-

New VicOne Cybersecurity Report Reveals Growing Automotive Data Exploitation, as Industry Examines Cyberattacks and Security Measures

VicOne Automotive Cyberthreat Landscape Report 2023 reveals supply chain as major source of growth in automotive cyberattacks

DALLAS & TOKYO--(BUSINESS WIRE)--VicOne, an automotive cybersecurity solutions leader, today announced the availability of VicOne Automotive Cyberthreat Landscape Report 2023. Based on data from automotive original equipment manufacturers (OEMs), suppliers and dealers globally, the comprehensive VicOne report details:

  • Growth in usage and monetization of automotive data—and, in turn, threat of exploitation by cybercriminals
  • Trends and incidents that have arisen this year in the dynamic automotive cyberthreat landscape
  • Predictions of upcoming developments and key focus areas for an effective cybersecurity strategy for the next year and beyond

“In our analysis of the threat landscape, we noticed that the losses from cyberattacks in the first half of the year exceeded US$11 billion, marking an unprecedented surge compared to the last two years,” reads VicOne Automotive Cyberthreat Landscape Report 2023. “A closer examination reveals that these cyberattacks predominantly targeted automotive suppliers, indicating a rising trend. Alarmingly, over 90% of these attacks were not aimed at OEMs themselves but rather at other entities in the supply chain. Attackers often find it difficult to penetrate well-protected companies, so they target less vigilant firms instead. But OEMs are affected all the same, because of the supply chain disruptions. Consequently, defending systems against cyberattacks is no longer just about securing an individual firm; it is about strengthening the entire supply chain.”

The new VicOne report untangles the cybersecurity issues developing along with the increasing complexity of vehicles and their integration of connectivity, automation and advanced driver assistance systems (ADAS). It shows that industry losses are growing from cyberattacks such as ransomware and exposure of leaked data or personally identifiable information (PII), as well as costs associated with system downtime. The calculations in VicOne Automotive Cyberthreat Landscape Report 2023 are based only on tangible costs related to technology and operations and not intangible costs such as branding, public relations, sales and marketing expenses.

The report identifies the top vulnerabilities by which vehicle data can be compromised, listing common weakness enumeration (CWE) vulnerabilities in tables. Out-of-bounds write (OOBW), out-of-bounds read (OOBR), buffer overflow, use after free and improper input validation vulnerabilities are among the most frequent issues that VicOne documented. Most of the issues were found on chipsets or systems-on-chip (SoCs), followed by vulnerabilities in third-party management applications and in-vehicle infotainment (IVI) systems. Third-party suppliers—including logistics providers, service providers and companies engaged in the production of components, accessories or parts—have emerged as a growing focus of attacks.

The VicOne report presents case studies on some of the key incidents from the last year, including the Zenbleed vulnerability, potentially leading to the leakage of sensitive data at a remarkably fast rate of 30kb/s per core; CAN bus injection, emerging as a favorite technique among vehicle thieves; and penetration of backend cloud infrastructure, by exploiting vulnerabilities in telematics systems and application programming interfaces (APIs).

While noting that there is currently a regulatory vacuum when it comes to vehicle data, the VicOne report points out that UN R155 will mandate safety conditions for newly manufactured cars by July 2024.

“It’s clear that the automotive industry needs to give higher priority to cybersecurity, in terms of resources and budget. That is something that must be happening continually—building up the processes, building up the organization, building up the talent, building up the entire system—or you will never be able to implement cybersecurity effectively,” said Max Cheng, chief executive officer of VicOne. “Now is the time for organizations throughout the global automotive industry to get serious about exploring how to build up their capabilities across the important focus areas that our new report covers.”

VicOne Automotive Cyberthreat Landscape Report 2023 is available at https://vicone.com/reports/automotive-cybersecurity-report-2023.

About VicOne

With a vision to secure the vehicles of tomorrow, VicOne delivers a broad portfolio of cybersecurity software and services for the automotive industry. Purpose-built to address the rigorous needs of automotive manufacturers, VicOne solutions are designed to secure and scale with the specialized demands of the modern vehicle. As a Trend Micro subsidiary, VicOne is powered by a solid foundation in cybersecurity drawn from Trend Micro's 30+ years in the industry, delivering unparalleled automotive protection and deep security insights that enable our customers to build secure as well as smart vehicles. For more information, visit vicone.com.

Contacts

U.S. Media Contact:
Vivian Kelly Interprose for VicOne
+1 703.509.5412
viviankelly@interprosepr.com

VicOne


Release Versions

Contacts

U.S. Media Contact:
Vivian Kelly Interprose for VicOne
+1 703.509.5412
viviankelly@interprosepr.com

More News From VicOne

VicOne Research Estimates Tens of Billions in Automotive-Cyberattack Losses, Plus Rising Vulnerabilities and Growing AI, EV and Dark-Web Risks

DETROIT & TOKYO--(BUSINESS WIRE)--VicOne, an automotive cybersecurity solutions leader, today announced in-depth analysis revealing concerning signs for the global automotive industry in 2025, despite promising law-enforcement success around cybersecurity in the last year. Shifting Gears: VicOne 2025 Automotive Cybersecurity Report, which is available to download, explores the rapidly evolving landscape of automotive cybersecurity, delivering actionable insights and emerging trends and data poi...

VicOne and Trend Micro Stage Pwn2Own Automotive Zero Day Vulnerability Event to Boost Industry Cybersecurity as SDV Trend Reshapes Threat

DETROIT & TOKYO--(BUSINESS WIRE)--VicOne, an automotive cybersecurity solutions leader, today announced that it co-hosted with Trend Micro the world’s largest zero-day vulnerability discovery contest, Pwn2Own Automotive 2025, at Automotive World, which took place Jan. 22-24 in Tokyo. Top-tier security researchers performed real-world testing on cutting-edge automotive technologies, all within Trend Micro’s proven Zero Day Initiative (ZDI) platform, the world’s largest vendor-agnostic bug bounty...

VicOne at CES 2025 Showcases Award-winning Cybersecurity Portfolio and Emphasize Growing Range of Best-of-Breed Partnerships

DETROIT & TOKYO--(BUSINESS WIRE)--VicOne, an automotive cybersecurity solutions leader, today announced its activities at CES 2025, which concludes today in Las Vegas. In addition to its own award-winning, comprehensive portfolio of cutting-edge cybersecurity software and services, VicOne is showcasing its industry-leading array of partnerships. “The automotive industry is so complex; no single company can secure it alone. We're building the industry’s broadest cast of best-of-breed partners to...
Back to Newsroom