Hackers Target Dealer Social Media Posts
TIMONIUM, Md. — Helion Automotive Technologies has issued an urgent data security warning for auto dealers: Hackers are now planting malware inside of social media posts. If an employee takes the bait and clicks on the social media post (e.g. Facebook and Twitter messages and public postings), according to the firm, the malware is downloaded onto the ... Read More »
TIMONIUM, Md. — Helion Automotive Technologies has issued an urgent data security warning for auto dealers: Hackers are now planting malware inside of social media posts.
If an employee takes the bait and clicks on the social media post (e.g. Facebook and Twitter messages and public postings), according to the firm, the malware is downloaded onto the employee’s computer and may compromise the entire organization’s network. Security software and firewalls cannot prevent this type of attack, according to Erik Nachbahr, president and CEO of Helion and an Auto Dealer Today contributor.
“This is the same spear phishing scheme that hackers have been using successfully in targeted email messages for several years now,” Nachbahr said. “The problem is that although most employees have been told and know not to click on emails from people they don’t know, they don’t think twice when it comes to clicking on a message or offer in their Facebook feed. They are more trusting in a social media environment.”
Spear phishing is a type of attack that involves identifying specific people for attack, studying their social media posts to learn their interests and activities, and then creating a message or offer that appeals to them.
Nachbahr cited the example of a recent breach at the Pentagon. It was caused when the wife of an employee clicked on a Twitter link that promised a great deal for a family-friendly vacation. She had previously been exchanging messages with friends over what they should do with their children over the summer. Although the wife was at home at the time, the hackers accessed the Pentagon employee’s computer via a shared home network, and once the employee was back at the Pentagon, accessed the network from his computer.
Auto dealership employees are ideal targets for spear phishers looking to steal personally identifiable information (PII) and bank account numbers.
Helion recently conducted a phishing test at an auto dealership by sending emails to 125 employees. Three employees clicked on the emails and were taken to a website where they entered their user names and passwords when prompted. If this was a real attack and customer information was compromised, the consequences for that dealership may have been thousands of dollars paid out in credit monitoring for customers, investigations and lawsuits.
“That test was a good sample that revealed auto dealerships are very vulnerable to this type of attack and need to do a better job at educating their employees,” said Nachbahr.
To help prevent this type of attack, Nachbahr recommends counseling employees against clicking on links in social media posts and messages from their computers or personal devices while at work or at home, require them to change their network login passwords every 90 days, keep social media profiles private, and don’t accept friend or connection requests from people they don’t know.
Every auto dealership should have cyber liability insurance, Nachbahr added, and dealers should install software updates, also known as patches, to Microsoft Windows, Internet Explorer and all software applications on every PC on a regular basis.
More Industry

RV Group Expands Carolina Footprint
Blue Compass RV Columbia Northeast is the 13th RV dealership owned by Blue Compass in the Carolinas.
Read More →
Agent Acumen
An Agent Summit panel of people who’ve been supporting auto dealers for years gave both timely and timeless advice for those starting out or mulling the prospect.
Read More →
Missed Maintenance Creates Opportunity
As families get back on the road and into daily school routines, service drives have an opportunity to capture customers who are behind on recommended vehicle maintenance.
Read More →
Mitsubishi Unveils U.S. Plan
The automaker announced a strategy that includes an expanded lineup and dealership presence, along with more ‘rugged’ and electric models.
Read More →
Selling to Grow
The question of whether you should sell your agency and if so, when, is up to you. But it’s a question worth asking to ensure you keep the business on the right path for yourself, employees and clients.
Read More →
Recalled Vehicles Hit 5-Year High
Though the number of events has fallen so far this year, impacted units are up significantly. Meanwhile, regulators consider consumer notification changes.
Read More →
Auto Group Acquires Top-Performing Rooftop
Car Pros sold its Kia Huntington Beach location to Sutherlin Automotive Group, marking the buyer’s third location in Southern California.
Read More →
China as Pacesetter
Automotive leaders huddled on where North America stands in the global picture and how it can strengthen its position against the Asian juggernaut’s surging industry.
Read More →
BMW Concept Car Makes Fuel to Burn
The prototype developed in concert with a South Carolina university engineering team generates more solar energy than it uses in a typical daily commute.
Read More →
South Carolina Auto Group Downsizes
Florida-based group Holler-Classic has acquired four rooftops, its first in South Carolina, from Dick Smith Automotive Group.
Read More →