An account assigned to a former salesperson remained active for six months. Someone used the credentials to enter the dealership’s systems without multifactor authentication and export 4,200 customer records.
The IT manager received the call Tuesday at 9 a.m.
“We found 4,200 dealership customer records in a dark-web collection.”
The exposed data included names, addresses, phone numbers, driver’s-license information and the last four digits of Social Security numbers.
The access logs pointed to an account assigned to a salesperson who had left six months earlier. Nobody disabled the DMS login or removed remote access.
The account had no multifactor authentication. Someone signed in during the night and exported a CSV file containing 4,200 records.
The investigation took 62 days. Forensics cost $18,000. Customer notification cost another $8,400.
The initial incident worksheet listed a total cost of $58,600. The documented line items supplied for this case add up to $52,200. The missing $6,400 should not appear as breach cost without an invoice or internal labor calculation supporting it.
This is the 62-day dealership data breach timeline and the controls which should have stopped it.
| Day | What Happened | Documented Cost | People Involved | Safeguards Rule Issue | Control That Was Missing |
| Day 0 | Credentials assigned to a former salesperson accessed the DMS remotely | $0 | Account user and IT | Access controls and periodic access review under §314.4(c)(1) | Same-day offboarding, MFA and quarterly account review |
| Day 1 | Monitoring alert identified 4,200 customer records in an outside data set | $0 | IT and monitoring provider | Risk management and monitoring concerns | Current risk assessment and alert process |
| Day 2 | Logs showed a large CSV export from the old account | $0 | IT and GM | Excess access and weak activity monitoring | Least privilege, export alerts and log review |
| Day 3 | Dealership hired counsel and a forensic firm | $18,000 | Counsel and forensics | Incident-response readiness under §314.4(h) | Written response plan and approved response vendors |
| Day 5 | Forensics confirmed scope and unprotected CSV export | $0 | Forensics | Encryption and compensating controls under §314.4(c)(3) | MFA, export control, monitoring and encryption |
| Day 7 | Counsel reviewed FTC and state notification duties | $3,500 | Counsel and compliance | Notification assessment under §314.4(j) | Notification decision tree and current data map |
| Day 10 | Team prepared a 4,200-person notification list | $8,400 mailing cost | Office, counsel and mail vendor | State notification duties depended on affected residents | Tested notification templates and address data |
| Day 14 | Dealership opened its cyber-insurance claim | $10,000 deductible | Insurer, broker and counsel | Cyber insurance is not a Safeguards Rule requirement | Annual policy and coverage review |
| Day 21 | IT removed 12 stale accounts, added MFA and set export controls | $2,000 | IT and system vendors | Access, MFA and monitoring controls | Automated offboarding and access certification |
| Day 30 | Required notices were mailed and monitoring support arranged | $6,300 monitoring model | Office, counsel and vendor | State duties varied by resident and data type | Preselected response vendor |
| Day 45 | Team documented the revised security program and remediation | $4,000 legal cost | Counsel and compliance | Written program, risk assessment and proof of remediation | Current written program and annual review |
| Day 62 | Investigation, remediation and response work closed | $52,200 total | Owner, IT, legal and office | Multiple control failures | Offboarding, MFA, least privilege, monitoring and response plan |
The timeline reflects one case study. Breach-notification duties differ by state, affected data, encryption status and evidence of acquisition. Owners should follow incident counsel’s advice rather than treating day 30 as one national customer-notification deadline.
Day 0: The Former Employee’s Account Still Worked
The salesperson had left six months earlier.
HR completed the final payroll process. Management reassigned the leads. Nobody sent IT a formal offboarding request.
The DMS user remained active. Remote access remained available. The account still held permission to export a large customer list.
The logs showed a login at about 2 a.m. The credentials produced a successful remote session without a second authentication factor.
The evidence proved use of the former employee’s assigned credentials. It did not automatically prove the former employee performed the export. A stolen password, shared credential or another unauthorized user remained possible until the investigation established identity.
This distinction matters. Do not accuse an employee before forensic evidence supports the claim.
The failure began with process ownership. HR assumed IT received notice. IT assumed the department manager requested removal. The manager assumed terminated employees lost access through payroll.
Nobody owned the final check.
Use one offboarding ticket with these fields:
Employee name
Final working date and time
DMS access
CRM access
Email account
VPN or remote access
OEM portals
Vendor platforms
Shared passwords
Company devices
Completion confirmation
Disable access at the employee’s departure time. Preserve records required for legal, payroll or business purposes without preserving login rights.
Action: Make HR responsible for opening the ticket and IT responsible for documenting closure.
Days 1 and 2: The Alert Found What Access Controls Missed
The first alert did not come from the DMS.
An outside monitoring service reported customer records appearing in a dark-web data collection. IT searched logs and identified the old user account.
The export included 4,200 records.
The dealership had no alert for an unusual login time. It had no approval requirement for a large export. Nobody received a warning when one sales account downloaded thousands of customer records.
A data-loss prevention rule might have blocked or quarantined the transfer. A simpler threshold alert would at least have sent the event to IT for review.
Do not choose the threshold blindly. Blocking every export above 500 records might interrupt legitimate accounting, compliance or marketing work.
Use an approval workflow:
Small routine export: permitted and logged
Medium export: manager approval
Large sensitive export: IT approval and security review
Unusual after-hours export: block or escalate
Encryption at rest would protect stored databases from some forms of theft. It would not necessarily stop a valid account from exporting readable data. Once an authorized application decrypts information for a logged-in user, stronger identity, least privilege and export monitoring become the primary controls.
The Safeguards Rule requires covered dealers to base protections on a written risk assessment and implement safeguards including access controls, encryption, MFA and logging. FTC Safeguards Rule FAQs for automobile dealers
Action: Alert on stale-account logins, after-hours access and bulk exports involving customer information.
Days 3 Through 7: The First Invoice Was $18,000
The dealership did not have an approved forensic firm or a tested incident-response plan.
The GM called outside counsel. Counsel contacted a forensic company. The firm required an $18,000 retainer before beginning work.
Forensics needed to answer five questions:
How did the access occur?
Which systems were involved?
What information left the environment?
How many people were affected?
Was unauthorized acquisition still continuing?
Counsel reviewed the dealership’s written information security program, risk assessment, access controls, MFA coverage, logs and response procedures.
The security program had not received a meaningful update in two years. The document named old vendors and omitted newer remote-access systems.
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program, perform a written risk assessment and create a written incident-response plan. The incident-response requirement appears in 16 CFR §314.4(h), not §314.4(d). 16 CFR §314.4
The dealership also needed to assess federal notification.
Under the Safeguards Rule, a covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event. The federal threshold involves unauthorized acquisition of at least 500 consumers’ unencrypted customer information. Unauthorized acquisition is presumed unless reliable evidence shows it did not occur or could not reasonably have occurred.
This rule does not mean every 4,200-record incident produces an FTC enforcement letter. It means the dealership and counsel must determine whether the event meets the reporting standard.
Action: Approve incident counsel, forensics, insurance contacts and decision authority before an event occurs.
Days 10 Through 30: Notification Added $24,700
Counsel determined which affected individuals required notice under the applicable state laws.
The case model used 4,200 mailed letters at $2 each:
4,200 × $2 = $8,400
The $2 estimate included printing, envelope preparation and postage under the supplied mailing model.
The dealership also carried a $10,000 cyber-insurance deductible.
The credit-monitoring model assumed a $15 enrollment cost for 420 people, equal to 10% of the affected population:
420 × $15 = $6,300
Combined notification-stage cost:
$8,400 + $10,000 + $6,300 = $24,700
The 10% acceptance assumption is not a legal standard. Vendor pricing also differs. Some contracts bill per affected individual, others per enrollee or through tiered packages.
State notification requirements differ. Driver’s-license information and partial Social Security numbers do not produce identical duties in every state. Timing, content, regulator notice and credit-monitoring obligations also vary.
The FTC’s breach-response guidance tells businesses to work with legal counsel, preserve evidence, determine the scope and consult applicable federal and state requirements. FTC Data Breach Response Guide
Action: Maintain state-specific notification guidance, approved letter templates and a current response-vendor contact list.
Day 21: Twelve Old Accounts Were Still Active
The breach review found 12 user accounts belonging to former employees.
Some accounts had access only to low-risk tools. Others reached customer systems. None should have remained active without a documented business reason.
IT disabled the accounts and added MFA across 60 users for the DMS, Microsoft 365 and remote-access systems where supported.
The team also added:
Alerts for bulk exports
After-hours login monitoring
Quarterly access reviews
Department-based permissions
Manager approval for high-volume downloads
Documented exception handling
MFA appears under §314.4(c)(5). The rule requires MFA for individuals accessing information systems unless the qualified individual approves a reasonably equivalent or more secure control in writing.
MFA would have made password-only access harder. It would not have corrected excessive export rights or stale accounts by itself.
Action: Review every active user by employee status, department, system and access level once per quarter.
Day 62: Technical Cleanup Ended, Customer Questions Did Not
The forensic team closed its investigation on day 62.
The owner had spent two months reading legal updates, approving letters, joining insurance calls and asking whether another system held the same records.
Employees answered customer questions. Two negative reviews mentioned the breach. The dealership had no verified dollar value for the reputational impact, so none belongs in the cost total.
Documented incident costs were:
Forensic retainer: $18,000
Initial legal review: $3,500
Customer letters: $8,400
Insurance deductible: $10,000
IT remediation time: $2,000
Credit-monitoring model: $6,300
Follow-up legal work: $4,000
Total:
$18,000 + $3,500 + $8,400 + $10,000 + $2,000 + $6,300 + $4,000 = $52,200
Cost per affected record:
$52,200 ÷ 4,200 = $12.43
Do not publish $58,600 unless the dealership documents another $6,400 in internal labor, call-center expense, postage variance or vendor charges.
Action: Track every breach expense by invoice, internal labor, reimbursement status and insurance coverage.
Compliance Math: $52,200 Incident Versus an $8,200 Prevention Plan
The annual prevention model in this case used:
MFA: $5 per user × 60 users × 12 months = $3,600
Dark-web monitoring: $1,200
Quarterly access review: 4 hours × $100 = $400
Annual legal review of the security program: $2,000
DLP and export-monitoring allowance: $1,000
Total annual prevention model:
$3,600 + $1,200 + $400 + $2,000 + $1,000 = $8,200
Documented breach cost divided by prevention cost:
$52,200 ÷ $8,200 = 6.37
The incident cost about 6.4 times the annual prevention model.
Vendor pricing and existing licenses change the comparison. Some Microsoft, identity or DMS subscriptions already include MFA. A DLP deployment across email, endpoints and dealership systems might cost more than $1,000.
The prevention checklist still fits on one page:
Disable departing users the same day
Require MFA for every supported customer-data system
Limit and monitor bulk exports
Review access quarterly
Maintain and test the written incident-response plan
The breach started with one account nobody closed.
The cleanup required 62 days, four outside parties and $52,200 in documented cost.
Sponsored by Gas.net — powering dealership growth through intelligent data.
Alt text: “Gas.net connects franchise dealers with integrated analytics and marketing tools.”