The increasing digitalization of transportation has significantly expanded the attack surface: ransomware against manufacturers, fleet sabotage, shipment manipulation, and attacks on electric charging infrastructures are among the main risks identified.
Modern vehicles already come with complex digital devices, with extensive remote communication capabilities and constant connection to cloud infrastructures. This evolution increases functionalities but also risks.
Cybersecurity, moreover, acquires special relevance for the sector. The report highlights the growing impact of attacks on critical infrastructures and essential operators, in a context of accelerated digitalization.
The cybersecurity company Kaspersky has identified the main threats that could affect the automotive industry and transportation infrastructures.
Cyberattacks on manufacturers and supply chain
Economically motivated cyberattacks will continue to be predominant, especially through ransomware. The objective is to encrypt files, systems, or entire networks to demand a ransom, usually in cryptocurrencies, in exchange for restoring access. Additionally, new leaks of confidential data, both from users and linked to vehicle movements, could occur.
Another relevant vector is the cyberattack on the supply chain. Cybercriminals can compromise contractors or technology providers to subsequently access critical systems of manufacturers, generate operational disruptions, and cause economic losses.
Targets: fleets, carsharing, and logistics
Taxi, carsharing, transportation, and logistics infrastructures are also targets for cybercriminals. The theft of personal data and access to user accounts remain goals for cybercriminals. Likewise, ransomware cyberattacks aimed at paralyzing critical systems could directly affect business operations.
A particularly concerning risk is the remote blocking of vehicles. Many companies install modules that allow remote control of cars. If cybercriminals gain access to these systems, they could immobilize entire fleets for extortion or sabotage purposes.
Refueling and charging infrastructures
In the logistics field, the digital manipulation of transport orders can end in the physical theft of goods. The comprehensive digitalization of the supply chain allows altering shipment data and redirecting loads to fraudulent addresses without the need for direct physical intervention.
Gas stations and electric vehicle charging stations are increasingly connected to cloud infrastructures. This connectivity provides new opportunities for cybercriminals. Cyberattacks aimed at these platforms can steal fuel or electricity, as well as customers’ personal data or information associated with refueling cards.
Vulnerabilities in vehicle architecture
The proliferation of vehicles with multiple electronic control units (ECUs) expands the possible entry points. Implementation errors and technical vulnerabilities can be exploited for car theft.
A recent case demonstrated that it was possible to access the CAN bus of vehicles from a manufacturer through a headlight, subsequently obtaining access to the start system. Experts foresee new vulnerabilities will be identified for similar purposes. Potentially exploitable interfaces include the CAN bus, the OBD port, Ethernet ports, NFC modules, Wi-Fi and Bluetooth chips, or the LTE modem.
Since the computer systems embedded in modern vehicles are directly or indirectly connected to the internet, attacks against them are, in many cases, a matter of time. To develop resilient systems, it is essential to incorporate security principles from the design and development phases, with the aim of mitigating risks and reducing the likelihood of vulnerability exploitation.
Advice
To reduce exposure to these threats in the transportation and automotive sector, Kaspersky experts recommend:
- Integrating cybersecurity from the design of vehicles and their electronic systems.
- Conducting regular security audits to identify and correct vulnerabilities early, both in manufacturers and supply chain providers.
- Protecting corporate and industrial network endpoints with specialized solutions that include protection against ransomware and other advanced threats.
- Evaluating the implementation of secure gateways that isolate and control communications between vehicle systems and the outside.
