Cyberattacks On Outside Suppliers Threaten Automakers With Millions In Liability

A 2026 breach at an automotive tech provider left up to 150,000 drivers unable to use their vehicles, illustrating how third-party digital failures can expose automakers to liability, according to Munich Re and TÜV SÜD.
By: | August 13, 2026
auto manufacturing

Connected and software-defined vehicles have turned automotive cyber risk from a product security problem into a systemic ecosystem risk, according to a joint report from Munich Re and TÜV SÜD, a global testing and certification provider.

In a March 2026 incident, a cyberattack on a U.S. breathalyzer technology provider disrupted ignition interlock systems without hacking the vehicles directly, yet still caused large-scale immobilization. Based on publicly available information, the report estimates that 15,000 to 30,000 vehicles were directly affected out of roughly 150,000 users, with per-vehicle losses of $500 to $2,000 depending on duration and usage type.

That puts aggregated availability-driven losses at an estimated $7.5 million to $60 million, the report said, while potential class-action litigation exposure could exceed $100 million depending on participation rates and settlement dynamics. Corporate costs for incident response, remediation and reputational impact are likely to reach tens of millions of dollars, according to the report.

The report also cited a 2023 Rivian over-the-air software update incident, which caused widespread customer disruption across vehicle fleets without any malicious activity, and 2024 vulnerabilities in Kia’s connected vehicle platform that allowed unauthorized access to vehicle-related functions through backend systems rather than the vehicles themselves.

Together, these cases show that modern automotive cyber risk is defined by system-level dependencies and rapid, fleet-wide scalability, the report said.

Liability Is Fragmenting Across OEMs, Vendors And Suppliers

Cyber incidents in connected vehicle ecosystems create what the report calls a fragmented and interdependent liability structure, with responsibility depending on the origin of the failure, system architecture and degree of control across the ecosystem. The report outlines four liability scenarios:

  • OEM liability tied to vehicle architecture vulnerabilities or backend outages.
  • Connected service provider liability for failures in cloud, telematics or app systems.
  • Driver or operator liability for misuse or ignored warnings.
  • Supply chain liability for vulnerable third-party components or infrastructure outages.

In the breathalyzer case, the service provider operated independently from the OEM, resulting in a distributed liability model, the report said. Even so, OEMs may face secondary exposure where integration design lacks adequate fallback mechanisms, and supply chain actors may become involved through contractual recourse if the root cause lies upstream.

The report noted that OEM liability and service provider liability scenarios are increasingly converging as automakers expand their role in developing and operating connected-vehicle services, a trend expected to further blur the line between product liability and service liability.

Regulatory frameworks are reinforcing this shift. UN Regulation 155 establishes cybersecurity as a continuous lifecycle obligation for OEMs spanning development through end-of-life, while the European Union’s revised Product Liability Directive expands the definition of a product “defect” to include cybersecurity vulnerabilities and inadequate software updates, according to the report.

The EU’s Cyber Resilience Act, meanwhile, links cybersecurity requirements directly to market access, effectively setting the standard of care against which liability may later be judged under the Product Liability Directive.

Compliance Alone Won’t Close The Gap, Report Finds

Even in highly compliant environments, residual cyber risk remains unavoidable due to software complexity, ecosystem dependencies and evolving threats, the report said. Industry data cited in the report shows a rapid increase in reported automotive cybersecurity vulnerabilities since 2021, reflecting growing software complexity and connectivity.

To address this gap, Munich Re and TÜV SÜD are jointly developing a framework that assesses cybersecurity maturity across the vehicle ecosystem and translates it into a structured risk rating, combining TÜV SÜD’s automotive cybersecurity and certification expertise with Munich Re’s risk quantification and underwriting capabilities.

Rather than measuring minimum regulatory requirements, the framework evaluates actual control effectiveness against realistic loss scenarios, including service disruption, liability exposure, data breaches and digital fraud, according to the report. The goal, the report said, is to translate cybersecurity posture into insurable risk profiles, allowing coverage structures, limits and pricing to be aligned with an organization’s actual cybersecurity maturity rather than generic assumptions.

Obtain the full report here.

The R&I Editorial Team can be reached at [email protected].