FTC: DealerBuilt Hack Affected 130 Dealerships
A 2016 cyberattack laid bare the personally identifiable information of about 12.5 million customers of 130 U.S. dealerships, according to a Federal Trade Commission bulletin announcing a consent agreement with dealer software provider DealerBuilt.

In 2016, a hacker accessed the personal data of about 12.5 million U.S. dealership customers and posted more than 69,000 of those records online over a 10-day period. The breach would be traced to a cybersecurity lapse blamed on dealer software provider DealerBuilt.
Photo by Génesis Gabriella via Pixabay
WASHINGTON — The Federal Trade Commission announced it has reached a consent agreement with LightYear Dealer Technologies, better known to the U.S. auto retail industry as DealerBuilt. The action is related to a 2016 incident in which a hacker accessed the records of about 12.5 million customers who had done business with 130 DealerBuilt dealerships nationwide.
“The firm’s poor data security practices led to a breach that exposed the personal information of millions of consumers,” the FTC’s statement reads, in part, noting the company “failed to implement readily available and low-cost measures to protect personal information it obtained from its auto dealer clients.”
The hacker posted a 69,283-customer sampling online over a 10-day period. The breach was initially discovered by one of the affected customers, spurring investigations at the federal and state levels. FTC officials said personally identifiable information such as names, dates of birth, Social Security numbers, and bank accounts was “stored and transmitted in clear text, without any access controls or authentication protections.”
The breach was eventually traced back to a DealerBuilt employee who connected an unsecured external storage device to the company’s backup network and left it there for 18 months. “The company never performed any vulnerability scanning, penetration testing, or other measures that would have detected the vulnerability,” according to FTC officials.
The consent agreement precludes DealerBuilt from transmitting or storing personal information until “reasonable data access controls” that meet the standards of the Gramm-Leach-Bliley Act’s Safeguards Rule are confirmed to be in place. Any violation of the agreement could result in severe financial penalties.
DealerBuilt CEO Michael Trasatti told Automotive News the company acted quickly when the breach was discovered three years ago and has been attacking potential vulnerabilities ever since.
“We take securing customer data seriously,” Trasatti said. “We work to continuously improve our security.”
To read the FTC’s statement in its entirety, click here.
Originally posted on Auto Dealer Today
More Compliance

Dueling Banjos in the Car Biz
Reports and accounts at variance show auto dealers’ trust profiles have risen in many consumers’ minds but that there remains a need for greater transparency by some.
Read More →
NADA and the Miracle on 34th Street
Automotive dealers should follow the National Automobile Dealers Association's consumer-friendly guidelines in order to minimize their legal risks.
Read More →
Another Look at a Recent Data Breach
Get caught up on the most pressing legal and regulatory matters facing dealers and F&I professionals, including data security, shotgun purchases, and inconsistent payment quotes.
Read More →

The Best Thing a Dealer Can Do to Avoid Legal Problems
Citing the issue is a strategy borrowed from the legal field itself.
Read More →
Fines of the Times
Civil penalties for noncompliance with federal auto retail and finance rules and regulations can add up quickly. Use this checklist to cover your bases.
Read More →
Goodwill and Car Dealers
A dealer goodwill tale is a cautionary tale worth paying attention to.
Read More →
The Regulatory Empire Is Striking Back
President Trump - entropist and corporate disruptor in consumer law
Read More →
How to Clear a Red Flag
Refine and enforce your dealership’s FTC-mandated ID theft-prevention program to ensure no transaction goes awry.
Read More →
