KELA REPORT

German Automotive Sector Cybercrime Threats Landscape Report

The German automotive sector is one of the leading sectors in Germany.

Share:

KELA report cover: German Automotive Sector Cybercrime Threats Landscape Report

The automotive sector is considered to be the largest sector in Germany, generating over 411 billion euro in revenue. Germany is the largest automobile manufacturing country in Europe, producing 30% of all passenger cars in the EU in 2021. Automotive companies, their employees and users have frequently become targets of cybercriminals aiming to perform various attacks. One of the recent examples is an info-stealing campaign that targeted customers of German companies, mainly car dealers, with phishing emails aimed to infect the victims with info-stealing malware. Another recent cyberattack that occurred in March 2022, targeted a German subsidiary of Denso, a Japanese automotive supplier. The Pandora ransomware group announced that it compromised the network and shared screenshots of purchase orders, automotive technical diagrams, and emails on its blog. Moreover, the gang claimed to have stolen 1.4 TB of data from the company. Following the attack, Denso apologized for any inconvenience caused and confirmed that the German network was illegally accessed. With more and more vehicles connected to the internet and using many digital functions, major automotive companies are exposing cars to additional malicious activities and increasing the risk of cyberattacks. The recent cyber-attacks that have targeted the automotive industry in Germany drove KELA to investigate the level of exposure of the 15 largest German automotive manufacturers, suppliers, and dealers to shed light on cyber threats they faced from January 2021 to April 2022.

Key Report Highlights:

  • Demand for keyless-entry hacking tools and repeaters, while only 5% of 501 tested vehicles were protected from keyless theft
  • Databases, source code and SQL-injection vulnerabilities of German manufacturers for sale, including 2.7 million Audi USA records and the 3.3-million-customer Volkswagen breach
  • Close to 4,800 unique leaked credentials for 15 companies, mostly exposed through third-party breaches such as RedCappi, IndiaMART and JD
  • Over 5,600 compromised accounts on botnet markets, including Jira, internal email, Citrix and FortiClient VPN portals
  • Citrix access to a USD 2 billion parts manufacturer sold by an IAB, and 179 ransomware attacks on German companies, making Germany the sector’s second most targeted country

Download the Report

Related Resources

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested