Skip to content
cisonews.net

Incident · 8-K Item 8.01; Item 1.05

Sonic Automotive reports material second-quarter impact from the CDK Global outage

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Sonic Automotive, a US auto dealership group, disclosed on June 21, 2024 that systems it relies on from software provider CDK Global had been suspended after a cybersecurity incident at CDK. The incident was at a supplier, not inside Sonic's own network, yet Sonic later reported it under Item 1.05 because of its effect on sales.

First disclosure, Item 8.01

Dealerships stayed open on workarounds while the dealer management and customer relationship systems were down.

Item 1.05 filing, July 5, 2024

Two weeks later Sonic concluded that the outage was reasonably likely to materially affect its second-quarter results, citing slower vehicle sales. Basic dealer management functions had come back by then, while other systems were still offline.

August 2024 amendment

The 8-K/A put a number on the quarter. Reported GAAP earnings per diluted share for the quarter were $1.18. Sonic said access to the affected systems had been restored, with lingering disruption to some CDK applications through July.

Not covered

Sonic's filings do not describe the attack on CDK itself, and CDK Global is not an SEC filer in this log.

Sources

  1. 2024-06-21 · ASonic Automotive, Inc., Form 8-K (SEC EDGAR), published June 21, 2024
  2. 2024-07-05 · ASonic Automotive, Inc., Form 8-K, Item 1.05 (SEC EDGAR), published July 5, 2024
  3. 2024-08-05 · ASonic Automotive, Inc., Form 8-K/A (SEC EDGAR), published August 5, 2024

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.