Home / Other / Horror on the Roads: Hackers Attack Cars in Search of Data

Horror on the Roads: Hackers Attack Cars in Search of Data

About a week ago, the media reported on robotaxis that grouped for unknown reasons and stopped at an intersection, blocking all traffic. These were autonomous vehicles from Cruise that drive the streets of San Francisco, and traffic was blocked until employees from the company arrived to remove them one by one from the road. After the incident, a Cruise spokesperson stated that the vehicles grouped by themselves but did not specify the causes. It is very possible that it was some kind of hacking attack; fortunately, the incident occurred at night when there was less traffic, so there was no significant damage. If it was a hacking attack, it would not be surprising, as the frequency of cyberattacks on cars has increased by 225% from 2018 to 2021, according to a report from Upstream, a cybersecurity platform for connected vehicles.

It can be

The most significant increase occurred last year because every new car is somehow connected to the network, but as New York University scientist Justin Cappos once said, ‘every car produced after 2005 can be remotely controlled by hackers if they know how.’ One of the most famous car hacks occurred in 2015 when cybersecurity researchers Charlie Miller and Chris Valasek, who now work for the aforementioned robotaxi company Cruise, hacked a Jeep Cherokee from over sixteen kilometers away while it was in motion. They could start and stop the car without any issues, control the brakes, wipers, air conditioning… In fact, they could do whatever they wanted, needing only a laptop and the internet. After the incident, Jeep recalled 1.4 million vehicles to address this security issue.

Everything is a target

Last September, hackers in London stole 25 luxury cars using what the media described as ‘sophisticated hardware’, and in Oakville, Canada, a city with about two hundred thousand residents, 124 vehicle thefts were reported in just the first half of the year. Sixty-six percent of those thefts occurred due to contactless keys, meaning that thieves copied smart keys and signals from the cars.

Experts can take control of every car produced after 2005 remotely. Allegedly, hackers do not attack cars to destroy them, but mainly for theft – of data.

Not only cars are targets: two large Israeli public transport companies were recently hit by ransomware, and stolen data found its way to the dark web and its known marketplaces. In addition to the stolen data, the companies’ websites were also inaccessible, i.e., down. Along with all vehicles susceptible to hacking, even electric vehicle chargers were targeted by hackers. Upstream reports that hackers can – remotely, of course – turn chargers on or off, deny the owner access to the charger, and can even steal the owner’s identity during charging. The report states that almost all chargers they tested were vulnerable to attacks.

Huge losses

Such incidents will become more frequent, and Upstream predicts that the automotive industry will lose $505 billion due to cyberattacks by 2024. As if the last two years haven’t been tough and stressful enough… It should be added that in 2018 there were 330 million connected cars, and it is estimated that this number will jump to 775 million by next year, opening up many opportunities for hackers. Last year, nearly 85% of attacks were carried out remotely, and the main targets were data, in 38% of cases. Regarding car theft, 50% of them occur due to hacking attacks on car keys. In this case, hackers must be near the keys to capture the signal, which they then simply reproduce, and – voilà! In any case, car manufacturers are in distress. As the automotive industry continues to evolve towards greater digitalization and autonomy, the sophistication of hackers will also increase, giving them even more options and opportunities to ‘enter’ highly digitized cars in the near future.

Huge possibilities

Hacking attacks on cars today can range from harmless and mildly annoying to catastrophic. Hackers can steal personal data from drivers or eavesdrop on conversations, which might be useful for the DORH, police, and similar institutions, so their employees no longer have to crawl under the cars of suspects (if only they had some capable ones in their ranks, but that’s another story). However, they can also be less harmless, causing sudden accelerations, brake failures, and similar issues, which is, in fact, the biggest headache for people in the auto industry. A whole fleet could also be taken over, as may have happened with the robotaxis. Last year, a nonprofit group from Santa Monica, California, Consumer Watchdog, sent a message to all Teslas on their screens: !Hacked!

– Taking control of the direction of a car’s movement and its speed worries everyone in the industry – says Ami Dotan, CEO of Security Karambe, a vehicle security company, adding that everyone is aware that this could happen.

The challenge could be even greater than securing global air carriers. According to a report by McKinsey & Company on automotive cybersecurity, modern vehicles use about 150 electronic control units and around a hundred million lines of code, and by 2030, with the emergence of autonomous driving features and so-called vehicle-to-vehicle communication, the number of lines of code could triple. There are not even that many in the passenger aircraft Boeing 787 Dreamliner (it has only 15 million).

Almost 85% of cyberattacks on cars last year were carried out remotely, and the main targets were data, in 38% of cases. When car thieves play hackers, in 50% of cases, they carry out the theft by attacking car keys. In this case, hackers must be near them to capture the signal, which they then simply reproduce, and – voilà!

Because of all this, car manufacturers realize that just one successful hacking attack could deal a significant blow to the entire industry and cause massive headaches for their PR teams. They are particularly concerned about those with fleets and large vehicle parks.

New guidelines

Until now, vehicle cybersecurity has been reduced to patching or patchwork, without international standards or regulations, but that will soon change as this year the United Nations Regulation on Vehicle Cybersecurity came into force, ‘which obliges manufacturers to conduct various risk assessments and report intrusion attempts to confirm cybersecurity readiness.’ It will come into force for all vehicles sold in Europe in July 2024, and in Japan and South Korea in 2022. Although the United States is not among the 54 signatories, vehicles sold in America will likely be manufactured to meet various cybersecurity standards, as required by the UN.

How to protect yourself

Protection against hacking means going back to basics. Car manufacturers must require and confirm that every company in the supply chain makes regular and complete backups. Similarly, large and small companies must continuously update their systems and install all software patches, from server software to web applications. Two-factor authentication, password managers, and training to recognize phishing scams are also key tools for protecting car manufacturers from hacking attacks. One thing is certain: everything that were classic security measures in many IT and online companies must now be mirrored in the automotive industry, which must learn everything that many internet companies already know. Without good protection, a hacking attack will happen – it’s just a matter of time.