Modern vehicles are so dependent on outside technology that a breach at a third-party supplier can now cost automakers tens of millions of dollars without a single car being hacked. That is the core warning of a joint study from Munich Re and TUV SUD, reported by Risk & Insurance on August 13.
The report’s anchor case unfolded in March 2026, when a cyberattack hit a US breathalyzer technology provider and knocked out ignition interlock systems. Vehicles were not hacked directly, yet drivers were left stranded. The researchers estimate 15,000 to 30,000 of roughly 150,000 users were directly affected, with losses of $500 to $2,000 per vehicle. Aggregated availability-driven losses reach $7.5M to $60M, and class-action exposure could top $100M depending on participation and settlement outcomes.
Two older incidents illustrate the pattern. A 2023 Rivian over-the-air software update disrupted fleets despite involving no malicious activity, and 2024 vulnerabilities in Kia’s connected vehicle platform allowed unauthorized access through backend systems. Both show how a single failure can scale across an entire fleet through system-level dependencies.
The study sketches four liability scenarios: OEM liability for architecture flaws or backend outages, service provider liability for cloud and telematics failures, driver liability for misuse, and supply chain liability for vulnerable components. UN Regulation 155 makes cybersecurity a continuous lifecycle obligation for OEMs, while the EU’s revised Product Liability Directive expands product defect definitions to cover cybersecurity vulnerabilities and inadequate software updates. Munich Re and TUV SUD are developing a joint framework to rate cybersecurity maturity across the vehicle ecosystem.