auto dealer in black and red logo
MenuMENU
SearchSEARCH
Cover Feature
September 1, 2026

How A Simple Phone Call Can Cause a Dealership Data Breach

Despite the sophisticated techniques fraudsters often employ today to gain access to dealerships’ valuable information, they sometimes use a somewhat old-fashioned approach.

Adam Crowell
Photo of phone on a surface next to a window

Simple phone-based scams can be convincing to potential victims.

Credit:

Pexels/Engin Akyurt

4 min to read


It does not take a sophisticated cyberattack to cause a data breach. Sometimes, it is just a phone call.

That is what makes what’s called “vishing” attacks so effective. Someone calls, sounds legitimate, creates urgency, and asks for the right piece of information. In the moment, it feels routine. After the fact, it is anything but.

Ad Loading...

The recent CarGurus data breach is a good example. Reports point to a phone-based social engineering attack that led to unauthorized access. No complex exploit. Just a conversation that worked.

And that’s exactly why dealerships should pay attention.

Why Vishing Works

It is easy to assume such scams are obvious. In reality, they are often convincing.

Attackers know how to sound credible. They spoof phone numbers. They pose as IT support, vendors or even employees. They create urgency so the person on the other end feels like he or she needs to act right away.

In a dealership environment, where phones are constantly ringing and employees are juggling multiple priorities, that pressure can be enough.

Vishing doesn’t break systems. It relies on people doing what they think is the right thing.

Where Dealerships Are Most Exposed

Most dealerships have invested in technical safeguards, like firewalls, end-point protection and multifactor authentication, or MFA.

Vishing works around all of that. Common weak points include:

  • Sharing log-in credentials or MFA codes over the phone
  • Trusting inbound calls that appear to come from familiar numbers
  • Acting on urgent requests without verifying the source
  • New or temporary employees who have not been trained on security expectations

It only takes one call and one decision.

What Actually Helps Prevent It

Defense is not about turning employees into cybersecurity experts. It is about giving them simple habits they can rely on in the moment.

A few habits that make a real difference:

  • Never share credentials or codes over the phone. There is no legitimate reason for someone to ask for them.
  • Get off the phone and call a known number. If someone claims to be IT, a vendor or even another employee, verify it independently.
  • Slow things down. Urgency is part of the tactic. Employees should feel comfortable pausing to confirm.
  • Use internal processes. Ticket numbers, approvals or standard procedures help filter out suspicious requests.
  • Make reporting easy. If something feels off, employees should know exactly whom to contact. Most dealerships already have written information-security programs, incident response plans and other required policies. The issue is whether employees remember them when it counts.

Training Matters As Much As Policy

Short, regular reminders tend to be more effective than long annual trainings. Real-world examples help reinforce what these attacks actually look like. It also helps to make it clear that questioning a request is always acceptable.

In high-turnover environments, this has to be ongoing.

Building a Resilient Dealership

Data breaches and their fallout are an unfortunate risk of running a business these days. What was notable in the CarGurus incident was the unremarkable nature of the attack. It was just a phone call, until it wasn’t.

The next breach may or may not look like this one. But it will test the same thing: whether your people know what to do when it counts. And by offering continuous, proactive education and reinforcement, especially in a high-turnover dealership environment, you can minimize the risk of making the kind of headline that nobody wants.

The Bottom Line

The CarGurus breach did not start with a computer system failure. It reportedly started with a conversation.

Dealerships are just as susceptible. Every dealership has employees answering phones, helping customers, and handling requests throughout the day. That is when these types of attacks can happen.

You don’t always need complex IT solutions for all situations. Sometimes you just need people who know when something feels off and what to do next when it does.

Adam Crowell is the chief legal and strategy officer at KPA, which helps dealerships improve safety and stay compliant.

EDITOR’S NOTE: This article was authored and edited according to Auto Dealer Today editorial standards and style. Opinions expressed may not reflect that of the publication.

Loading data...

Ad Loading...