• Stop being a LURKER - join our dealer community and get involved. Sign up and start a conversation.

Reply to thread

I used to work for CDK on the digital side (formerly Cobalt Group). Then it became Sincro, now Ansira. I can tell you the digital side was pretty buttoned up code wise. All solid engineering practices. I can't speak for DMS and what not, but I'm pretty confident this wasn't reckless engineering. The "smell" to me sounds like social engineering.


With some other attacks I've heard about, I think a lot of these attacks in the future are going to be social engineering exploits. I already know of a few that utilize LinkedIn to pose as members of different accounting teams to update routing numbers, invoices, etc. With AI tools, it's going to make it easier and cheaper. I think I even heard of someone using an AI generated team member on a Zoom call.