The auto dealers outage has been hamstringing car dealerships for days. Experts say that’s the new normal for cyberattacks

Cyberattacks seem to be more devastating than ever and taking targeted companies even longer to resolve.

The latest attack to receive wide attention continues that trend: An ongoing cyber incident at CDK Global, whose software car dealerships use to manage everything from scheduling to records, has crippled dealerships for days now, with no clear end in sight.

In May, a cyberattack on Ascension, a St. Louis-based nonprofit network that includes 140 hospitals in 19 states, forced the system to divert ambulances from several of its hospitals. It took almost a month to fully resolve the issue.

And in February ransomware attack on Change Healthcare, a subsidiary of healthcare giant UnitedHealth Group, caused billing disruptions at pharmacies across the US and threatened to put some health providers out of business.

Experts say hackers are getting more sophisticated and can hide in an organization’s systems for longer undetected. These hackers target companies in a supply chain-style attack, taking down entire industries to leverage more money. And certain industries that often use outdated systems, like healthcare, are becoming even easier targets.

“We can’t even compare what was going on ten years ago to what’s going on today,” Dror Liwer, co-founder of cybersecurity company Coro, told CNN. “(Hackers) are in the game for much bigger gains than they were before.”

Why hacks are so much more devastating

Hackers are not just more sophisticated, but they’re also more patient, Liwer said.

Hackers hide themselves inside an organization’s framework for a while, and move laterally through that framework, affecting numerous parts of the system. They wait until it’s the right time to launch attacks. And the longer the hackers wait, the bigger the damage.

“When (hackers) turn the attack on and execute, it’s truly crippling to the organization which then generates more revenue for them,” Liwer said.

Experts with whom CNN spoke said it’s difficult to get specific details on individual cyberattacks immediately. For one thing, companies want to protect their brand reputation from potential litigation. Also, organizations may not want to reveal specific details of the attack before an investigation concludes, the experts said, in case there are any copycats.

Eric Noonan, CEO of cybersecurity provider CyberSheath, said that ransomware attacks typically breach through avenues like a phishing email. These breaches can go undetected for days or even weeks as the hacker moves laterally.

The actual deployment of ransomware is often quick and widespread, Noonan said. Most victims find out they’ve been hacked once they lose access to important files or receive digital ransom notes.

“Ransomware is the digital equivalent of squatters taking over a home. The initial entry goes unnoticed allowing the squatters to occupy and control the property and by the time homeowners notice there is a problem the process for regaining control and ownership is disruptive and expensive,” Noonan said.

While companies used less interconnected systems in the past, the move to the cloud and reliance on third-party systems — despite helping daily business operations — creates complex systems that are more susceptible to widespread hacks.

“It also creates kind of a bullseye and it helps attackers focus their efforts on specific types of infrastructure or specific cloud platforms,” Noonan said.

And hackers are targeting organizations that serve in the supply chain of industries. By attacking CDK’s software, for instance, hackers were able to bring the vehicle dealership industry to a standstill. Change and Ascension, large hospital chains, were not able to provide adequate care to their many branches. That gives hackers leverage to ask for larger and larger sums of money, said John Dwyer, director of security research at Binary Defense, a cybersecurity solutions firm.

Though hackers have more leverage, the success of paying a ransom and a speedy recovery is elusive, experts said.

“There’s never been a story written on a company that successfully paid a ransom, and then quickly recovered their systems,” Noonan said.

Healthcare is an easy target

Noonan said the issue isn’t that hackers are necessarily getting more advanced, but that many organizations lack modern, up-to-date systems. Most organizations don’t do incident response exercises, which is why it’s taking longer to recover from these massive hacks.

“Much of our critical infrastructure is way behind in terms of being prepared for recognizing cyber threats when they appear, but then more importantly, recovering from them,” Noonan said.

the auto dealers outage has been hamstringing car dealerships for days. experts say that’s the new normal for cyberattacks

The UnitedHealth website on a smartphone arranged in New York, US, on Friday, July 7, 2023. - Gabby Jones/Bloomberg/Getty Images

An FBI report found that ransomware attackers targeted the healthcare and public health sector the most, followed by critical manufacturing and government facilities.

As systems become more interconnected, there is only so much a business can do to upkeep its cybersecurity – especially when relying on third party systems, like car dealerships do with CDK.

“Auto dealerships are not in the business of cybersecurity, so they aren’t really up to the task of protecting that kind of a system. It’s up to the vendor,” Cliff Steinhauer, director of information security and engagement at National Cybersecurity Alliance said.

Steinhauer also said it’s a constant game of “cat and mouse.”

“Every time we fix something, the hacker can still break it. And they only have to be right once, we have to be right every single time,” Steinhauer said.

Hospital attacks have surged. A nurse who works at Ascension Providence Rochester Hospital near Detroit, Michigan, previously told CNN that the ransomware attack on the networks is “putting patients’ lives in danger,” as healthcare workers have to resort to paper charting with a load of patients to take care of.

Others say healthcare is targeted because of the field’s aging technology, Steven McKeon, founder and CEO of software companies MacguyverTech and MacNerd, said in a release. This technology helps patients request prescription refills, view test results and schedule appointments, but is also more susceptible to hacks.

CNN has reached out to Ascension and Change for comment.

How to prevent long shutdowns

Dwyer said companies can do a better job of using third-party expertise since many internal security teams are pretty small. The best examples use an internal team that is an expert on the internal systems of the organization and hire third-party cybersecurity providers to bolster their size.

Organizations can also put into place systems that can look at security across their business, Liwer said.

Others say there should be mandatory minimum cybersecurity requirements for publicly traded companies. Those minimum standards should be viewed like seatbelts and airbags, Noonan said — they won’t prevent accidents from happening, but will better prepare companies.

“There’s many software companies or critical parts makers or parts of the supply chains that Americans have never heard of – these companies, the applications and the software or parts that they make until they’re no longer available. There’s many other CDK’s out there,” Noonan said.

CNN’s Sean Lyngaas contributed to this report.

For more CNN news and newsletters create an account at CNN.com

OTHER NEWS

21 minutes ago

Sources: Chris Paul signing free agent deal with Spurs

21 minutes ago

McLaughlin-Levrone breaks her own 400m hurdles world record

21 minutes ago

Utah inks defenseman Sean Durzi to a four-year extension

21 minutes ago

Canadiens trade Kovacevic to Devils for fourth-round pick

21 minutes ago

Bills Possess a Fantasy Football 'Sleeper' at WR for Josh Allen

21 minutes ago

Redbox Parent Company Files for Bankruptcy

21 minutes ago

Philadelphia 76ers news: Team makes first signing of NBA free agency, add 2-time All-Star

21 minutes ago

Taraji P. Henson Goes for Gold in Custom Balmain Dress on the BET Awards 2024 Red Carpet

21 minutes ago

Blues Sign Hunter Skinner to One-year, Two-way Contract

21 minutes ago

Denver Broncos all-time greatest players: No. 27 Chris Harris

21 minutes ago

Sporting News 2024 bowl projections for Rutgers

21 minutes ago

England's 'character' can't be questioned after Slovakia win, says Southgate

21 minutes ago

'If Gautam Gambhir takes the job it's...': BCCI president Roger Binny on Rahul Dravid's replacement as Team India head coach

21 minutes ago

Stranger Things' Joseph Quinn admits he's nervous about Gladiator sequel

24 minutes ago

Multiple agencies respond to large wildfire in Brazoria County

29 minutes ago

McLaughlin-Levrone runs 50.65 to break world record, qualify to defend Olympic title

29 minutes ago

Masai Russell, Alaysha Johnson silence doubters in emotional interviews

29 minutes ago

‘Peaky Blinders’ actress Charlene McKenna has secretly had first baby

29 minutes ago

Orpheus Pledger: Former Home and Away star admits brutal attack on woman

29 minutes ago

Susan Sarandon’s daughter Eva Amurri marries chef Ian Hock

29 minutes ago

Chevrolet Corvette recalled

29 minutes ago

When does “The Acolyte” take place in the Star Wars timeline?

29 minutes ago

HBO's Harry Potter Show Doubles Down on an Exciting Genre Trend

29 minutes ago

Soccer-Ipswich sign Hutchinson from Chelsea on five-year deal

29 minutes ago

One Race's Role in Zelda: Echoes of Wisdom is a Head-Scratcher

29 minutes ago

Maple Leafs sign defenseman to a two-year extension

29 minutes ago

‘He provides game-changing moments’: Southgate lauds Bellingham’s late show

32 minutes ago

CNBC Daily Open: U.S. seeks Boeing guilty plea

35 minutes ago

76ers frontrunners to sign Paul George, sources say

35 minutes ago

South Korea factory activity sees fastest growth in 26 months on rising demand

35 minutes ago

Suspending Senator Fatima from the Labor caucus was the 'right call'

35 minutes ago

Four-star EDGE and Alabama target Justin Hill announces commitment date

35 minutes ago

Soma Golden Behr, Longtime Senior Editor at The Times, Dies at 84

35 minutes ago

England keep the faith and Jude Bellingham conjures a late miracle

35 minutes ago

Jean-Luc Mélenchon will not be PM if left-wing alliance wins majority, Greens candidate says

44 minutes ago

Americans and Japanese take far less time off — but Europeans say they're more 'vacation deprived'

44 minutes ago

Michigan’s Newest Lakeside Inn Is Giving Gilmore Girls Traditional, But In The Midwest

44 minutes ago

Writing in Ancient Egypt caused hip, spine and shoulder injuries

44 minutes ago

Video: Nat Barr grills NSW Police Minister Yasmin Catley over delayed cop response to alleged DV murder of Sarah Miles in Casino

44 minutes ago

Video: Lila Moss follows in mum Kate's footsteps by visiting Glastonbury as young model wears a tassled leather jacket and biker boots for day out at Worthy Farm