Auto Dealership Cybersecurity: 5 Essential Practices to Protect Customer Data

Updated September 8, 2026
Auto dealerships are high-value targets. Social security numbers, credit applications, bank details, and driver's licenses flow through every transaction. Attackers know it. In June 2024, a cyberattack on a major automotive technology provider shut down operations at more than 15,000 dealerships for days, exposing how fragile the industry's digital infrastructure can be. The fallout was immediate: lost revenue, stalled deals, and damaged customer trust.
Auto dealership cybersecurity is a business-wide responsibility, and the threat is growing. One in five dealerships reported being targeted in 2025, with phishing and ransomware remaining the top attack vectors, according to CDK's State of Dealership Cybersecurity 2025 study. Customers who experience a data breach at a dealership are unlikely to return. Lost trust doesn't show up on a balance sheet. Lost revenue does.
Key takeaways
- Cybersecurity is a leadership issue, not an IT issue. When dealership principals treat it as a named priority, the entire organization shifts.
- Ransomware recovery depends on tested backups. Having a backup is necessary but insufficient. If you haven't tested restoration, you don't know whether the backup works.
- Password reuse is one of the most common entry points for attackers. A password manager paired with multi-factor authentication (MFA) closes that gap across your DMS, CRM, and email systems.
- Business Email Compromise (BEC) attacks don't rely on malware, which means standard security tools won't catch them. Employee training is the primary defense.
- The FTC Safeguards Rule classifies auto dealerships as financial institutions and requires a documented cybersecurity program. Compliance is not optional.
- Network security protects your infrastructure. Identity verification at the transaction level protects the deal itself, from credit applications to title transfers.
Why auto dealerships are prime cybersecurity targets
Auto dealerships collect more sensitive personal and financial data per transaction than most businesses. A single vehicle purchase generates a credit application, a driver's license scan, bank account details, and a social security number. Multiply that across hundreds of transactions per month and the exposure is significant.
Attackers view dealerships as high-value, relatively accessible targets. Only 30% of dealers employ a network engineer with computer security certifications or training, according to a Total Dealer Compliance survey. That gap between the value of the data and the maturity of the defenses is exactly what cybercriminals exploit.
The threat landscape for dealerships includes:
- Ransomware that can shut down your DMS and halt all sales activity
- Phishing campaigns that use leaked credentials sourced from the dark web
- Business Email Compromise targeting finance and insurance departments
- Third-party vendor compromise through DMS providers, CRMs, and integrations
- Synthetic identity fraud at the point of signing or financing
The FTC Safeguards Rule, updated in 2021 and amended in 2023, classifies auto dealerships as financial institutions under the Gramm-Leach-Bliley Act. That means every dealership in the U.S. is legally required to maintain a comprehensive written information security program. The FTC's June 2025 guidance document outlined 10 required elements, including written risk assessments, employee training, third-party vendor oversight, and a documented incident response plan.
Non-compliance exposes dealerships to federal penalties, mandatory breach disclosure, and legal action from affected customers.
The real cost of a dealership data breach
The financial and reputational damage from a breach extends well beyond the immediate recovery costs. Here is what the timeline actually looks like.
Hour 1. Your IT contact notices something wrong. Customer data has been compromised. No one knows who is responsible for what. Should you call your attorney? Contact customers? Notify regulators? While the team debates, the breach continues.
Days 1 to 2. You are racing against state and federal notification deadlines. The FTC now requires notification within 30 days of a breach affecting 500 or more customers. Attorneys are expensive, and every consultation reveals another requirement you weren't aware of.
Week 1. The breach becomes public record. Local media covers it. Competitors mention it to mutual customers. Your reputation in the community, built over years, takes a direct hit.
Months later. Legal action from affected customers begins. Insurance rates increase. Customers who have been loyal for years quietly take their business elsewhere. Some dealerships never recover.
The data on customer behavior is stark. Research consistently shows that 84% of consumers say they would not purchase another car from a dealership whose data was compromised. Reputation is one of the only differentiators between dealerships selling the same vehicles at similar prices. A breach removes it.
5 auto dealership cybersecurity best practices
1. Build a culture of cybersecurity
Annual check-the-box training doesn't work. Lessons fade within weeks, and employees return to old habits.
The shift starts at the top. Dealership leaders need to make cybersecurity a named priority and communicate it clearly and consistently. When leadership treats security as a core operational value, the entire organization responds differently.
Embed security into the rhythm of the dealership:
- Include a two-minute cybersecurity tip at every weekly team meeting. One real-world example per week lands better than an annual slide deck.
- Share what a single incident actually costs. Downtime, lost deals, customer attrition, legal exposure. Make it tangible so every department understands the stakes.
- Run simulated phishing campaigns and recognize employees who flag suspicious messages before clicking.
- Post clear escalation steps so anyone who spots something suspicious knows exactly who to contact.
The goal is to make security awareness automatic, not episodic.
2. Back up dealership data and test the backups
Ransomware continues to be a top threat to auto dealerships. A complete, tested backup gives your dealership the ability to restore operations without paying a ransom. Backed-up data removes the leverage attackers count on.
Backing up is necessary but not sufficient. Most dealerships have never actually tested their incident response plan. Problems in the backup process, whether a missed step or an improperly configured automated backup, only surface when you try to restore. If the plan hasn't been tested, you won't know it's broken until you need it most.
Run through your incident response plan before an attack forces you to. Test the restoration process on a scheduled basis. Document the results.
3. Use a password manager and require MFA
Dealership employees log into multiple systems throughout the day, often across laptops, phones, and tablets. The result is a sprawl of credentials that becomes nearly impossible to manage securely. Many employees reuse the same password across systems, which gives attackers easy lateral movement once a single credential is compromised.
A password manager solves this problem. Employees use one strong master password to access all their systems, while the manager generates and stores unique, complex passwords for each site. This removes the convenience argument for password reuse.
Strong passwords alone are not enough. Pair them with multi-factor authentication (MFA) on every system that supports it, especially your DMS, CRM, and email. MFA adds a second verification step, such as a push notification or one-time code, so a stolen password cannot unlock an account on its own. CISA lists MFA as one of the most impactful steps any organization can take to improve its security posture.
4. Train employees to recognize phishing and BEC attacks
Phishing is one of the most reliable attack vectors against automotive businesses. Cybercriminals use credential dumps as the starting point for campaigns, targeting employees whose login details have already surfaced on the dark web. Your exposure may be larger than you realize.
Beyond standard phishing, Business Email Compromise (BEC) is a growing and particularly dangerous threat. In BEC attacks, a criminal impersonates a vendor, executive, or lender to redirect payments or extract sensitive information. These attacks look completely legitimate and don't rely on malware, which means traditional security tools won't catch them.
Common tactics to watch for:
- Messages from companies or vendors the dealership doesn't work with
- Email addresses that don't match the sender's claimed organization domain
- Urgent requests to download files, click links, or redirect payments
- Emails impersonating a manager, vendor, or lender with slightly altered display names
- AI-generated phishing messages that are grammatically polished and contextually specific
What you can do:
- Share real examples of phishing emails with your team on a regular basis
- Create a clear checklist for employees who suspect a phishing email, including who to contact internally
- Make one rule non-negotiable: do not click any links, open attachments, or reply to the message until it has been verified through a separate channel
- Run simulated phishing campaigns and recognize employees who flag suspicious messages
5. Implement a formal patch management program
Software updates patch the vulnerabilities attackers exploit. Cybercriminals actively target organizations that delay applying fixes, and unpatched systems are routinely exposed to known, patchable vulnerabilities. The risk compounds as attackers share exploit kits across networks.
The same risk applies to personal devices employees use for work. Phones and tablets that haven't been updated create entry points your IT team may not have visibility into.
Create a formal patch management program with a documented process and checklist for your IT department. As your dealership adopts new platforms, integrations, or devices, update your security policies to match. Send reminder communications when major software updates are released and make clear that applying those updates to personal devices is expected.
The identity layer most dealerships are missing
Network security protects your infrastructure. It does not protect the deal itself.
Every auto transaction involves a moment where someone claims to be a customer, a co-signer, or a lender representative. Firewalls and antivirus software cannot verify whether the person signing a credit application or authorizing a wire transfer is actually who they claim to be. That gap is where synthetic identity fraud, forged signatures, and BEC-driven payment redirection happen.
The FTC Safeguards Rule requires dealerships to protect against unauthorized access to customer information. Identity verification at the transaction level is a direct response to that requirement. When identity is confirmed before documents are signed, fraud signals are monitored in real time, and every completed transaction produces a cryptographic record, the dealership holds defensible evidence that can survive a dispute or a regulatory audit.
This is where Proof fits into the auto dealership security stack. With identity verification and document security tools built for auto workflows, Proof adds a protection layer at every transaction touchpoint, from credit applications to title transfers. Every completed transaction produces a tamper-proof record that can't be forged or disputed.
The cost of a breach goes well beyond the recovery bill. It's the deals that stall, the customers who don't come back, and the days of downtime your team can't afford. The five practices above address the infrastructure risk. Identity verification at the transaction level closes the gap that infrastructure security leaves open.














































.jpg)





























































.jpg)



























