In this special edition of Cyber Playbook for Business, Corey Bilton speaks directly to dealership principals, owners, GMs, controllers, and fixed ops leaders about the risk that’s changing auto retail: you don’t have to be “hacked” to be hurt.
When your operation runs on centralized platforms, DMS, marketplaces, and enterprise back-office systems, one vendor incident can become a one-to-many disruption that hits your store’s ability to sell, service, and get paid.
Corey breaks down three ecosystem-level cyber events tied to dealership and auto-marketplace associated companies since 2024:
CDK Global ransomware (June 2024): the “single vendor, thousands of dealers” outage moment
Oracle E-Business Suite zero-day tied to Cox Enterprises/Cox Automotive-related operations (Aug–Oct 2025 timeline): enterprise compromise, delayed detection, data exposure risk
CarGurus breach listing (February 2026): large-scale marketplace data exposure that can be weaponized for phishing, impersonation, and fraud
Then, he delivers a practical owner’s playbook: the questions to ask vendors, how to build a real “manual mode” binder, how to harden identity and privileged access, and a clear 30-day course-correct plan to reduce downtime, blast radius, and recovery time.