{
  "id": "case-cdk-global-blacksuit",
  "slug": "cdk-global-blacksuit-ransomware",
  "title": "CDK Global BlackSuit Ransomware Incident",
  "summary": "Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.",
  "case_number": "1:24-cv-05231",
  "court": "U.S. District Court for the Northern District of Illinois",
  "district": "N.D. Ill.",
  "country": "United States",
  "opened_at": "2024-06-19",
  "status": "alleged",
  "victim_sector": "Information Technology, Retail, Automotive",
  "victim_country": "United States",
  "loss_amount_usd": 1000000000,
  "loss_amount_note": "Over $1 billion in delayed auto sales, franchise operational disruption, and an estimated $25M (387 BTC) ransom payment.",
  "first_seen_at": "2024-06-18T00:00:00Z",
  "last_updated_at": "2026-09-01T00:00:00Z",
  "actor_slug": "blacksuit-gang",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Attackers gained access to CDK enterprise networks using compromised administrator credentials, bypassing secondary verification checks.",
      "evidence_locator": "Class Action Complaint: 1:24-cv-05231 (N.D. Ill.)",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Court Docket: 1:24-cv-05231",
      "source_url": "https://www.courtlistener.com",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "BlackSuit ransomware payloads encrypted virtualized database instances, dealer inventory feeds, and customer relationship management clusters.",
      "evidence_locator": "CISA & FBI Joint Advisory AA24-220A (BlackSuit)",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-220A",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1490",
      "evidence_excerpt": "The ransomware deleted Volume Shadow Copies and backup catalogues, crippling initial automated recovery attempts and forcing a secondary blackout.",
      "evidence_locator": "CISA Advisory AA24-220A Technical Details",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Technical Analysis",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Inhibit System Recovery",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-06-19",
      "description": "CDK Global detects BlackSuit ransomware executing across core servers and shuts down systems."
    },
    {
      "event_type": "incident",
      "event_date": "2024-06-20",
      "description": "A second encryption wave triggers during restoration efforts, shutting down dealership services again."
    },
    {
      "event_type": "ransom_payment",
      "event_date": "2024-06-25",
      "description": "CDK Global transfers 387 Bitcoin (approx. $25M) to a BlackSuit extortion address to obtain decryptor."
    },
    {
      "event_type": "recovery",
      "event_date": "2024-07-04",
      "description": "Core dealer management system services are restored to nearly all 15,000 dealerships."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversaries gained initial ingress to CDK Global internal network infrastructure via compromised administrative credentials, subsequently establishing an undetected command foothold.",
    "blast_radius": "Shutdown of CDK dealer management systems utilized by approximately 15,000 car dealerships in the United States and Canada. Dealerships were unable to process new vehicle purchases, register titles, order replacement parts, or service vehicles for nearly two weeks. Industry sales losses estimated in the billions, with an estimated $25M ransom payment.",
    "kill_chain": [
      {
        "phase": "Initial Ingress",
        "title": "Compromised Administrative Credentials",
        "description": "BlackSuit ransomware affiliates authenticated to internal CDK management subnets using valid administrator credentials that lacked second-factor validation.",
        "technical_artifacts": [
          "Compromised administrator accounts",
          "RDP sessions",
          "VPN gateway logs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Defense Blindfolding",
        "title": "Shadow Copy Deletion and Security Agent Disablement",
        "description": "Attackers executed vssadmin commands to destroy local Volume Shadow Copies and attempted to disable host monitoring agents across hypervisor hosts.",
        "technical_artifacts": [
          "vssadmin.exe delete shadows /all /quiet",
          "bcdedit.exe /set {default} recoveryenabled No"
        ],
        "mitre_technique_id": "T1490"
      },
      {
        "phase": "System-Wide Encryption",
        "title": "BlackSuit VMware ESXi and Windows Encryption",
        "description": "Adversaries unleashed the BlackSuit encryption binary across both Windows server clusters and VMware ESXi hypervisors, encrypting database virtual disks (.vmdk) simultaneously.",
        "technical_artifacts": [
          "BlackSuit ELF/ESXi payload",
          "BlackSuit Windows binary",
          ".blacksuit encrypted file extension"
        ],
        "mitre_technique_id": "T1486"
      },
      {
        "phase": "Secondary Disruption",
        "title": "Re-infection During Premature Restoration",
        "description": "As CDK engineering teams attempted to bring backup systems online, the ransomware detonated a second time across newly exposed environments, forcing an extended blackout.",
        "technical_artifacts": [
          "Persistent registry run keys",
          "Scheduled task triggers",
          "Secondary extortion note drop"
        ],
        "mitre_technique_id": "T1053.005"
      }
    ],
    "defensive_takeaways": [
      "Isolate hypervisor management interfaces (ESXi / vCenter) completely from general corporate Active Directory domains.",
      "Implement automated immutable offline backups that cannot be modified or deleted via network administrator credentials.",
      "Conduct full forensic containment and credential revocation across all environments prior to initiating system restoration.",
      "Establish secondary out-of-band communication workflows and manual fallback protocols for critical SaaS platforms."
    ]
  }
}