Dealership Cybersecurity and Data Protection: Audit Vendors Now

Updated September 2026

Proton Dealership IT (information technology) and Cybersecurity recorded nearly a 1,000% spike in attempted attacks on dealerships in March compared with activity before June 2024, and the main entry point was software that gives third-party vendors access to troubleshoot systems, according to Car Dealership Guy News. Dealership cybersecurity and data protection now begins with one question most stores never ask a vendor: who on your team can reach our customer data?

Key takeaways

  • Attempted attacks on dealerships jumped nearly 1,000% in March versus pre June 2024 activity, and current volume is more than triple what it was two years ago (Car Dealership Guy News).
  • Multi-factor authentication (MFA) was in use 97% of the time credentials were compromised, so standard MFA is no longer a finish line (Car Dealership Guy News).
  • Average ransomware recovery now runs $1.7 million, up $200,000 in the past year, and that figure excludes any ransom paid (Car Dealership Guy News).
  • The Federal Trade Commission (FTC) updated its Safeguards Rule in 2021 and 2023, requiring dealers to implement and maintain a security program or risk heavy fines.
  • Run a vendor access inventory this month and kill logins for vendors you no longer use.

How much did cyberattacks on dealerships actually increase?

Nearly 1,000% in March compared with activity before June 2024, according to a study by Proton Dealership IT and Cybersecurity reported by Car Dealership Guy News. Activity dropped after March, picked back up in June, and sits at more than triple the level of two years ago.

The March surge came through software that allows third-party vendors to log in and troubleshoot systems. Proton said other industries were hit by the same vulnerability a year earlier, which is the part dealers should sit with. The attack path was public for twelve months before it reached the car business.

Sean Patronis, Chief Information Security Officer at Proton Dealership IT with more than 25 years in technology and information security, said his team detected the compromised third-party software before the attack started and blocked the attempts using protections put in place ahead of time. Detection beat the attack because someone was watching the vendor layer, not just the firewall.

Cybercriminals target dealers for two reasons: consumer data and scams designed to collect money. A single rooftop holds credit applications, driver license scans, bank details and service histories for thousands of households. That is a rich target sitting behind logins your store did not issue and often does not track.

Why is multi-factor authentication failing to stop dealership breaches?

Because attackers are capturing the code as users enter it. Proton found that MFA was being used 97% of the time credentials were compromised, per Car Dealership Guy News. The control was on. It did not matter.

Patronis described the mechanic plainly: many scams now try to capture the user entering the MFA code, and from that point the attacker impersonates the user. Whatever that login opens, the attacker now opens too.

His guidance is specific. Text MFA is better than email MFA. Better still is phishing-resistant MFA that uses biometrics or physical interaction, which cannot be relayed by a fake login page.

AI is what made the front end of this work. Patronis said AI has eliminated some of the old tells in phishing emails and helps criminals scrape additional information to write more convincing messages. In his words, an attacker can scrape open-source data about a person and their business and phish them directly because they know the target is a salesperson at a dealership. The typos and the odd grammar that trained your staff to hesitate are gone.

What does the FTC Safeguards Rule require a dealership to do?

The FTC updated its Safeguards Rule in 2021 and 2023, requiring in part that dealers implement and maintain security programs to keep customer information secure or risk heavy fines for incidents. Proton's summary for dealers is short: follow the rule and have a plan in place, including appointing a point person.

The appointed person matters more than the org chart suggests. When an incident hits at 6 p.m. on a Saturday, the question is who calls the vendor, who calls the insurer and who decides whether systems come down.

Patronis flagged the failure mode he sees most often: dealers buy the tool and think they are protected. He said it is not that simple, that you need expertise and knowledge from internal teams or a third party, and that training associates is a key piece because they have to spot the new phishing emails.

We are marketing and data analysts, not your compliance counsel. Work the specifics of the rule with qualified legal and IT security help.

How do I audit which vendors have access to my DMS and CRM?

Start with a written inventory, because most stores cannot produce one on demand. Six steps that fit inside a week:

  1. Pull the active user list from your DMS, CRM, website platform, inventory tool and reporting dashboards. Export it, do not eyeball it.
  2. Flag every login that belongs to an outside company rather than an employee. Name the company and the human being responsible for it.
  3. Delete anything tied to a vendor you no longer use or an employee who left. Old logins are the cheapest attack surface in the store.
  4. Document what each remaining vendor can see and do: read only reporting, full customer records, write access to deals, remote control of a workstation.
  5. Require phishing-resistant MFA from every vendor that touches customer records, and get the answer in writing.
  6. Put a review date on the calendar every 90 days and assign it to your Safeguards Rule point person.

Do this in the same meeting where you review vendor performance. You are already asking whether the agency hit cost per sale. Ask who on their team can open your customer file while you have them on the line.

What does it cost a dealership to recover from a ransomware attack?

The average cost of recovering from a ransomware attack is now $1.7 million, an increase of $200,000 in the past year, and that total does not include any ransom paid to restore accounts, as reported by Car Dealership Guy News. Patronis attributed the rise to insurance premiums, labor costs, hardware, software and firewalls, and said he expects those costs to go up again next year.

Put $1.7 million against your store's net for the year. Then add the possibility of FTC fines on top, plus the weeks your sales and service teams spend working off paper. The audit above costs a few hours of someone's time. The math is not close.

What should you ask a marketing vendor about dealership cybersecurity and data protection?

Four questions, asked of every vendor with a login. Ask them before you sign, the same way you ask about attribution and co-op eligibility.

QuestionWhat a solid answer sounds likeRed flag
Who on your team can reach our customer data?A named role list with least-privilege access and an offboarding process"Our support team" with no further detail
What MFA do you require of your own staff?Phishing-resistant MFA using biometrics or a physical keyEmail codes, or MFA that is optional per employee
How fast do you notify us of an incident?A defined window in the contract, with a named contact"We would let you know"
How is consumer data handled at rest?Encryption, stated retention limits, documented compliance postureNo answer without a call back from legal

What this means for your dealership

Dealers spend real time auditing marketing vendors for performance and almost none auditing them for access. Both audits should happen in the same meeting, with the same people in the room.

This month: build the vendor access inventory, cut the logins you do not need, and require phishing-resistant MFA from anyone who touches customer records. Then train the floor on what AI-written phishing looks like, because the old tells are gone and your salespeople are the ones being targeted by role.

Drivonic is a dealer-owned data and technology company, and we are California Consumer Privacy Act (CCPA) and Gramm-Leach-Bliley Act (GLBA) compliant. Our data foundation, IRIS℠, works from 304M+ consumer profiles and 175M+ VIN-verified records at the audience level. We do not identify individual shoppers by name to the outside world, and that distinction matters when you are the one answering to the FTC.

The same standard applies to execution. MarketBuilder℠ and ActivReach℠ run on audience segments and VIN-verified matching, not on raw customer files passed between platforms. When you evaluate any marketing partner, ask how the data moves. If nobody can explain it in one sentence, that is your answer.

Frequently asked questions

How much did attempted cyberattacks on dealerships increase?

Proton Dealership IT and Cybersecurity found nearly a 1,000% spike in March compared with activity before June 2024, reported by Car Dealership Guy News. Activity fell after March, rose again in June, and is more than triple where it stood two years ago.

Is standard MFA still worth using?

Yes, but treat it as a floor. MFA was in use 97% of the time credentials were compromised, per Proton's study. Patronis said text MFA beats email MFA and pushed clients toward phishing-resistant MFA using biometrics or physical interaction.

What does ransomware recovery cost a dealership?

An average of $1.7 million, up $200,000 in the past year, before any ransom payment (Car Dealership Guy News). Rising insurance premiums, labor, hardware, software and firewall costs are driving the number higher.

How often should we review vendor access to the DMS and CRM?

Every 90 days, assigned to the point person you appoint under the FTC Safeguards Rule. Remove logins for former employees and vendors you no longer work with the same day the relationship ends.

Why are AI phishing emails harder for staff to catch?

AI removed the old tells and lets attackers scrape open-source data about a person and their employer. The email can name the job that person does at the store, so a fake DMS or CRM login screen looks like any other Tuesday morning.

If you want a straight conversation about how your marketing data is handled and where your intelligence layer should live, schedule a demo with Drivonic.

Sources

  1. Cyberattacks on dealerships spike 1,000% in March over 2024 levels, Car Dealership Guy News

About the author

Drivonic Editorial Team

Automotive data and marketing analysts

Drivonic is a dealer-owned data and technology company with over 10 years of automotive data excellence. It turns fragmented automotive data into sales outcomes for dealerships, OEMs, Tier 2 associations and marketing agencies. The editorial team turns IRIS℠ audience data and industry reporting into practical guidance for dealership leaders.

More from Drivonic

Dominate your market and steal market share from your competition.

Schedule a strategy call
Drivonic