
South Korea will hold a joint public-private drill simulating a scenario in which a moving vehicle is hacked and components such as the steering wheel operate against the driver's intent. The government plans to strengthen automotive cybersecurity capabilities across the full response chain, from incident detection to containment, vehicle recovery and prevention of recurrence.
The Ministry of Land, Infrastructure and Transport said it will conduct the joint public-private simulation drill on automotive cybersecurity incident response on the 15th at Hyundai Motor's AVP Division in Pangyo, together with the Korea Automobile Safety Research Institute (KATRI) of the Korea Transportation Safety Authority, the Korea Internet & Security Agency (KISA), the Korean National Police Agency and Hyundai Motor.
The drill was arranged to check in advance whether cooperation among the agencies functions smoothly in an actual incident following the introduction of the Cyber Security Management System (CSMS) for vehicles. It assumes a scenario in which a server at an auto parts supplier is hacked and software containing hidden malicious code is distributed to vehicles through an over-the-air (OTA) update, causing them to malfunction. The scenario reflects the possibility that the impact of a cyberattack could spread across the entire supply chain, including automakers and parts suppliers, as the industry shifts toward software-defined vehicles (SDVs).
The exercise begins with Hyundai Motor detecting an abnormal signal and reporting the incident, then tests the cooperation framework among agencies, including KATRI's technical review and report to the transport ministry, KISA's analysis of the cause of the breach, and the police agency's tracking and investigation of the hacker. Participants will then carry out the entire process according to actual procedures, including halting software distribution, restoring vehicles by distributing corrected software, tracking vehicles that have not been fixed, and strengthening vehicle defense layers and supplier security.
"Unlike ordinary cybersecurity incidents, automotive cybersecurity incidents are directly linked to the lives and safety of the public," said Park Jun-hyung, director general of the ministry's Mobility and Automobile Bureau. "With cyberattacks such as AI-assisted infiltration of automakers' supply chains becoming more sophisticated and more frequent, we will build an automotive cybersecurity environment that puts national security and public safety first."






