Download of Record of Default (RoD) is disabled for creditors - To request for RoD, please call RoD Hotline No 88673 92123 or Email at rod@nesl.co.in

Cyber incident in the Automotive Industry with Global Impact

Middle of last quarter witnessed a massive cyber incident that led to shutting down of manufacturing sites of a major automobile manufacturing company and also disrupting the entire supply chain. The incident caused threats to the jobs of thousands in the ecosystem and made a massive loss to the company. It is learned that the company had not availed any insurance coverage against cyber offences. The complete recovery is yet to be achieved even after weeks.

Even though there were some indicators during the previous quarter in the dark web related to possible data leakage (by HELLCAT, a ransomware group), a major hit came towards end of August 2025. A criminal group calling themselves “Scattered Lapsus$ Hunters” claimed the credit and showcased the exploits through internal information including documentation, debug logs, backend code etc.

The company, which released a statement on Cyber Incident on 02nd September 2025 and informed the world officially that it has been impacted and is proactively shutting down the systems. In this initial release company informed that there is no evidence of customer data being stolen, but their retail and production activities are severely disrupted. Later on 10th September 2025 company informed that as part of investigations, it is believed that some data has been affected and being informed to the relevant regulators. The mitigation steps and phased restart of the services are in progress, and the status is being informed by the company through regular updates in the “Response to Cyber Incident” releases.

The impact was multi-fold affecting company’s own manufacturing units spread across five or more countries including India and the overall ecosystem of suppliers, distributors and retailers/dealers spread across the globe.

National Crime Agency (NCA), an agency focused on tackling serious and organized crime in UK along with National Cyber Security Centre (NCSC), which provides cybersecurity guidance and incident response in UK is also actively investigating the case. Even though the mode of operation is similar to ransomware groups, there was no evidence of demand for ransom. The investigators suspect the support and direct involvement of nation-stateactors, targeting a country in the current geo-political warfare.

In view of the digital footprint in the companies worldwide irrespective of the domain of operation or the size, this cyber incident brings many lessons back to the forefront.

  • The quick decisions to shut down/isolate IT systems in its global operations helped the company to contain the breach by nullifying possibility of lateral movements by offenders and stopping additional damages. This throws light to the need of a predefined incident response plan and practicing the incident responses through drills and tabletop exercises.
  • Use of compromised user credentials and privilege escalation is suspected through phishing methods, which emphasis the need for multi-factor authentication, concept of least privilege access, regular credential rotation, robust privilege access management mechanisms and regular user access audits.
  • The attack is also suspected to be through a vulnerability in the software supply chain leading to need for third party risk management framework and constant review of risks with respect to critical third-party integrations. The Cyber Security and Cyber Resilience Framework (CSCRF) released by SEBI in India mandates a Software Bill of Materials (SBOM) for all regulated entities which helps in better management of third-party risks in the software supply chain. A proper inventory of both hardware and software assets with traceability of the deployment changes is essential. Legacy systems, if any are to be identified, protected with focussed security controls and to be replaced at the earliest possible
  • This incident also highlights the need for enforcing the Business continuity policies and procedures and testing of the capabilities through frequent drills and tabletop exercises. The BCP to be extended to all critical functions including third party integrations.
  • Another aspect to the incident is the need for implementation towards Zero-TrustArchitecture (ZTA), which works with a notion that internal systems may already be compromised. This model requires continuous verification of users, devices, and services before granting any access and principle of least privilege is applied. The overall concept of ZTA is that none of the users or systems should be trusted by default, irrespective of whether it is in inside zones (trusted zone in earlier concepts) or outside zones (untrust).

-by Jyothish Jolisa
VP (Information Security) & CISO

Leave a Reply

Your email address will not be published. Required fields are marked *