The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Automotive
Breach intelligence, attack campaigns, and threat reports targeting the Automotive sector.
Explore Other Sectors
Automotive Threat Reports
Volvo NA Employee SSNs Exposed in 2023 Supply Chain Ransomware Attack
In August 2023, Volvo Group North America (Volvo NA) suffered a significant data breach when its third-party HR software provider, Miljödata, was compromised by the DataCarry ransomware group. Attackers exploited weaknesses in Miljödata's cloud infrastructure, gaining unauthorized access and exfiltrating sensitive employee data—including names and Social Security numbers—belonging to nearly 20,000 Volvo NA employees. The incident, discovered days after the intrusion, led to a ransom demand before the stolen data was published on the Dark Web. While Volvo NA's own systems were not directly breached, the exposure of highly sensitive employee data has far-reaching implications for individual privacy and trust. This breach highlights growing risks from supply chain cyberattacks targeting SaaS providers and underscores the importance of rigorous third-party risk management. High-value employee PII leaks also raise urgent questions around operational resilience, compliance, and the potential for subsequent identity-driven fraud.
8 months ago
Kill Chain
Stellantis 2024 Salesforce Supplier Breach: Lessons on Third-Party SaaS Risk
In June 2024, automaker Stellantis confirmed that a cybersecurity incident impacted some of its North American customers after attackers compromised a third-party service provider’s platform integrated with their Salesforce infrastructure. The breach exposed sensitive customer data, though financial and highly confidential information reportedly remained secure. The attackers exploited weaknesses in the external vendor’s environment to gain unauthorized access, demonstrating the risks inherent in today's interconnected supply chains. Stellantis responded by notifying affected customers, engaging security experts, and working closely with the vendor to contain and investigate the incident. This breach highlights the ongoing surge of supply chain and third-party risks as enterprises rely on hosted platforms like Salesforce for mission-critical operations. The event underscores the increasing sophistication of attackers targeting SaaS ecosystems and underscores the need for robust supplier security controls and monitoring.
8 months ago
Kill Chain
Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)
In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools. This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.
8 months ago
Kill Chain
Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations
In September 2025, a critical vulnerability (CVE-2025-5086, CVSS 9.0) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management software was found to be actively exploited in the wild. Threat actors leveraged this flaw to gain unauthorized access, bypassing authentication and executing arbitrary code on exposed systems. The breach impacted several manufacturing sector organizations globally, leading to disruptions in operational technology, potential data compromise, and urgent incident response actions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog and issuing public guidance for immediate patching and mitigation. This incident is significant as adversaries continue to target vulnerable OT/IoT platforms central to manufacturing operations. The increased frequency of high-severity vulnerabilities in critical infrastructure software, combined with rapid weaponization by threat actors, is driving regulatory scrutiny and highlighting the urgent need for robust vulnerability management and zero trust controls across industrial environments.
8 months ago
Kill Chain
Apple CarPlay RCE Exploit: Most Cars Remain Vulnerable in 2024
In early 2024, security researchers disclosed a serious remote code execution (RCE) vulnerability affecting Apple CarPlay integrations in numerous vehicles. The exploit enables attackers to send maliciously crafted data via the CarPlay interface, potentially gaining control over in-vehicle systems or accessing sensitive driver data. Despite a fix being available, the diversity of manufacturers and slow fleet-wide software updates have left most vehicles exposed, raising concerns about the integrity and safety of modern vehicular systems. Automakers’ challenges in distributing timely patches have amplified risks for consumers and enterprises relying on smart car features. This incident underscores the growing cybersecurity challenges presented by increasingly connected and software-driven vehicles. With threat actors continually probing automotive systems and regulatory scrutiny on the rise, failure to promptly remediate such vulnerabilities could result in regulatory penalties, reputational damage, or physical safety incidents.
8 months ago
Kill Chain
Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing
In early 2024, Bridgestone Americas, a leading tire manufacturer, experienced a cyberattack that impacted several of its North American manufacturing plants. The incident led to operational disruptions, with reports confirming at least one plant in Quebec suspending activity. Bridgestone acted promptly, implementing its established cyber incident response protocols and containing the breach while launching a forensic investigation to determine the incident's scope. According to statements from company officials and local authorities, no employee or customer data was reported compromised, and business operations have largely returned to normal as of the latest updates. This attack highlights how IT/OT convergence in manufacturing continues to expose critical infrastructure to cyber threats, even in the absence of clear threat actor attribution or significant data loss. The event underscores the rising necessity for robust east-west security controls and rapid response capabilities within industrial environments facing increasing cyber risk.
8 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.
8 months ago
Kill Chain
Exploits for Dassault DELMIA Apriso RCE (CVE-2025-5086) Target Manufacturing Operations
In June 2025, Dassault Systèmes disclosed a critical deserialization vulnerability (CVE-2025-5086) in its DELMIA Apriso Manufacturing Operation Management system, affecting releases from 2020 through 2025. Attackers exploited this remote code execution flaw via crafted SOAP requests containing malicious serialized data, enabling them to upload and execute arbitrary Windows executables on vulnerable servers. The exploit activity, orchestrated through automated scanners—some associated with the Project Discovery framework—originated from multiple geographies and targeted the core manufacturing process integration point, posing risks to operational uptime and potential lateral movement within enterprise environments. This incident underscores the growing threat targeting industrial control applications and critical infrastructure through software supply chain vulnerabilities. Exploiting deserialization bugs in widely deployed operational technology platforms has become a preferred method for threat actors, highlighting the urgent need for timely patching, application-layer anomaly detection, and zero trust segmentation within manufacturing and industrial settings.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports