19 Sep 2026, Sat

South Korea Just Rehearsed a Hacked Steering Wheel. The U.S. Never Wrote the Playbook.

A car speedometer and digital display showing a high road speed

Nobody’s steering wheel actually moved on September 15. That was the point.

Inside Hyundai’s Advanced Vehicle Platform division in Pangyo, South Korea, government officials, police investigators, and Hyundai engineers spent the day working through a scenario that had nothing to do with a hacker in a hoodie hijacking a car for the cameras. It started somewhere far more boring: a parts supplier’s server gets breached. Malicious code rides along inside a routine over-the-air software update. Vehicles that install it start behaving in ways their drivers never asked for, including, in the drill’s script, the steering.

That’s the whole plot. It’s also a far more useful story than any carjacking thriller, because it’s the one automakers, regulators, and now police actually have to plan for.

What Actually Happened in Pangyo

South Korea’s Ministry of Land, Infrastructure and Transport ran the country’s first joint public-private simulation of an automotive cyberattack, working alongside the Korea Automobile Safety Research Institute (KATRI), the Korea Internet & Security Agency (KISA), the National Police Agency, and Hyundai Motor, according to Seoul Economic Daily and STARNEWS, which both covered the event.

The scenario ran in five stages: Hyundai detects an abnormal signal and reports it; KATRI runs a technical review while KISA traces the breach and police begin hunting the intrusion; the automaker halts the tainted software rollout and pushes a corrected update; agencies track down vehicles that never got patched and lean on the supplier to close the hole that let the code through in the first place; everyone verifies the fix actually worked before calling the incident closed.

Notice what’s missing from that list. Nobody drove anywhere. Nobody towed a car. The entire response happened at the level of code, servers, and phone calls between agencies that don’t normally share an org chart. That’s the part worth sitting with: modern car safety increasingly lives in a conference call, not a service bay.

Why This Drill Exists Right Now

This wasn’t a one-off publicity stunt. It’s a rehearsal for a law that’s already in effect and about to get a lot more teeth.

In February 2024, Korea amended its Motor Vehicle Management Act to build in a Cybersecurity Management System, modeled on UN Regulation No. 155, the international cybersecurity standard the UN Economic Commission for Europe adopted back in 2020. Under UN R155, an automaker has to run a full risk assessment across a vehicle’s entire life, from development through years of use, implement and test mitigations for the threats it finds, keep monitoring vehicles after they’re sold, and, this is the detail that made this particular drill scenario realistic, explicitly manage the cybersecurity risk posed by its own suppliers. Fail the audit, and regulators can refuse or pull the vehicle’s type approval, the same authority they’d use to block a car that failed a crash test.

Korea’s version has been mandatory for newly registered vehicle types since August 2025. It extends to every existing mass-production model already on Korean roads starting in August 2027. That deadline is the real subject of this article. Hyundai and the Korean government just spent a day finding the gaps in an incident-response system before the harder date arrives and every car the company already sells has to comply.

The Gap Nobody’s Advertising

Here’s the part that should bother American car owners more than it currently does: nothing like this exists in the United States, and not by accident.

NHTSA’s own cybersecurity guidance, most recently updated in September 2022, says outright that it “does not have the force and effect of law and is not a regulation.” The agency went further in its Federal Register notice, explaining that it deliberately declined to build anything resembling UN R155 into its guidance, in part because the United States doesn’t perform vehicle type approval at all and isn’t even party to the international agreement that makes UN R155-style rules enforceable. American automakers self-certify that their vehicles meet federal safety standards. There’s no government cybersecurity audit standing between a bad CSMS and a car reaching a dealer lot, because there’s no type approval process for a regulator to withhold in the first place.

That leaves NHTSA to respond the way it always has: after the fact, through its defect and recall authority, once something has already gone wrong. Korea just demonstrated the alternative: a standing, rehearsed, multi-agency process built to catch a supply-chain hack before it reaches very many driveways.

Why the Supplier Is the Real Target

The drill’s chosen attack path is worth teaching, because it’s not the movie version of car hacking. Nobody in this scenario cracked Hyundai’s own network. They went after a parts supplier instead, then rode a legitimate OTA update straight past the front door.

Modern vehicles are assembled from software written by dozens of tiered suppliers, aggregated and signed before it ever reaches a car. That’s structurally the same weakness enterprise IT learned about the hard way during the 2020 SolarWinds breach, translated into a machine that also steers, brakes, and accelerates. Hyundai’s own push toward software-defined vehicles makes this more relevant, not less: the more of the car that lives in code shared across a supply chain, the more a single compromised vendor can act as a way in for everyone downstream. This isn’t a hypothetical the industry invented for a press release, either. Researchers demonstrated a related version of the problem this summer when a compromised EV charger was shown capable of infecting a connected car, and Norway’s own testing found that remote-control access already exists on ordinary connected vehicles, not just imported buses built with it in mind.

Hyundai appears to be taking the pressure seriously on its own ledger, too. The automaker raised its cybersecurity investment by roughly 46% year over year in 2025, and in June, HMG Security Center head Kichang Yang told a trilateral cybersecurity working group with Kia, the U.S., and Japan that “cross-border cybersecurity response is no longer optional, but essential” as global supply chains grow more interconnected. Every dollar of that spending, and every hour of this week’s drill, sits downstream of the same pressure: an automotive cybersecurity market that regulation, not consumer demand, is now shaping.

What to Remember

The scary headline was never really “hackers can control your steering wheel.” Every engineer in this field has known that was theoretically possible for years. The story worth remembering is who’s required to answer the phone when it stops being theoretical.

In Korea, a hacked OTA update now gets handled like a bank robbery, with a safety regulator, a cybersecurity agency, and actual police on the same call, on a schedule the law forces everyone to keep. In the United States, the same incident would currently be handled the way any other customer complaint is: voluntarily, eventually, and only after NHTSA can prove a defect exists.

Korea didn’t rehearse a hacked car. It rehearsed a chain of command. That’s the part America hasn’t built yet, and the part that will actually determine how fast your car gets fixed the day this scenario stops being a drill.

Should the US require the same kind of mandatory cybersecurity audits Korea just rehearsed? Let us know in the comments.

By Shawn Henry

Shawn Henry has been writing about cars long enough that it's less a job than a habit he can't shake. He covers a little of everything—classic machines, the newest tech, and wherever the industry happens to be heading—and he's the type who actually understands what's going on under the hood, not just how to describe it. Mostly, he just likes telling a good car story.

Join the conversation

No comments yet — be the first to share your take.

Your email address will not be published. Required fields are marked *