On June 19, 2024, ransomware hit CDK Global — the company whose dealer management software runs the sales floors, service bays, parts counters, and financing paperwork of roughly 15,000 car dealerships across North America. CDK shut down its systems, restored partially, was hit again, and shut down once more. For nearly two weeks, one of the largest retail sectors in the United States operated on handwritten forms, spreadsheets, and phone calls. Sales stalled. Service departments could not look up warranty coverage. Dealer groups reported material hits to quarterly results, and the aggregate industry loss was later estimated in the region of a billion dollars.

Not one of those dealerships was individually targeted. Each had made a sensible, independent procurement decision years earlier, choosing the market-leading platform because it was the market leader. The aggregate result was an industry with a shared spine — and when that spine was encrypted, competitors who had nothing to do with each other went down in unison. Reporting indicated CDK ultimately paid a ransom in the region of $25 million, a figure that tells you what two weeks of national retail paralysis is worth to the people holding the keys.

June 2024 belongs in this archive as the clearest early lesson in sector-wide concentration: the risk is not that your vendor is careless, but that your entire industry chose the same one. It is precisely the structure that would take down supermarket logistics in November, and the reason the CrowdStrike outage a month later felt less like a shock than a confirmation.

Also that month · The cloud tenancy campaign

Snowflake, and 165 companies' worth of stolen logins

June was when the Snowflake campaign became public in force. Ticketmaster and Santander customer data surfaced for sale, and researchers established the pattern: attackers using credentials harvested long ago by infostealer malware to log into customer tenancies on the Snowflake data platform that lacked multi-factor authentication. Around 165 organisations were identified as potentially affected. Snowflake's own systems were not breached — the failure lived entirely in the shared-responsibility gap, where the provider offers the controls and the customer forgets to enable them. The industry's response, arriving over subsequent months, was blunt: platforms began enforcing MFA rather than offering it.

Also that month · No backups

Indonesia's national data centre goes down

On June 20, ransomware struck Indonesia's temporary National Data Centre, disrupting services across more than 200 government agencies, including immigration processing at airports. Then came the admission that made it a global case study: officials acknowledged that the overwhelming majority of the affected data had not been backed up. The attackers demanded $8 million; the government refused, and in an unusual epilogue the group publicly apologised and released the decryption key at no charge in early July. A country got its data back through the goodwill of its attackers. Ministers resigned in the aftermath, and "do we have backups, actually?" briefly became a question asked at cabinet level worldwide.

India desk · June 2024

The most-attacked, by the numbers

June found India in an unwelcome position at the top of several charts. Threat researchers tracking the period recorded Indian organisations facing among the highest weekly attack volumes of any major economy — a consequence of scale, rapid digitisation, and an attack surface expanding faster than the security workforce hired to defend it. The month's context was structural rather than headline-driven: a reported intrusion at BSNL still under assessment, the aftershocks of Hathway's spring leak, and a national data protection law that remained un-operationalised. India was, by mid-2024, generating world-scale digital infrastructure and world-scale digital exposure simultaneously — with the rulebook to govern it still in a drawer.

⏳ Time capsule — June 2024

  • Car dealership staff rediscovered carbon-copy forms; several posted photographs that went viral.
  • Apple announced Apple Intelligence at WWDC, and privacy engineers spent the month reading the architecture notes.
  • "Enable MFA on your Snowflake tenancy" became the most repeated advisory of the quarter.
  • India's general election results landed early in the month, with the feared wave of AI-generated disinformation proving noisy but not decisive.
Where it stands today — 2026

Everyone's supplier is everyone's risk

CDK became the standard American example of sector-wide concentration risk, cited whenever an industry realises it has standardised on a single platform — and its two weeks of paper forms echo directly in the empty supermarket shelves of November 2024 and the stopped production lines of September 2025. The Snowflake campaign did more for MFA adoption than a decade of best-practice guidance, and its infostealer-credential mechanism is the direct ancestor of the sixteen-billion-credential panic of June 2025. Indonesia's backup admission remains the most-cited resilience cautionary tale in government IT. Three incidents, one message: modern outages are rarely about one company's failure, and almost always about how many others were standing on it.