Hyundai AutoEver America, an IT solutions affiliate of Hyundai Motor Group, suffered a cyberattack that compromised its IT environment between February 22 and March 2, 2025. The breach resulted in unauthorized access to sensitive personal information, including names, Social Security numbers, and driver's license details. The company discovered the intrusion on March 1 and immediately launched an investigation with external cybersecurity experts, also notifying law enforcement. The breach notification was confirmed by both the company and the Massachusetts government portal, though the total number of affected individuals and whether employees or customers were impacted remains unclear.
No ransomware group has claimed responsibility for the incident, and there is no evidence yet of data misuse. Hyundai AutoEver America provides IT services for Hyundai and Kia affiliates, supporting vehicle telematics, over-the-air updates, and digital manufacturing platforms. The breach follows a series of cybersecurity incidents affecting Hyundai Motor Group, including ransomware attacks and data exposures in its European operations. The company has not disclosed further details on the extent of the breach or the specific systems compromised.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Hyundai AutoEver America publicly disclosed that the earlier 2025 cyberattack resulted in a personal data breach. Reporting said the company had not clarified the full scope of affected individuals, and no ransomware group had publicly claimed the intrusion at that time.
Hyundai AutoEver America said an unauthorized party accessed its IT environment between 2025-02-22 and 2025-03-02. The intrusion exposed personal information including names, driver's license data, and Social Security numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.