Tuesday, September 15, 2026

Joint Exercise to Address Vehicle Hacking Threats...MOLIT, Police, and Hyundai Motor Company Join Forces

Input
2026-09-15 11:00:00
Updated
2026-09-15 11:00:00
Photo: Yonhap News Agency

[Financial News] A public-private joint exercise will be held to prepare for situations in which a vehicle is hacked while in operation and behaves contrary to the driver’s intentions. The government plans to strengthen its automotive cybersecurity response capabilities by reviewing the entire process as if it were a real incident—from detecting and reporting the accident to containing its spread, restoring the vehicle, and preventing recurrence.
The Ministry of Land, Infrastructure and Transport (MOLIT) announced on the 15th that it will conduct a “Public-Private Joint Tabletop Exercise for Responding to Automotive Cybersecurity Incidents” at Hyundai Motor Company’s Pangyo AVP headquarters, together with the Korea Transportation Safety Authority’s Korea Automobile Testing & Research Institute (KATRI), the Korea Internet & Security Agency (KISA), the Korean National Police Agency, and Hyundai Motor Company.
The exercise was organized to verify in advance whether response procedures and cooperation among relevant organizations would function smoothly during an actual incident following the implementation of the Cyber Security Management System (CSMS) for vehicles. Rather than hacking an actual vehicle or system, the exercise will assign a simulated incident scenario in stages, with each organization carrying out reporting, notification, and response measures as it would in a real incident.
The exercise assumes that a server belonging to an automotive parts supplier is hacked and that software containing malware is distributed to vehicles through an over-the-air (OTA) update, causing them to malfunction. The scenario reflects the possibility that, as vehicles transition to software-defined vehicles (SDVs), the impact of a cyberattack could spread beyond individual vehicles across the entire supply chain, including automakers and parts suppliers.
The exercise will proceed in the following order: △detecting and reporting the incident and containing its spread; △analyzing the cause and coordinating with relevant organizations; △taking short-term measures to restore vehicles; △taking final measures to address vulnerabilities and strengthen supply-chain security; and △verifying the appropriateness of the measures and closing the incident.
Specifically, the exercise will review the cooperation system among relevant organizations, beginning with Hyundai Motor Company detecting abnormal signals and reporting the incident, followed by KATRI’s technical review and report to MOLIT, KISA’s analysis of the cause of the intrusion, and the Korean National Police Agency’s tracking and investigation of the hacker. The participants will then follow actual procedures through the entire process, from containing the spread of the incident—including suspending software distribution, restoring vehicles by distributing improved software, tracking vehicles that have not received the necessary measures, and strengthening vehicle defense layers and supplier security—to preventing recurrence and closing the incident.
A MOLIT official said, “Unlike ordinary cybersecurity incidents, automotive cybersecurity incidents are directly linked to the lives and safety of the public. As cyberattacks become more sophisticated and frequent, including recent intrusions into automakers’ supply chains using AI, we will use this joint exercise as an opportunity to continuously improve the roles of relevant organizations and their cooperation system. We will also build an automotive cybersecurity environment that prioritizes national security and public safety.”

[email protected] Reporter Jeong Gyeong-su Reporter