Skip to content
Search AI Powered

Latest Stories

Report: hackers target third-party suppliers in automakers’ supply chains

90% of cyberattacks in the sector are aimed at “less vigilant firms” instead of well-protected OEMs

VicOne_Automotive_Cyberthreat_Landscape_Report_2023.jpeg

Nine out of 10 cyberattacks launched at automotive manufacturers are not aimed at the original equipment manufacturers (OEMs) themselves, but at other companies in their supply chains, according to a study from cybersecurity software and service provider VicOne.

That trend means that third-party suppliers—including logistics providers, service providers, and companies engaged in the production of components, accessories or parts—have emerged as a growing focus of attacks, the company said in its “VicOne Automotive Cyberthreat Landscape Report 2023.”


One reason for rising attacks is the increasing complexity of vehicles and their integration of connectivity, automation, and advanced driver assistance systems (ADAS). Most of the security issues were found on chipsets or systems-on-chip (SoCs), followed by vulnerabilities in third-party management applications and in-vehicle infotainment (IVI) systems, the report said.

One problem in preventing such cyber attacks is the regulatory vacuum concerning vehicle data, the report said. However, VicOne said that a new United Nations cyber security policy known as UN R155 will mandate safety conditions for newly manufactured cars beginning in July, 2024.

But in the meantime, auto industry losses are growing from cyberattacks such as ransomware and exposure of leaked data or personally identifiable information (PII), as well as costs associated with system downtime.

“Alarmingly, over 90% of these attacks were not aimed at OEMs themselves but rather at other entities in the supply chain,” the report said. “Attackers often find it difficult to penetrate well-protected companies, so they target less vigilant firms instead. But OEMs are affected all the same, because of the supply chain disruptions. Consequently, defending systems against cyberattacks is no longer just about securing an individual firm; it is about strengthening the entire supply chain.”
 

 

 

The Latest

More Stories

autonomous tugger vehicle

Cyngn delivers autonomous tuggers to wheel maker COATS

Autonomous forklift maker Cyngn is deploying its DriveMod Tugger model at COATS Company, the largest full-line wheel service equipment manufacturer in North America, the companies said today.

The deal was announced the same week that California-based Cyngn said it had raised $33 million in funding through a stock sale.

Keep ReadingShow less

Featured

Study: Industry workers bypass essential processes amid mounting stress

Study: Industry workers bypass essential processes amid mounting stress

Manufacturing and logistics workers are raising a red flag over workplace quality issues according to industry research released this week.

A comparative study of more than 4,000 workers from the United States, the United Kingdom, and Australia found that manufacturing and logistics workers say they have seen colleagues reduce the quality of their work and not follow processes in the workplace over the past year, with rates exceeding the overall average by 11% and 8%, respectively.

Keep ReadingShow less
photo of a cargo ship cruising

Project44 tallies supply chain impacts of a turbulent 2024

Following a year in which global logistics networks were buffeted by labor strikes, natural disasters, regional political violence, and economic turbulence, the supply chain visibility provider Project44 has compiled the impact of each of those events in a new study.

The “2024 Year in Review” report lists the various transportation delays, freight volume restrictions, and infrastructure repair costs of a long string of events. Those disruptions include labor strikes at Canadian ports and postal sites, the U.S. East and Gulf coast port strike; hurricanes Helene, Francine, and Milton; the Francis Scott key Bridge collapse in Baltimore Harbor; the CrowdStrike cyber attack; and Red Sea missile attacks on passing cargo ships.

Keep ReadingShow less
diagram of transportation modes

Shippeo gains $30 million backing for its transportation visibility platform

The French transportation visibility provider Shippeo today said it has raised $30 million in financial backing, saying the money will support its accelerated expansion across North America and APAC, while driving enhancements to its “Real-Time Transportation Visibility Platform” product.

The funding round was led by Woven Capital, Toyota’s growth fund, with participation from existing investors: Battery Ventures, Partech, NGP Capital, Bpifrance Digital Venture, LFX Venture Partners, Shift4Good and Yamaha Motor Ventures. With this round, Shippeo’s total funding exceeds $140 million.

Keep ReadingShow less
Cover image for the white paper, "The threat of resiliency and sustainability in global supply chain management: expectations for 2025."

CSCMP releases new white paper looking at potential supply chain impact of incoming Trump administration

Donald Trump has been clear that he plans to hit the ground running after his inauguration on January 20, launching ambitious plans that could have significant repercussions for global supply chains.

With a new white paper—"The threat of resiliency and sustainability in global supply chain management: Expectations for 2025”—the Council of Supply Chain Management Professionals (CSCMP) seeks to provide some guidance on what companies can expect for the first year of the second Trump Administration.

Keep ReadingShow less