A hijacked software rollout was the plot. On September 15, Korean officials and Hyundai engineers walked through it together at the automaker's Pangyo campus, in the country's first joint public-private simulation of an automotive cyberattack.
The transport ministry convened the exercise. A vehicle safety research institute supplied technical reviewers, the national cyber agency traced the intrusion, and police opened an investigation alongside the manufacturer.
The intruders never touched Hyundai's own network. They breached a parts supplier instead and rode a legitimate over-the-air update into customer cars, which then behaved in ways nobody behind the wheel had asked for, steering among them. Five stages followed: detection, technical review, tracing with a police case, a halted rollout and corrected update, then a hunt for unpatched vehicles and pressure on the supplier.
Drivers in America carry the downside of the gap. No federal audit stands between a weak security programme and a showroom, because NHTSA's guidance binds nobody by its own description, the agency declined to import R155-style duties, and the country runs neither a type-approval process nor a seat at the UN agreement the standard rests on.
Seoul chose the approval itself as its lever. A February 2024 rewrite of the Motor Vehicle Management Act means a manufacturer that cannot demonstrate a cybersecurity management system may be refused permission to sell, or lose it later. UNECE R155, Europe's benchmark, sets the bar. New model lines entered scope in August 2025, and everything already on Korean roads follows in August 2027.