Cyberattacks against CDK Global, used by ~15K car dealerships, and Change Healthcare show how large swathes of some industries have a “single point of failure”
Context & Ripple Effects
CDK’s outage followed its decision to shut down most systems while investigating a cyber incident, interrupting the shared software layer used across a large dealer base. The subsequent restoration of substantially all dealer connections underscores both the scale of the dependency and the difficulty of recovering it.
The comparison with Change Healthcare broadens the issue beyond auto retail: a compromise at a central vendor can simultaneously disrupt operations and expose sensitive information across an entire customer ecosystem. Healthcare had already recorded the most publicly disclosed sector attacks in early 2023, according to Omdia’s sector tally.
First-order effects
- Dealerships reliant on CDK face disrupted sales, service, financing, and administrative workflows when the provider’s systems are unavailable.
- At Change Healthcare, the breach turns a vendor outage into a broad data-security event, affecting organizations and individuals whose records passed through its systems.
Second-order effects
- Customers of major vertical-software vendors must absorb continuity costs and reassess manual workarounds, backup access, and the concentration of critical workflows in one provider.
- Vendors serving regulated or transaction-heavy sectors face greater pressure to demonstrate incident response, recovery capability, and protections for customer data; CDK’s reported ransom payment also highlights ransomware’s financial leverage.
Third-order effects
- If organizations continue consolidating essential workflows with a small number of intermediaries, cyber resilience will increasingly be judged at the ecosystem level rather than by any single company’s defenses.
- The pattern could push buyers and policymakers toward stronger third-party risk requirements and operational-resilience planning, though the corpus does not establish what form those requirements will take.
The trend: Cyberattacks are exposing how concentration in essential industry software can turn a supplier breach into an ecosystem-wide operational and data-risk event.