber liability or data breach insurance, which offers financial protection in the event of a successful breach or attack.

Just because auto dealers are prime targets for cybercriminals, doesn’t mean your dealership has to become their next victim. Take the necessary steps today to protect your customer data, your bank accounts, and your reputation.

Ad Loading...

Erik Nachbahr is president and founder at Helion Technologies.

Read: Final Week to Vote for 2020 Dealers' Choice Awards

Subscribe to Our Newsletter

More Digital

Scott Worthington, vice president of product management at Reynolds and Reynolds, stands indoors in front of large windows wearing a navy blazer and white shirt.
Digitalby StaffMarch 3, 2026

Reynolds, Corpay Partner to Enhance Dealership Payables

The new connection between the companies is designed to help digitize payments, targeting smoother transactions for automotive dealers.

Read More →
Headshot of Zach Shefska, CEO of CarEdge, alongside the CarEdge logo on a blue background.
Digitalby StaffFebruary 24, 2026

Free Public Scoring System Rewards Honest Dealer Prices

CarEdge Dealer Transparency Index is based on verified quotes, and retailers can be rewarded with badges and other marketable proofs of honest pricing.

Read More →
Graphic promoting StoneEagle at the 2026 NADA Show in Las Vegas, featuring a photo of CEO Cindy Allen.
Product & Technologyby StaffJanuary 20, 2026

StoneEagle to Unveil Next-Gen F&I Solutions at NADA

Empowering the F&I office through data is central to the company’s reimagined solutions it's scheduled to debut soon.

Read More →
Ad Loading...
Digitalby Hannah MitchellJanuary 9, 2026

Automaker Websites Valuable Tools

The majority of shoppers visit them, and most undecided consumers consider the brands whose sites they peruse, but some automakers emphasize brand over product detail.

Read More →
Product & Technologyby Hannah MitchellNovember 25, 2025

AI-Guided Car-Shopping Insight

Consumers say they’re using the tech, but many still end up at dealerships to seal the deal.

Read More →
A smartphone displaying a Hertz Car Sales online listing sits beside the Cox Automotive logo, illustrating Cox’s new omnichannel car-buying platform.
Digitalby StaffNovember 11, 2025

Omnichannel Car-Buying Platform Launches

Cox Automotive says the technology enables online transactions on client sites and third-party marketplaces simultaneously.

Read More →
Ad Loading...
Digitalby Hannah MitchellOctober 31, 2025

Audi Drivers Can Ditch That Pesky Manual

Updated mobile app features AI assistant for tech questions, EV tasks and more

Read More →
Digitalby Hannah MitchellOctober 24, 2025

GM Cars to Get Smarter Over Time

Automaker announces single vehicle computing system to connect lineup for faster updates

Read More →
Shawn Concannon, president of TSD Mobility Solutions, stands inside a modern office building, representing TSD’s continued growth in connected-fleet technology.
Digitalby StaffOctober 14, 2025

TSD Mobility Acquisition to Bolster Telematics

Latest addition expands connected-fleet technology, strengthening telematics capabilities and global reach

Read More →
Ad Loading...
Digitalby Hannah MitchellSeptember 5, 2025

Cyber Threats Continue Apace

Hackers, seeing auto retail vulnerabilities in 2024 CDK incident, are taking advantage, data show.

Read More →