Skip to main content
Sister Publication Links
  • Automotive News
  • Automotive News Europe
  • Automotive News China
  • Automobilwoche
Subscribe
  • Subscribe
  • login
  • HOME
  • News
    • News by Brand
    • Auto Shows
    • Canadians Abroad
    • Photo Galleries
    • Automakers
    • Suppliers
    • Retail
    • Dealer Best Practices
    • Government Relations
    • Trade and Tariffs
    • Technology
    • Labour
    • Aston Martin
    • BMW
      • Mini
      • Rolls Royce
    • Daimler
      • Mercedes Benz
      • Smart
    • Ferrari
    • Ford
      • Lincoln
    • General Motors
      • Buick
      • Cadillac
      • Chevrolet
      • GMC
    • Honda
      • Acura
    • Hyundai
      • Kia
    • Mazda
    • Mitsubishi
    • Nissan
      • Infiniti
    • Stellantis
      • Alfa Romeo
      • Chrysler
      • Dodge
      • Fiat Chrysler
      • Jeep
      • Fiat
      • Lancia
      • Maserati
      • Ram
    • Subaru
    • Tata
      • Jaguar
      • Land Rover
    • Tesla
    • Toyota
      • Lexus
    • Volkswagen
      • Audi
      • Bentley
      • Bugatti
      • Lamborghini
      • Porsche
    • Volvo
    • VinFast
    • Toronto Auto Show
  • Opinion
    • Blogs
  • Video
  • Podcasts
  • EVENTS & AWARDS
    • 2022 Auto News Canada All-Stars
    • 2022 Canadians To Watch
    • 2022 Diversity Champions
    • Best Dealerships To Work For
    • Canada Congress
    • Retail Forum: Dealer Discussions
    • Leading Women Roundtables
    • Embracing Diversity Roundtable
    • EVs Decoded
  • Jobs & Classifieds
  • +MORE
    • IN THE DRIVER'S SEAT
    • NEWSLETTERS
    • SUBSCRIBE
    • CLASSIFIEDS
    • PEOPLE ON THE MOVE
    • COMPANIES ON THE MOVE
    • WEBINARS
    • ADVERTISE WITH US
    • CONTACT US
    • DIGITAL EDITION
    • PUBLISHING PARTNERS
MENU
Breadcrumb
  1. Home
  2. Technology
March 08, 2023 08:00 AM

Automakers pay white hat hackers much less compared with other industries

Automakers are paying ‘bug bounties' to hackers to identify vulnerabilities in consumer and corporate data protection. But are they paying enough?

  • Tweet
  • Share
  • Share
  • Email
  • More
    Print
    wesley_tingey_HACKERS_RED-MAIN.jpg
    WESLEY TINGEY

    Automakers are so worried about vehicle and software security gaps that they are paying hackers to uncover vulnerabilities.

    These bug bounty programs reward friendly digital invaders, known as white hat hackers, who look for breaches and notify automakers and suppliers of the problems — although the auto industry pays them considerably less for their efforts than some other sectors do.

    Cybersecurity has become a major issue for the industry as cars increasingly rely on software, sensors and computers for operation, infotainment, automated driving and safety systems. Moreover, automakers are loading connectivity and subscription features that add to the digital vulnerabilities.
    The number of publicly reported auto cyberattacks jumped 239 percent in 2022 compared with 2018, according to Israeli cybersecurity firm Upstream.

    Last in rewards

    The auto industry was in last place in 2022 among the sectors ranked by HackerOne on how much they pay friendly hackers. All figures in USD
    Internet and online services
     
    $13.1 million
    Computer software
     
    $8.7 million
    Telecoms
     
    $4.7 million
    Financial services
     
    $3.4 million
    Crypto and blockchain
     
    $1.6 million
    Retail and e-commerce
     
    $1.4 million
    Government
     
    $703,084
    Automotive
     
    $483,809
    Source: 2022 Hacker-Powered Security Report

    Automakers want to find problems before hostile hackers uncover vulnerabilities they can exploit, which could allow them to gain access to a driver's personal information or even control a car for ransom.

    Last year, white hat hackers notified automakers of security gaps in customer files, back-end operations or both in BMW, Ferrari, Ford, Jaguar Land Rover, Mercedes-Benz, Porsche and Toyota systems and models. They also discovered flaws in SiriusXM's telematics service that created breaches in Honda, Hyundai and Nissan vehicles.

    Even more consumer data will be exposed in the coming years as automakers expand software-enabled services, said Andrea Amico, founder and CEO of Privacy4Cars, a company that helps dealerships clear personal data from vehicles. Hostile hackers will want that information, he said.

    PROACTIVE APPROACHES

    The auto industry lags others in cybersecurity, said Mohammed Ismail, chair of the Electrical and Computer Engineering Department at Wayne State University in Detroit.

    "With any new technology, this is a very typical situation," he said. "When Wi-Fi and Bluetooth started 25 years ago, it took years for those technologies to be seamless and mature."

    Ismail estimates the auto industry needs about five more years of R&D to produce millions of predominantly software-based vehicles that are very secure.

    Friendly hackers will help the industry get there.

    "Using a bug bounty platform has proven to be an effective way to bring on board the knowledge and expertise of the security community," Katja Liesenfeld, Mercedes-Benz Cars & Vans' manager for IT communications, said in an email. "We cannot give more details on any technical details as the programs are private."

    Automakers are reluctant to talk about their reward programs and cybersecurity issues. Ford, Jaguar Land Rover, Nissan, Stellantis and Subaru declined to discuss their cybersecurity programs with sibling publication Automotive News. BMW, Porsche and Volkswagen did not respond to queries. Honda said it doesn't have a bug bounty program.

    Nonetheless, most of the auto industry is proactive about cybersecurity issues, said Kevin Tierney, General Motors' chief cybersecurity officer and vice chair of the Automotive Information Sharing and Analysis Center, known as Auto-ISAC. The group of automakers shares information about potential cyberthreats, vulnerabilities and incidents.

    "Everyone's making big moves and big investments," Tierney said. "It's not always obvious to the end consumer with everything that's happening."

    GM started its bug bounty program in 2016. It is administered by HackerOne, of San Francisco, which also runs programs for BMW, Ford, Rivian and Toyota.

    HackerOne's automotive business jumped 400 percent from 2021 to 2022 as clients added services to their contracts. In addition to bug bounty management, HackerOne provides vulnerability disclosure programs, penetration testing of online systems and other services.

    AT THE BOTTOM

    The auto industry paid out $483,809 in bug bounties last year, the least of the eight sectors HackerOne tracks. The average auto bug bounty paid out a little over $2,000, according to HackerOne's 2022 Hacker-Powered Security Report. The Internet sector paid out $13.1 million last year. Telecoms gave friendly hackers $4.7 million. Government entities rewarded them with $703,084.
    Stellantis, which uses Bugcrowd, another San Francisco cybersecurity management company, pays $150 to $7,500 per vulnerability discovered, with an average payout of $737.50 over the past three months. Yet hackers at a February conference in Miami exploring industrial cyber vulnerabilities earned $5,000 to $40,000 per breach, news site SecurityWeek reported.

    Bounties paid out by Google in 2022 included a record $605,000, company spokesman Ed Fernandez said in an email. Since 2017, Intel has paid $4.1 million through its bug bounty program, said Jennifer Foss, a company spokeswoman.

    Some friendly hackers want to see the auto industry step up payment.

    Late last year, Eaton Zveare, a hacking hobbyist in Sarasota, Fla., breached Toyota's global supplier management web portal, gaining read-and-write access to 14,000 corporate email accounts, associated confidential documents, projects, supplier rankings, comments and other information. He informed Toyota, and the breach was quickly closed.

    Zveare said he appreciated Toyota's prompt response and recognition but was dismayed by the lack of monetary compensation.

    "Given how much profit they make per year, I think they should definitely allocate some to the security teams that they can use to reward researchers," Zveare said.

    A 'FOREVER' PROBLEM

    Automakers need to offer ample rewards if they want the help of security researchers looking for flaws, said Roger Grimes, cybersecurity consultant at KnowBe4, a Clearwater, Fla., cybersecurity consultancy and training company.

    "Not paying smart people to help you find and eradicate your bugs is just foolish," Grimes said.

    White hat hackers may get discouraged and turn their efforts to industries that have higher rewards. Or worse, they could sell their skills to nefarious actors targeting the auto sector, he said.

    Grimes said he expected hacking to be a "forever" problem for automakers, forcing them to ensure safety and theft prevention systems are as secure as possible.

    "Vehicles are a critical component of daily life, and if security isn't built in from the ground up and tested, then tested, and tested once more, the consequences could be catastrophic," Kayla Underkoffler, HackerOne's lead security technologist, said in an email. "For something as critical as our personal safety, we need the best minds working on solutions."

    RECOMMENDED FOR YOU
    Flo calls U.S. federal aid ‘critical' to its expansion strategy
    Recommended for You
    FLOGUYS-MAIN_i.jpg
    Flo calls U.S. federal aid ‘critical' to its expansion strategy
    Nissan Acerta
    Canada's Acerta Analytics Solutions, Nissan test AI tool made to prevent failures
    UCFRONT-MAIN.gif
    GM Ultra Cruise hands-free driving system is positioned as opposite of Tesla's approach
    Andy Wadeson
    Sponsored Content: Expert Insights: The Implications of Rising Interest Rates
    Digital Edition
    March 2023 Cover
    View latest issue
    See our archive
    Sign up for free newsletters
    EMAIL ADDRESS

    Please enter a valid email address.

    Please enter your email address.

    Please verify captcha.

    Please select at least one newsletter to subscribe.

    You can unsubscribe at any time through links in these emails. For more information, see our Privacy Policy.

    Get Free Newsletters

    Sign up today for our Weekly Newsletter, Daily Newsletter and Breaking News Alerts. We'll deliver the news you need to know straight to your inbox.

    You can unsubscribe at any time through links in these emails. For more information, see our Privacy Policy.

    Subscribe Now

    An Automotive News Canada subscription includes 12 monthly issues – delivered in print to your doorstep, and digitally to your inbox – plus unlimited, 24/7 access to our website.

    Subscribe Now
    Connect With Us
    • Facebook
    • Twitter
    • Instagram

    Our Mission

    The Automotive News Canada mission is to be the primary source of industry news, data and understanding for the industry's decision-makers interested in Canada.

    Contact Us

    1155 Gratiot Ave
    Detroit MI 48207

    1-877-812-1257

    Email Us

    ISSN 2475-5001 (print)
    ISSN 2475-501X (online)

    Resources
    • About us
    • Contact Us
    • Digital Edition Archive
    • Advertise with Us
    • Reprints
    • Ad Choices Ad Choices
    • Sitemap
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Automotive News Canada
    Copyright © 1996-2023. Crain Communications, Inc. All Rights Reserved.
    • HOME
    • News
      • News by Brand
        • Aston Martin
        • BMW
          • Mini
          • Rolls Royce
        • Daimler
          • Mercedes Benz
          • Smart
        • Ferrari
        • Ford
          • Lincoln
        • General Motors
          • Buick
          • Cadillac
          • Chevrolet
          • GMC
        • Honda
          • Acura
        • Hyundai
          • Kia
        • Mazda
        • Mitsubishi
        • Nissan
          • Infiniti
        • Stellantis
          • Alfa Romeo
          • Chrysler
          • Dodge
          • Fiat Chrysler
          • Jeep
          • Fiat
          • Lancia
          • Maserati
          • Ram
        • Subaru
        • Tata
          • Jaguar
          • Land Rover
        • Tesla
        • Toyota
          • Lexus
        • Volkswagen
          • Audi
          • Bentley
          • Bugatti
          • Lamborghini
          • Porsche
        • Volvo
        • VinFast
      • Auto Shows
        • Toronto Auto Show
      • Canadians Abroad
      • Photo Galleries
      • Automakers
      • Suppliers
      • Retail
      • Dealer Best Practices
      • Government Relations
      • Trade and Tariffs
      • Technology
      • Labour
    • Opinion
      • Blogs
    • Video
    • Podcasts
    • EVENTS & AWARDS
      • 2022 Auto News Canada All-Stars
      • 2022 Canadians To Watch
      • 2022 Diversity Champions
      • Best Dealerships To Work For
      • Canada Congress
      • Retail Forum: Dealer Discussions
      • Leading Women Roundtables
      • Embracing Diversity Roundtable
      • EVs Decoded
    • Jobs & Classifieds
    • +MORE
      • IN THE DRIVER'S SEAT
      • NEWSLETTERS
      • SUBSCRIBE
      • CLASSIFIEDS
      • PEOPLE ON THE MOVE
      • COMPANIES ON THE MOVE
      • WEBINARS
      • ADVERTISE WITH US
      • CONTACT US
      • DIGITAL EDITION
      • PUBLISHING PARTNERS