Black Basta claimed three terabytes of data from Hyundai Motor Europe
- Organization
- Hyundai Motor Europe
- Exploit
- Ransomware
- Industry
- Automotive
Hyundai Motor Europe, the German-headquartered division that oversees the carmaker's European operations, confirmed in February 2024 that an unauthorized third party had accessed part of its network. The company said the access covered a limited part of the network, that external cybersecurity and legal experts were assisting, and that the relevant authorities had been informed.
The confirmation followed a claim by the Black Basta ransomware group, which shared with BleepingComputer an image listing folders it said had been stolen from several Windows domains, including domains belonging to Kia's European business. The group put the total at three terabytes of corporate data. Folder names pointed to material from legal, sales, human resources, accounting, IT and management functions. Cybernews reported that at the time of its own coverage it had seen no mention of Hyundai or the allegedly stolen data on Black Basta's dark web leak site.
The intrusion traced back to early January 2024, when Hyundai Motor Europe experienced disruption it initially described to reporters as IT issues without linking it to an attack. The company acknowledged a cyberattack only after journalists put the leak site claims to it.
No sample files, victim counts or ransom figure were made public, and Hyundai did not say whether customer or employee personal data was among the material taken. The three terabyte figure came from the attackers and was never independently verified. The company gave no further detail while its investigation continued.
Sources
- Security Affairs, Black Basta ransomware gang hacked Hyundai Motor Europe
- Born's Tech and Windows World, Hyundai Motor Europe victim of the Black Basta ransomware
- BleepingComputer, Hyundai Motor Europe hit by Black Basta ransomware attack
- Cybernews, Hyundai Europe claimed as latest ransom victim of Black Basta