
Automotive dealerships are facing a growing number of cyberattacks.
New data from Proton Dealership IT and Cybersecurity shows attack activity remaining elevated over the past year, including a dramatic spike in early 2026 tied to an attack involving remote-connectivity software.
“Attacks have just grown quicker year over year. They’ve grown in more volume year over year,” said Sean Patronis, Chief Information Security Officer for Proton Dealership IT, in an interview with Canadian auto dealer.
Proton, a U.S.-based dealership IT and cybersecurity company acquired by Reynolds and Reynolds in 2022, tracked malicious activity across all Proton clients in the U.S. and Canada from July 2025 through June 2026. Even when attacks dropped sharply in February, they remained nearly double the rate recorded before a major automotive industry cyberattack in 2024.
Then came March. Attack activity surged to nearly 1,000 per cent above the pre-attack level. Proton traced the spike to an attack involving remote-connectivity software that threat actors tried to use to gain access to business networks.
“Essentially the bad guys co-opted this for nefarious reasons and tried to implant it into a lot of business networks. We caught that attack pretty early,” said Patronis.
Proton responded with what Patronis described as a “massive threat hunt” across its dealership environments. He said the company detected and blocked the activity before it affected its customers. Petronis said other businesses were caught up in the attack, which led to more ransomware attacks.
“If you look at our report, you’ll see this big spike and that’s what that’s from,” he said.
The spike subsided, but Proton’s data shows attacks beginning to rise again in June. Patronis said phishing now accounts for more than half of the attacks Proton sees, overtaking exploited vulnerabilities as the leading attack vector.
Vulnerability attacks also increased, Petronis said, but phishing grew faster and now represents a larger share of the total.
“Year over year, more attacks, more phishing. Bad guys are using AI to create more convincing attacks, phishing attacks specifically,” he said.
Stolen credentials are another concern.
“They’re walking in through the front door like they’re an employee just with your credentials or whoever’s credentials they’ve harvested,” said Patronis.
He said monitoring login activity can help identify an account being accessed from an unexpected location.
The financial stakes are also increasing. Proton’s report cites industry experts who put the average cost of recovering from a ransomware attack at $1.7 million in 2026, up from $1.5 million in 2025, excluding any ransom paid.


