Hyundai AutoEver America (HAEA), a subsidiary of Hyundai Motor Group, recently revealed that it suffered a serious cyberattackin which hackers gained access to data employee and customer. The incident was confirmed on March 1, 2025, but an internal investigation revealed that cybercriminals had been inside the systems as early as February 22.

The company, which specializes in IT solutions for the automotive industry, said that immediately after the discovery of the incident, it activated immediate response protocols and collaborated with external cybersecurity experts. At the same time, the relevant law enforcement authorities were informed, with the aim of fully investigating and identifying the perpetrators.
See also: Increase in ransomware attacks on European organizations
Who is Hyundai AutoEver America?
Hyundai AutoEver America is the technology arm of Hyundai Motor Group in the United States. The company provides IT consulting, infrastructure management, helpdesk support and software development for the entire automotive lifecycle — from production to vehicle retirement.
HAEA plays a critical role in connecting Hyundai and Kia’s digital services, including OTA (over-the-air) updates, maps, telematics and autonomous driving systems. According to its official website, it has 5,000 employees and serves over 2 million users, with its technologies already integrated into 2.7 million vehicles worldwide.

What kind of data was exposed?
Although the company has not yet released a full list of the leaked data, the notification sent to affected individuals lists names, while the official Massachusetts government portal adds that Social Security Numbers (SSN) and driver's licenses.
It is not clear whether the information concerns employees or customers, nor the exact number of victims. At this time, Hyundai AutoEver America and parent Hyundai Motor Group have not issued an official statement with further details.
The perpetrators remain unknown – no claim of responsibility
So far, no known ransomware group has claimed responsibility for the attack, which complicates the investigation. Typically, cybercriminal groups using ransomware publicize incidents to pressure companies into paying ransom. The silence, however, could indicate either targeted espionage or an attack with different motives, such as collecting data for resale on the dark web.
See also: Miljödata: Data breach affects 1.5 million people
A series of cybersecurity incidents for Hyundai
Hyundai is no stranger to cyberattacks. Over the past two years, the group has repeatedly been targeted. In 2023, European subsidiary was attacked by ransomware from the Black Basta, while shortly after, a data breach exposed the personal information of vehicle owners in Italy and France.

At the same time, cybersecurity researchers had identified serious vulnerabilities in the Hyundai Companion, through which malicious users could gain access to remote control functions of Kia and Hyundai vehicles. In addition, the cars' built-in anti-theft systems proved ineffective in some cases, calling into question the security of the company's digital systems.
The growing threat to the automotive industry
This particular attack confirms a worrying pattern: car manufacturers are now prime targets for hackers. As vehicles become “mobile computers” with internet connectivity, the attack surface is growing exponentially.
See also: Nikkei: Data breach affects 17,000 people
From infotainment systems to connectivity tools, every digital interface can be a weak link. Cybersecurity experts emphasize that the industry must adopt stricter security standards, implement regular penetration testing and invest in real-time threat detection technologies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Time for digital vigilance
The breach at Hyundai AutoEver America is a reminder that even the most technologically advanced companies are not invulnerable. With the digital transformation accelerating, the security of data and systems must be as high a priority as the security of the vehicles themselves.
Hyundai is now called upon not only to repair the damage, but also to restore the trust of its users – in an era where cybercrime is moving faster than ever.
Source: www.bleepingcomputer.com
