CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Report warns supplier hacks could cost automakers $100M

A Munich Re and TUV SUD study prices third-party cyberattacks on car suppliers at up to $100M in potential liability.

CarThreat Staff
Last updated: August 14, 2026 10:13 pm
By
ctadmin
2 Min Read
SHARE

Modern vehicles are so dependent on outside technology that a breach at a third-party supplier can now cost automakers tens of millions of dollars without a single car being hacked. That is the core warning of a joint study from Munich Re and TUV SUD, reported by Risk & Insurance on August 13.

The report’s anchor case unfolded in March 2026, when a cyberattack hit a US breathalyzer technology provider and knocked out ignition interlock systems. Vehicles were not hacked directly, yet drivers were left stranded. The researchers estimate 15,000 to 30,000 of roughly 150,000 users were directly affected, with losses of $500 to $2,000 per vehicle. Aggregated availability-driven losses reach $7.5M to $60M, and class-action exposure could top $100M depending on participation and settlement outcomes.

Two older incidents illustrate the pattern. A 2023 Rivian over-the-air software update disrupted fleets despite involving no malicious activity, and 2024 vulnerabilities in Kia’s connected vehicle platform allowed unauthorized access through backend systems. Both show how a single failure can scale across an entire fleet through system-level dependencies.

The study sketches four liability scenarios: OEM liability for architecture flaws or backend outages, service provider liability for cloud and telematics failures, driver liability for misuse, and supply chain liability for vulnerable components. UN Regulation 155 makes cybersecurity a continuous lifecycle obligation for OEMs, while the EU’s revised Product Liability Directive expands product defect definitions to cover cybersecurity vulnerabilities and inadequate software updates. Munich Re and TUV SUD are developing a joint framework to rate cybersecurity maturity across the vehicle ecosystem.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityRegulationsSupply ChainUNECE R155Vehicle Software
SOURCES:Risk & Insurance
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

My Eicher fleet API flaws exposed 676,000 trucks to takeover
Cybersecurity

My Eicher fleet API flaws exposed 676,000 trucks to takeover

By
ctadmin
August 1, 2026
Cybersecurity

ECU Hardening Offers Alternative to CAN Protocol Replacement for Automotive Security

By
ctadmin
May 29, 2026
Cybersecurity

Fuzzing tool finds denial-of-service bug in V2X message gateways

By
ctadmin
August 13, 2026
CybersecurityIndustry & Culture

Tata Electronics breach leaks Apple and Tesla supply chain secrets

By
ctadmin
July 18, 2026
Cybersecurity

Quantum-safe update handshake keeps low-power ECUs safe on the road

By
ctadmin
August 12, 2026
Cybersecurity

Valeo and Zuken Launch Joint AI Platform to Speed Up Automotive Electronics Design

By
ctadmin
May 30, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?