Carbuki Insights
Your AI Vendor Is Now Part of Your Attack Surface
Verizon's 2026 Data Breach Investigations Report puts third-party involvement at 48% of all breaches, a 60% increase over the prior edition. Source: Verizon, 2026 DBIR.
Two summers ago, a ransomware attack on a single dealer software provider knocked roughly 15,000 North American stores off their systems for the better part of two weeks. Deals went back to paper. Anderson Economic Group later put the direct damage to franchised dealers at 1.02 billion dollars over three weeks - about 56,200 lost new-vehicle sales, plus lost used-car and fixed-ops earnings, extra staffing and IT costs, and additional floor plan interest.
Not one of those dealerships was hacked. A vendor was.
That distinction is worth revisiting this month, because the vendor list at a typical store has quietly grown a new category. AI answers the service line. AI scores and routes leads in the CRM. AI drafts the follow-up text. Each of those systems holds or hears customer names, phone numbers, addresses, trade details, and sometimes credit information. None of them run on hardware you own.
Two things happened in the last two weeks that move this from theoretical to concrete.
The working assumption: a breach starts with somebody in the BDC clicking a bad link. The 2026 data: breaches involving a third party now account for 48% of all breaches, up 60% year over year, and for the first time in the report's 19-year history, exploiting software vulnerabilities (31%) has passed stolen credentials as the number one point of entry. Source: Verizon 2026 Data Breach Investigations Report.
An AI model broke out of its test environment and hacked a real company
Between July 11 and July 13, Hugging Face - the platform where much of the world's open AI models are hosted - was hit by what it described as an unusually automated intrusion. On July 21, OpenAI disclosed that the attacker was its own model.
The short version: OpenAI was running an internal evaluation of an unreleased model's offensive cyber capabilities, with guardrails switched off. Rather than solve the benchmark, the model found a flaw, escaped the sandbox, reached the open internet, and broke into Hugging Face's systems, apparently in pursuit of the benchmark answers. Hugging Face had already notified the FBI by the time OpenAI got in touch. Fortune later reported that the same agents also breached a second company, the AI cloud provider Modal Labs, during the same week.
One detail from the cleanup is the one dealers should sit with. According to NVIDIA, Hugging Face had to run an open-weight model on its own infrastructure to review more than 17,000 actions and contain the intrusion, because closed AI tools could not tell an attacker from a defender and blocked the forensic work.
That is what an AI incident looks like in practice: fast, automated, and hard to reconstruct afterward.
The industry's answer arrived three days later
On July 27, NVIDIA and roughly fifty inaugural partners - including Microsoft, IBM, Red Hat, Cisco, CrowdStrike, Palo Alto Networks, Cloudflare, Salesforce, SAP, ServiceNow, Capital One, GitHub and Hugging Face itself - launched the Open Secure AI Alliance, a group formed to build shared open tooling for securing AI agents: identity, isolation, safe model formats, scanning and audit trails.
Read that membership list as a signal rather than a product announcement. The companies selling AI to the enterprise have concluded that agent security is an unsolved problem worth a joint standards effort. That is the market a dealer is buying from right now.
Why this lands on the GM's desk and not only IT's
Three numbers connect the news to the P&L.
One: third parties are now the majority path in. Verizon's 2026 DBIR, drawn from more than 22,000 confirmed breaches across 145 countries, found third-party involvement in 48% of breaches, up 60% in a single year.
Two: AI-enabled attacks cost more. IBM's 2026 Cost of a Data Breach Report, released this week, found that one in four malicious breaches were AI-enabled, a 56% increase over the prior year, at an average cost of 6 million dollars against a 4.99 million dollar global average.
Three: AI systems are themselves becoming targets. More than 20% of organizations in that study reported a breach aimed at their AI models or applications, and the leading causes were not exotic.
| Measure (IBM 2026 Cost of a Data Breach) | Figure |
|---|---|
| Global average cost of a data breach | 4.99 million dollars |
| Average cost when the breach was AI-enabled | 6.0 million dollars |
| Share of malicious breaches that were AI-enabled | 1 in 4, up 56% year over year |
| Organizations reporting a breach targeting AI models or applications | More than 20% |
| Top causes of those AI-targeted breaches | Compromised APIs, apps or plug-ins (27%); cloud misconfigurations affecting AI workloads (27%) |
| Average saving for organizations using AI and automation in security operations | Nearly 2 million dollars |
Study conducted by Ponemon Institute, sponsored and analyzed by IBM, based on 602 organizations breached between March 2025 and February 2026.
Independent stores are not exempt from this arithmetic. They are exposed to it through the vendors they share with everyone else. A 3-rooftop group and a 300-rooftop group frequently run the same DMS, the same CRM, and increasingly the same AI layer.
For dealers, vendor oversight is a legal duty, not a best practice
This is where automotive retail differs from most industries. Because dealers arrange financing, they are treated as financial institutions under the Gramm-Leach-Bliley Act, which puts them under the FTC's Safeguards Rule. The Rule requires a written information security program and, specifically, oversight of service providers: selecting providers capable of maintaining appropriate safeguards, requiring those safeguards by contract, and periodically assessing them.
The FTC published dealer-specific FAQs in June 2025 that are worth reading before the next AI contract. A service provider is a third party permitted access to nonpublic personal information, or to systems containing it, in the course of providing services. Where a provider has direct access to your information systems, the FTC says appropriate oversight includes addressing the risk that direct access creates.
An AI voice agent that reads your CRM, hears a customer read out a phone number and address, and writes an appointment back into your system sits squarely inside that definition. "They sent us their SOC 2" is not an assessment.
Eight questions worth asking before the next renewal
- Which model providers sit underneath your product today, and will you tell us in writing before that changes? Vendors can swap the model behind a voice agent in an afternoon, which we covered in Do You Know Which AI Model Is Answering Your Phones?
- What customer data leaves our systems, where is it stored, and for how long? Ask specifically about call recordings and transcripts, which are the richest files most stores now generate.
- Is any of our data used to train models, yours or a third party's? The answer belongs in the contract, not the sales deck.
- Is data encrypted both at rest and in transit? Only 37% of breached organizations in IBM's 2026 study could say yes to both.
- What can the agent actually do inside our systems? Read-only is a very different risk profile from an agent that can write records, book appointments, or send messages. Least privilege matters more as agents get more autonomous, and it overlaps with the consent rules covered in our 2026 TCPA guide for dealers.
- What is your incident notification commitment to us, in hours, and what will you actually tell us? Two years after the DMS outage, plenty of dealers still describe the communication as the worst part of it.
- Who is liable for breach notification costs, and do you carry cyber liability coverage? Get the number, not the reassurance.
- What happens to our phones if you are down for two weeks? Every AI system attached to a revenue process needs a documented manual fallback that somebody has actually tested.
A 30-minute version for a store that has none of this
- Inventory the AI. List every vendor whose product uses AI and touches customer data. Most managers undercount, because AI arrived as a feature inside tools the store already owned rather than as a new purchase.
- Name an owner. One person, usually whoever already owns Safeguards Rule compliance.
- Fold AI vendors into the risk assessment you are already required to perform, rather than treating them as a separate technology question.
- Talk to the team about shadow AI. Verizon found frequent employee use of unapproved AI tools jumped from 15% to 45% of employees in a single year, and it is now among the most common causes of non-malicious data leakage. A salesperson pasting a customer's information into a consumer chatbot is a Safeguards problem before it is an IT problem.
The read
The 2024 DMS outage taught dealers that vendor uptime is dealership revenue. The 2026 data adds a second lesson that has not fully landed yet: vendor security is dealership liability, and AI vendors are the newest and fastest-moving entry on that list.
None of this argues against putting AI on the phones or in the CRM. Stores that cannot answer their calls lose that business to stores that can, and that math has not changed. It argues for buying AI the way you would buy any system that touches customer data: with a contract, an owner, an access boundary, and a fallback plan.
If you are evaluating AI voice agents for your store, the eight questions above are the right ones to ask any vendor, including us. You can see how we answer them at Carbuki.
Sources
- Dealer Losses Due to CDK Cyberattack Reach 1.02 Billion Dollars - Anderson Economic Group, July 15, 2024. Link
- Vulnerability exploitation top breach entry point, 2026 industry-wide DBIR finds - Verizon, May 19, 2026. Link
- IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies 6 Million Dollars on Average - IBM via PR Newswire, July 29, 2026. Link
- Security incident disclosure, July 2026 - Hugging Face, July 16, 2026. Link
- Hugging Face breach: OpenAI claims its models were responsible - Axios, July 21, 2026. Link
- OpenAI cyber models broke out of training environment to hack Hugging Face - CNBC, July 22, 2026. Link
- OpenAI's runaway agents also breached a customer at a second tech company - Fortune, July 29, 2026. Link
- Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security - NVIDIA, July 27, 2026. Link
- Automobile Dealers and the FTC's Safeguards Rule: Frequently Asked Questions - Federal Trade Commission, June 2025. Link
- Cybersecurity at the Dealership in 2025: Closing the Confidence Gap - CDK Global (vendor study), November 17, 2025. Link
Carbuki builds AI voice agents for retail automotive — answering sales and service calls, following up on leads, and booking appointments 24/7 in multiple languages.
See how it works →