CDK Global pays $25 million in Bitcoin to end ransomware attack

In June, a ransomware group linked to the cyberattack on CDK Global received more than $25 million in Bitcoin, according to on-chain investigator ZachXBT. The attack last month disrupted CDK Global’s software, impacting approximately 15,000 US car dealerships.

CDK Paid 387 BTC to End Cyberattack 

According to ZachXBT, an address associated with BlackSuit received a 387 BTC payment on June 21. The funds were subsequently transferred to multiple centralized exchanges. BlackSuit, which surfaced in 2023, has gained notoriety for targeting US companies with ransomware attacks.

This payment corroborates an earlier Bloomberg report indicating that CDK Global intended to pay a ransom to prevent its data from being publicly disclosed. The company agreed to pay tens of millions to accelerate its system recovery.

However, CDK has not officially confirmed whether the ransom was paid. Instead, it reported that nearly all of its 15,000 car dealership customers were back online last week.

Ransomware entails deploying malware that restricts access to computer systems or data and demands ransom, typically in cryptocurrency, for its release. According to blockchain analysis firm Chainalysis, payments from crypto-related ransomware attacks nearly doubled to over $1 billion in 2023.

Source: Chainalysis

The analytics company highlighted that one extortion group called “cl0p” earned close to $100 million in ransom payments during the period. The group exploited the file-sharing software MOVEit.

Chainalysis commented that the ransomware landscape is not only widespread but also growing, posing challenges in monitoring every incident or tracing all cryptocurrency ransom payments. They noted an increasing number of new participants drawn by the prospect of substantial profits and relatively low entry barriers.

Reports suggest that the group Black Basta extorted over $107 million in Bitcoin, with a significant portion of these laundered ransom payments directed to the sanctioned Russian crypto exchange, Garantex. In a separate incident reported by BeInCrypto, hospitals across Romania were targeted by a Bitcoin ransomware attack in February, demanding 3.5 BTC as ransom.

These notable cases prompted federal agencies such as the US Federal Bureau of Investigation (FBI) to issue multiple advisories regarding these malicious actors.

The FBI recommended, “Regularly update and patch software and applications to their latest versions and perform routine vulnerability assessments.”

Related Posts