The Containment Era is here. →Explore

Industry Category

Automotive

Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.

146 threat reports
Page 12 of 13

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Automotive Threat Reports

Showing 133144 / 146 reports
New CAPI Backdoor Targets Russian Auto & E-Commerce with Phishing ZIPs
Impact· low

New CAPI Backdoor Targets Russian Auto & E-Commerce with Phishing ZIPs

In October 2025, cybersecurity researchers uncovered a sophisticated phishing campaign targeting Russian automobile and e-commerce firms. The attackers distributed phishing emails containing malicious ZIP files, which, when opened, triggered the deployment of a never-before-seen .NET-based malware known as the CAPI Backdoor. Once installed, the malware established persistent access, enabling threat actors to conduct internal network reconnaissance, exfiltrate sensitive information, and potentially disrupt business operations. Seqrite Labs, who analyzed the activity, report that the campaign’s execution appears highly tailored to exploit Russia’s rapidly digitizing sectors. This incident is significant amid a sharp increase in spear phishing and backdoor campaigns against supply chain and commercial organizations across Eastern Europe. The novelty of the CAPI Backdoor highlights evolving attacker sophistication and amplifies regulatory attention around encrypted traffic inspection, zero trust, and rapid anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Renault and Dacia UK 2025: Customer Data Breach Highlights Supply Chain Risks
Impact· high

Renault and Dacia UK 2025: Customer Data Breach Highlights Supply Chain Risks

In October 2025, Renault and Dacia UK notified customers of a data breach resulting from a cyberattack at an undisclosed third-party provider. The breach exposed sensitive information including full names, gender, phone numbers, email and postal addresses, as well as vehicle identification and registration numbers. While no financial data was compromised, this incident potentially increases the risk of phishing, scams, and targeted social engineering. Renault confirmed that the third-party provider contained the incident and regulatory authorities, including the UK’s Information Commissioner's Office, were notified as part of standard response. This event highlights the persistent risks posed by supply chain vulnerabilities, where companies are exposed through third-party relationships. As cyberattackers increasingly target vendors to bypass primary defenses, organizations must intensify scrutiny of their supply chains and enhance segmentation, monitoring, and incident response to align with evolving regulatory and threat landscapes.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Jaguar Land Rover Ransomware Breach: 2024 Supply Chain Disruption Case Study
Impact· high

Jaguar Land Rover Ransomware Breach: 2024 Supply Chain Disruption Case Study

In early 2024, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that exposed the company’s vulnerability to advanced persistent threats. Attackers, suspected to be Medusa ransomware operators, leveraged residual access from a prior breach to re-enter JLR’s systems, eventually encrypting sensitive data and disrupting operations across its supply chain. The breach forced significant production slowdowns, delayed supplier payments, and prompted the company to enact emergency IT protocols and notify regulatory authorities. This incident highlights the growing threat of repeat ransomware campaigns targeting global manufacturers and their digital supply chains. It underscores the critical need for continuous detection, east-west network visibility, and rigorous post-breach remediation in defending against evolving ransomware tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Multi-Vector Cyber Assault 2025: CarPlay, Cloud SQL, & iCloud Under Attack
Impact· medium

Multi-Vector Cyber Assault 2025: CarPlay, Cloud SQL, & iCloud Under Attack

In October 2025, coordinated threat actors launched a multi-vector attack campaign leveraging a critical CarPlay exploit, BYOVD (Bring Your Own Vulnerable Driver) tactics, SQL server compromise for covert command-and-control (C2), and targeted backdoor deployments against iCloud accounts. Attackers exploited unpatched vulnerabilities across automotive infotainment systems, enterprise firewalls, and cloud environments, enabling lateral movement and persistent access. The campaign demonstrated a sophisticated blend of supply chain targeting, abuse of trusted encryption protocols, malicious browser extension injection, and data exfiltration at scale. Impacted organizations faced substantial operational disruption, data loss, and the risk of regulatory penalties due to exposure of sensitive customer information and business-critical systems. This incident underscores the rapid evolution of attacker tradecraft, particularly in hybrid infrastructures and connected vehicles. The convergence of cloud, automotive, and critical business services in a single campaign highlights the increasing necessity for comprehensive, real-time security that spans east-west traffic, encrypted channels, and multi-cloud platforms.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients
Impact· high

Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients

In June 2024, Motility Software Solutions, a prominent provider of dealer management software, suffered a ransomware attack that resulted in the unauthorized access and exposure of sensitive data from approximately 766,000 clients. The attackers infiltrated Motility's networks, deployed ransomware to encrypt critical systems, and exfiltrated customer data, including personal and financial information. The attack caused significant operational disruptions for both Motility and its dealership clients, who rely on the platform for daily business operations. The incident highlights the persistent threat ransomware actors pose to software supply chains serving multiple downstream businesses. This breach is especially noteworthy amid an ongoing rise in ransomware targeting SaaS and vertical market providers, with attackers prioritizing data exfiltration for extortion. Regulators and business partners are increasing their demands for improved security controls and rapid incident disclosure, especially for service providers entrusted with large volumes of sensitive client data.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Jaguar Land Rover’s 2025 Ransomware Crisis: Lessons on Supply Chain and Zero Trust Resilience
Impact· high

Jaguar Land Rover’s 2025 Ransomware Crisis: Lessons on Supply Chain and Zero Trust Resilience

In September 2025, Jaguar Land Rover (JLR) was forced to halt production across multiple plants after suffering a catastrophic ransomware attack. The incident resulted in severe IT system disruption, suspended manufacturing operations, and subsequent data theft. A cybercrime group calling itself 'Scattered Lapsus$ Hunters' – reportedly linked to Scattered Spider and ShinyHunters – claimed responsibility, providing evidence of internal SAP system access. The attack’s impact exposed JLR’s business continuity vulnerabilities, prompted supply chain paralysis, and led the UK government to back a significant £1.5 billion loan guarantee to stabilize operations and prevent wider economic fallout. The breach highlights how ransomware actors are increasingly targeting critical manufacturing and supply chains for greater leverage. With mounting regulatory pressure and evolving attack tactics, strengthening enterprise resilience, zero trust architectures, and segmentation is more urgent than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Volvo NA Employee SSNs Exposed in 2023 Supply Chain Ransomware Attack
Impact· high

Volvo NA Employee SSNs Exposed in 2023 Supply Chain Ransomware Attack

In August 2023, Volvo Group North America (Volvo NA) suffered a significant data breach when its third-party HR software provider, Miljödata, was compromised by the DataCarry ransomware group. Attackers exploited weaknesses in Miljödata's cloud infrastructure, gaining unauthorized access and exfiltrating sensitive employee data—including names and Social Security numbers—belonging to nearly 20,000 Volvo NA employees. The incident, discovered days after the intrusion, led to a ransom demand before the stolen data was published on the Dark Web. While Volvo NA's own systems were not directly breached, the exposure of highly sensitive employee data has far-reaching implications for individual privacy and trust. This breach highlights growing risks from supply chain cyberattacks targeting SaaS providers and underscores the importance of rigorous third-party risk management. High-value employee PII leaks also raise urgent questions around operational resilience, compliance, and the potential for subsequent identity-driven fraud.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Stellantis 2024 Salesforce Supplier Breach: Lessons on Third-Party SaaS Risk
Impact· high

Stellantis 2024 Salesforce Supplier Breach: Lessons on Third-Party SaaS Risk

In June 2024, automaker Stellantis confirmed that a cybersecurity incident impacted some of its North American customers after attackers compromised a third-party service provider’s platform integrated with their Salesforce infrastructure. The breach exposed sensitive customer data, though financial and highly confidential information reportedly remained secure. The attackers exploited weaknesses in the external vendor’s environment to gain unauthorized access, demonstrating the risks inherent in today's interconnected supply chains. Stellantis responded by notifying affected customers, engaging security experts, and working closely with the vendor to contain and investigate the incident. This breach highlights the ongoing surge of supply chain and third-party risks as enterprises rely on hosted platforms like Salesforce for mission-critical operations. The event underscores the increasing sophistication of attackers targeting SaaS ecosystems and underscores the need for robust supplier security controls and monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)
Impact· medium

Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)

In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools. This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations
Impact· medium

Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations

In September 2025, a critical vulnerability (CVE-2025-5086, CVSS 9.0) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management software was found to be actively exploited in the wild. Threat actors leveraged this flaw to gain unauthorized access, bypassing authentication and executing arbitrary code on exposed systems. The breach impacted several manufacturing sector organizations globally, leading to disruptions in operational technology, potential data compromise, and urgent incident response actions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog and issuing public guidance for immediate patching and mitigation. This incident is significant as adversaries continue to target vulnerable OT/IoT platforms central to manufacturing operations. The increased frequency of high-severity vulnerabilities in critical infrastructure software, combined with rapid weaponization by threat actors, is driving regulatory scrutiny and highlighting the urgent need for robust vulnerability management and zero trust controls across industrial environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple CarPlay RCE Exploit: Most Cars Remain Vulnerable in 2024
Impact· medium

Apple CarPlay RCE Exploit: Most Cars Remain Vulnerable in 2024

In early 2024, security researchers disclosed a serious remote code execution (RCE) vulnerability affecting Apple CarPlay integrations in numerous vehicles. The exploit enables attackers to send maliciously crafted data via the CarPlay interface, potentially gaining control over in-vehicle systems or accessing sensitive driver data. Despite a fix being available, the diversity of manufacturers and slow fleet-wide software updates have left most vehicles exposed, raising concerns about the integrity and safety of modern vehicular systems. Automakers’ challenges in distributing timely patches have amplified risks for consumers and enterprises relying on smart car features. This incident underscores the growing cybersecurity challenges presented by increasingly connected and software-driven vehicles. With threat actors continually probing automotive systems and regulatory scrutiny on the rise, failure to promptly remediate such vulnerabilities could result in regulatory penalties, reputational damage, or physical safety incidents.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing
Impact· medium

Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing

In early 2024, Bridgestone Americas, a leading tire manufacturer, experienced a cyberattack that impacted several of its North American manufacturing plants. The incident led to operational disruptions, with reports confirming at least one plant in Quebec suspending activity. Bridgestone acted promptly, implementing its established cyber incident response protocols and containing the breach while launching a forensic investigation to determine the incident's scope. According to statements from company officials and local authorities, no employee or customer data was reported compromised, and business operations have largely returned to normal as of the latest updates. This attack highlights how IT/OT convergence in manufacturing continues to expose critical infrastructure to cyber threats, even in the absence of clear threat actor attribution or significant data loss. The event underscores the rising necessity for robust east-west security controls and rapid response capabilities within industrial environments facing increasing cyber risk.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports