Maybe an employee's email account suddenly starts sending messages they did not write. Files are being renamed or encrypted. Employees cannot log in. Someone notices an unfamiliar sign-in. A vendor calls about suspicious activity coming from the dealership.
At that point, the first question is no longer: How do we prevent a cyberattack?
It is: What do we do right now?
If your auto dealership suspects a cyberattack, the first priorities are to get the right people involved, contain the incident without unnecessarily destroying evidence, protect compromised accounts, contact the appropriate insurance and legal resources, determine what systems and information may be affected, and give employees clear instructions about what to do next.
The exact response will depend on what happened. A compromised email account is different from ransomware spreading across several computers, and a stolen password is different from an attacker gaining access to a server.
But one principle applies to almost every incident:
Do not let a stressful situation turn into a series of uncoordinated decisions.
Here is what dealership leadership should focus on during the first 24 hours.
1. Treat Suspicious Activity as a Security Incident Until You Understand It
Not every strange computer problem is a cyberattack.
But when something looks genuinely suspicious, it deserves a different response from an ordinary help-desk ticket.
Warning signs might include employees unexpectedly being locked out, unusual MFA prompts, suspicious email activity, files becoming unavailable, ransomware messages, unauthorized account changes, unexpected remote access, or indications that customer or business information may have been accessed.
The first job is not to determine exactly what happened yourself.
It is to escalate the situation quickly enough that the right people can determine what happened.
Employees should have a clear way to report suspicious activity, and leadership should know who has authority to activate the dealership's incident-response process.
The FTC's dealership-specific Safeguards Rule guidance requires covered dealerships to maintain a written incident response plan for security events affecting customer information.
A written plan matters because the middle of an incident is a poor time to start deciding who should call IT, who should contact the insurance company, and who is allowed to make decisions for the dealership.
2. Get Your IT or Cybersecurity Response Team Involved Immediately
Once there is a reasonable concern that the dealership may be dealing with a security incident, get qualified technical help involved.
That may be your managed IT provider, internal IT team, cybersecurity provider, incident-response firm, or a combination of them.
One person should take the technical lead.
That does not mean the Dealer Principal, General Manager, or Controller gives up control of the business response. It means the dealership is not asking five different people to independently troubleshoot the same incident.
The technical team needs to begin answering questions such as:
- Which accounts or devices appear to be affected?
- Is the suspicious activity still happening?
- Is the problem isolated to one employee or spreading?
- Are other dealership locations affected?
- Is remote access involved?
- Is email compromised?
- Are servers or shared files involved?
- Is there evidence of ransomware or data theft?
- What should be isolated?
- What evidence needs to be preserved?
The FTC recommends mobilizing a breach-response team quickly and says that, depending on the organization and incident, that team can involve IT, information security, forensic specialists, management, legal counsel, operations, HR, and communications.
For dealership leadership, the important part is simpler:
Get one coordinated response started instead of letting everyone try something.
3. Contain the Attack Without Destroying Evidence
The natural reaction when a computer appears to be compromised is often:
Turn it off. Reset everything. Delete the bad email. Rebuild the computer.
Sometimes immediate isolation is absolutely necessary.
But incident response and normal troubleshooting are not the same thing.
CISA recommends isolating impacted systems in a coordinated manner during a ransomware incident. FTC breach-response guidance similarly recommends taking affected equipment offline while cautioning businesses not to simply power machines off before forensic experts can assess them. The FTC also specifically advises businesses not to destroy forensic evidence during the investigation and remediation process.
That is why the safer general rule is:
Contain first, but do not start wiping, rebuilding, deleting, or making widespread changes without coordinating with the people handling the investigation.
The appropriate action depends on the incident.
An affected workstation may need to be disconnected from the network. An account may need to be disabled. Remote access may need to be blocked. A portion of the network may need to be isolated.
Let the response team make those decisions based on what it is seeing.
Preserving information can help determine how the attacker got in, what they accessed, where they moved, and whether the dealership has actually removed them.
4. Protect Compromised Accounts and Access
Changing a password may be part of the response.
It may not be the entire response.
If an attacker already has an authenticated session, stolen authentication token, administrator account, remote-access method, or other persistent access, changing one password may not remove them.
The response team may need to review:
- Email accounts
- Microsoft 365 or Google Workspace
- Administrator accounts
- Active login sessions
- MFA settings
- Remote access
- VPN accounts
- Service accounts
- Vendor remote-access accounts
- Password resets
- Forwarding rules
- Newly created users
- Changed permissions
The FTC advises businesses responding to a breach to update compromised credentials and review who has access to affected information, including whether that access is still necessary.
For a dealership, there is another complication: not every important account is controlled by the same company.
Your IT provider may control Microsoft 365 and the computers, while the DMS provider manages DMS accounts. A CRM vendor may manage another login. OEM, lender, payroll, payment, or other systems may each have their own account controls.
That is why one person needs to coordinate the response across vendors.
This is not the time for the General Manager to hear:
“We reset the Microsoft password, so everything should be fine.”
The better question is:
What access could the attacker have had, and have we removed it?
5. Contact Your Cyber Insurance Carrier or Broker
If the dealership has cyber insurance, bring the policy into the response early.
Do not assume you know what the carrier wants simply because the dealership has gone through a renewal questionnaire before.
Review the policy's incident-reporting process and contact the carrier or broker promptly according to those requirements.
Ask practical questions:
- Who should the dealership contact to report the incident?
- Does the carrier have an incident-response hotline?
- Are specific forensic or legal providers available through the policy?
- Are there steps the dealership needs to follow before engaging outside services?
- What information should be documented?
- Who will coordinate with the carrier as the investigation develops?
The answers depend on the actual insurance policy, so the dealership should rely on its carrier, broker, and appropriate advisors rather than assumptions.
This is also why cyber insurance preparation should happen before an attack. Leadership should know where the policy is, who the broker is, and how an incident gets reported.
If your dealership is unsure what cybersecurity controls are currently in place or how accurately it can answer insurance questions, our related article What Cybersecurity Controls Do Auto Dealerships Need for Cyber Insurance? goes deeper into that preparation.
6. Bring in Legal Counsel When Appropriate
A cyberattack can quickly become more than an IT problem.
If customer information may have been accessed, there can be questions about notification, regulatory requirements, contracts, insurance, law enforcement, and communications.
Those are not decisions the IT provider should make for the dealership.
The FTC specifically recommends consulting legal counsel during a breach response because federal and state laws may apply depending on what happened and what information was involved.
For covered dealerships, there is also a federal Safeguards Rule notification requirement to consider. The FTC requires covered financial institutions to notify the agency as soon as possible and no later than 30 days after discovery of certain notification events involving the information of at least 500 consumers. Whether a particular incident meets that definition depends on the facts.
New Jersey has its own breach-notification requirements as well. Current New Jersey law requires businesses conducting business in the state that maintain computerized personal information to provide notice when qualifying personal information of New Jersey residents was, or is reasonably believed to have been, accessed by an unauthorized person. New Jersey also requires qualifying breaches to be reported to the Division of State Police before customer notification.
That does not mean every suspicious login triggers all of those requirements.
It means the dealership should determine its obligations based on the actual facts rather than making a legal conclusion during the first few minutes of the incident.
Tech Marvel can help determine what happened technically.
Qualified legal counsel should advise the dealership on what the law requires.
7. Determine What Systems and Information May Have Been Affected
One of the most important questions during a cyberattack is also one of the hardest:
What did the attacker actually reach?
Avoid both extremes.
Do not immediately say:
“It was only one email account.”
But do not immediately assume:
“They have everything.”
Investigate.
For an auto dealership, that review may involve:
- Microsoft 365 or Google Workspace
- DMS
- CRM
- Employee computers
- Servers
- Shared files
- Accounting systems
- Payroll or HR systems
- Customer financial information
- OEM portals
- Lender systems
- Remote-access systems
- Vendor accounts
- Cloud applications
- Backup systems
The technical team may need to review logs, account activity, endpoint information, email activity, network records, and other evidence to determine the scope.
FTC breach-response guidance recommends reviewing logs and preserved information to establish who had access, the type of information involved, how many people may have been affected, and whether additional access needs to be restricted.
This takes time.
Leadership may understandably want an immediate answer, but sometimes the accurate answer during the first few hours is:
“We are still determining that.”
That is better than guessing.
8. Keep the Dealership Operating - But Don't Rush Recovery
While the security team investigates the attack, the dealership still has customers and employees.
Sales may need the CRM.
F&I may need lender systems.
Service needs to keep customers moving through the department.
Parts needs access to its systems.
Accounting still has work to do.
Phones and email may be affected.
The immediate business question becomes: What can we safely keep operating?
That may involve temporary procedures, alternate systems, manual processes, or prioritizing certain departments while other systems remain unavailable.
But be careful not to confuse keeping the business moving with restoring everything as quickly as possible.
The FTC recommends consulting forensic experts and law enforcement about when it is reasonable to resume normal operations after a breach.
If the response team does not yet know how an attacker gained access, restoring affected systems too quickly can create additional problems.
The first 24 hours are therefore about controlled continuity, not simply getting every computer back online.
Once the incident is contained and the response team is ready to move into restoration, the focus changes from incident response to business recovery.
That is where our Backup Fire Drill Every New Jersey Auto Dealership Should Run article becomes the better resource. It covers recovery priorities, backup testing, vendor coordination, temporary procedures, and getting dealership operations running again.
9. Control Internal and External Communications
During a cyberattack, information can spread through the dealership faster than the investigation.
Someone tells another employee they heard “everything was hacked.”
Someone tells a customer the dealership's database was stolen.
Another employee posts something online.
Meanwhile, the response team may not yet know what actually happened.
Dealership leadership should establish a clear communication process early.
Employees need to know:
- What happened, to the extent it is currently known
- What systems they should or should not use
- Whether they should turn off, disconnect, or leave devices alone
- Where suspicious messages should be reported
- Whether temporary work procedures are in place
- Who can answer questions
- Who is authorized to communicate externally
The FTC recommends creating a breach communications plan, avoiding misleading statements, and being careful not to publicly share information that could increase the risk to affected consumers.
That does not mean hiding the incident.
It means separating known facts from speculation.
Customer, regulatory, vendor, law-enforcement, or public notifications may become necessary depending on the incident. Those communications should be coordinated with the appropriate legal, insurance, security, and leadership resources.
In the first few hours, saying: “We are investigating and will provide accurate information as we learn more” is often more responsible than trying to answer questions the dealership cannot yet answer.
10. Document What Happens From the Beginning
The incident timeline should not be reconstructed three weeks later from everyone's memory.
Start documenting early.
Record things such as:
- When suspicious activity was first noticed
- Who reported it
- What they observed
- Which computers or accounts were involved
- When IT/security was contacted
- What systems were isolated
- What accounts were disabled or changed
- Which vendors were contacted
- When insurance was notified
- When legal counsel became involved
- Important technical findings
- Business interruptions
- Decisions made by leadership
- Employee instructions
- External communications
The FTC specifically recommends documenting the investigation, and preservation of evidence is an important part of an effective breach response.
Documentation can also help the technical investigation, insurance process, legal review, regulatory response, and later discussion about what should change.
It does not need to be elegant.
It needs to be accurate.
Should an Auto Dealership Contact Law Enforcement After a Cyberattack?
Potentially, yes.
The FTC recommends notifying appropriate law-enforcement authorities following a data breach, and the FBI provides a dedicated process through its Internet Crime Complaint Center (IC3) for businesses to report ransomware, data breaches, network intrusions, and other cyber incidents.
The FBI specifically encourages ransomware victims to report incidents, regardless of whether a ransom is paid.
For New Jersey dealerships, the state's own breach requirements may also involve reporting a qualifying breach to the New Jersey State Police.
Your legal counsel, incident-response team, insurer, and law-enforcement contacts can help determine the appropriate reporting path based on what happened.
If the incident involves fraudulent wire transfers or business email compromise, speed can be particularly important. The FBI advises victims of business email compromise to contact their financial institution immediately in addition to reporting the incident to IC3.
What Should You NOT Do After Discovering a Cyberattack?
Some of the most damaging mistakes happen because people are trying to help.
Don't Start Wiping Computers
A compromised computer may contain information the response team needs.
Containment and preservation should be coordinated with the people investigating the incident. The FTC specifically advises against destroying forensic evidence during remediation.
Don't Let Everyone Troubleshoot Independently
Five people making changes simultaneously makes it harder to understand what happened and what changed afterward.
Establish one technical lead.
Don't Delete Suspicious Emails or Logs
They may provide useful evidence about how the incident started or what the attacker did.
Preserve them for the response team.
Don't Assume One Password Reset Fixed Everything
Other sessions, accounts, tokens, forwarding rules, administrator access, or remote-access methods may still need attention.
Don't Restore Everything Just Because Employees Are Waiting
The pressure to get back to work is real.
But affected systems should return to production in a controlled way after the response team has determined it is appropriate to do so.
Don't Make Public Claims Before You Know the Facts
Avoid saying customer information definitely was - or definitely was not - accessed until the investigation supports that conclusion.
Don't Forget the Insurance Policy
If the dealership has cyber insurance, follow the policy's reporting process and coordinate with the broker or carrier rather than making assumptions about coverage.
Don't Decide Notification Requirements Yourself
Federal and state requirements depend on the facts of the incident and information involved. Get the appropriate legal advice.
Who Should Be on a Dealership Cyber Incident Response Team?
Not everyone needs to be in every conversation.
But every dealership should know who fills the important roles.
Depending on the incident, that may include:
Dealership Leadership
Usually a Dealer Principal, General Manager, Controller, or another designated executive who can make business decisions.
IT or Cybersecurity
Responsible for technical containment, investigation, account security, system analysis, and coordination with other technology vendors.
Cyber Insurance
The carrier or broker can explain the policy's incident process and available resources.
Legal Counsel
Advises leadership on notification, regulatory, contractual, law-enforcement, and other legal issues.
Forensic or Incident-Response Specialists
Some incidents require expertise beyond normal IT support.
Department Leadership
Sales, service, F&I, accounting, HR, or other departments may need to implement temporary procedures or help identify affected information.
Communications
For a larger incident, somebody should coordinate employee, customer, vendor, or public communications.
Law Enforcement
Depending on the circumstances, local authorities, the FBI, IC3, or New Jersey authorities may become involved.
The important thing is not creating a huge committee.
It is knowing who has the authority to make each decision.
What Happens After the First 24 Hours?
The first day is about gaining control.
After that, the work usually shifts toward several parallel questions:
Are we confident the attacker is out?
What systems are safe to restore?
What information was affected?
What notifications are required?
How do we get employees working normally again?
How did this happen?
What needs to change so it is less likely to happen again?
The technical team may continue forensic work while other teams restore operations, communicate with insurance and legal resources, address notification requirements, and bring systems back online.
The FTC advises businesses to remediate vulnerabilities identified during the investigation, verify service-provider fixes where relevant, and make sure access remains appropriate following a breach.
This is also when the dealership should eventually conduct a post-incident review.
Not:
“Who do we blame?”
But:
- What worked?
- What slowed us down?
- Did everyone know whom to call?
- Did we have the information the insurer needed?
- Were vendor contacts current?
- Could we restore the systems we expected?
- Were employees given clear instructions?
- Did we have unnecessary access?
- What should be different next time?
A cyber incident is expensive enough without wasting what it can teach you.
Frequently Asked Questions About Auto Dealership Cyberattacks
What should an auto dealership do first after being hacked?
Get the dealership's IT or cybersecurity response team involved immediately and begin a coordinated assessment of what is happening.
The first priorities are usually containing the incident, preserving evidence, securing compromised access, determining which systems are involved, and bringing in the appropriate business, insurance, legal, and law-enforcement resources.
Do not let employees independently start wiping or rebuilding affected systems. CISA and FTC guidance both emphasize coordinated containment and evidence preservation during incident response.
Should you turn off a computer during a cyberattack?
Not automatically.
The correct response depends on the incident. An affected computer may need to be disconnected or isolated quickly, but simply powering it off can affect evidence that forensic responders may need.
FTC guidance recommends taking affected equipment offline while cautioning against turning machines off before forensic experts arrive.
When possible, follow the instructions of your IT or incident-response team.
Should passwords be changed immediately after a cyberattack?
Compromised credentials often need to be changed, but password resets should be part of a coordinated access review.
The response may also need to address active sessions, administrator accounts, MFA, remote access, vendor accounts, forwarding rules, and other ways an attacker could maintain access. The FTC specifically recommends changing credentials that may have been stolen.
When should a dealership contact its cyber insurance company?
A dealership with cyber insurance should review its policy and contact the carrier or broker promptly according to the policy's incident-reporting requirements.
Do not assume that a service or expense will be covered without understanding the policy's process.
Does a dealership need to notify the FTC after a cyberattack?
Not every cyberattack automatically requires an FTC notification.
However, dealerships covered by the FTC Safeguards Rule may have to notify the FTC of certain security events involving at least 500 consumers. For qualifying events, notification is required as soon as possible and no later than 30 days after discovery.
Dealerships should work with qualified legal counsel to determine whether a particular incident triggers that or other notification requirements.
Does a New Jersey dealership have to notify customers after a data breach?
New Jersey has breach-notification requirements for businesses that conduct business in the state and maintain computerized personal information. Whether customer notice is required depends on whether the incident meets the law's requirements and what information was involved. Current New Jersey law also requires qualifying breaches to be reported to the Division of State Police before notice is sent to affected customers.
This is an area where dealerships should obtain legal guidance based on the specific incident.
Should customers be told immediately that the dealership was hacked?
Customers should receive required notifications promptly and in accordance with applicable law, but the dealership should first determine what it knows, what information was affected, and what notification obligations apply.
FTC guidance recommends coordinating notification timing appropriately and avoiding misleading statements or disclosures that could create additional risk.
Should an auto dealership pay a ransomware demand?
That decision involves legal, insurance, operational, security, and potentially regulatory considerations and should not be made casually.
The FBI states that it does not support paying ransomware demands because payment does not guarantee data recovery and can encourage additional criminal activity. The FBI asks organizations to report ransomware incidents regardless of whether payment is made.
A dealership facing an actual ransom demand should involve its incident-response team, cyber insurer, legal counsel, and appropriate law-enforcement resources.
When is it safe to restore dealership systems?
Affected systems should return to service in coordination with the incident-response team after there is reasonable confidence that doing so will not immediately recreate the problem.
FTC breach guidance recommends consulting forensic experts and law enforcement regarding when normal operations can safely resume.
What should employees do during a dealership cyberattack?
Employees should follow the instructions provided by the dealership's incident-response team.
They should report suspicious activity, avoid experimenting with affected systems, preserve suspicious messages or evidence, and use only the systems leadership has said are safe to use.
The dealership should provide one clear source of instructions rather than leaving individual employees to decide what to do.
The First 24 Hours Are About Getting Control of the Situation
A cyberattack puts dealership leadership under immediate pressure.
Employees want to know when they can work.
Customers are waiting.
Vendors need answers.
Leadership wants to know what happened.
The insurance company may need information.
And everyone understandably wants the systems back online.
That is exactly why the response needs to be deliberate.
Get the right people involved. Contain the incident. Preserve evidence. Secure access. Determine what was affected. Keep employees informed. Bring in insurance, legal, and law-enforcement resources when appropriate. Then recover systems in a controlled way.
The goal during the first 24 hours is not to have every answer.
It is to make sure the dealership is asking the right questions and that somebody owns each part of the response.
For Morris County and Northern New Jersey auto dealerships, Tech Marvel helps businesses prepare for cybersecurity incidents, coordinate technology vendors, secure accounts and systems, and understand the technical side of an incident when something goes wrong.
If you believe your dealership is experiencing an active cyberattack, contact your IT or cybersecurity response provider immediately.
If you are not dealing with an emergency but are not sure how prepared your dealership would be, schedule your free 20-minute Dealership IT Review.
We can talk through your current cybersecurity, backups, users, vendors, and incident-response process so you have a clearer picture before you ever need to use it.


