Connect with us

Technology

Hyundai AutoEver America breached: Know the risks to you

Published

on

Hyundai AutoEver America breached: Know the risks to you

NEWYou can now listen to Fox News articles!

Hyundai AutoEver America discovered on March 1, 2025, that hackers had compromised its systems. Investigators found the intrusion began on February 22 and continued until March 2. 

Hyundai AutoEver America (HAEA) provides IT services for Hyundai Motor America, including systems that support employee operations and certain connected-vehicle technologies. While the company works across Hyundai’s broader ecosystem, this incident did not involve customer or driver data.

According to the statement provided to CyberGuy, the breach was limited to employment-related information tied to Hyundai AutoEver America and Hyundai Motor America. The company confirmed that about 2,000 current and former employees were notified of the incident in late October. HAEA said it immediately alerted law enforcement and hired outside cybersecurity experts to assess the damage.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Advertisement

Cybercriminals targeted Hyundai AutoEver America’s systems, exposing sensitive data. (Kurt “CyberGuy” Knutsson)

Why this Hyundai AutoEver America breach matters

The exposed data reportedly includes names, Social Security numbers and driver’s license numbers, making this breach far more serious than one involving passwords alone. Experts warn that these details can be used for long-term identity theft and financial fraud. Because Social Security numbers cannot easily be changed, criminals have more time to create fake identities, open fraudulent accounts and launch targeted phishing attacks long after the initial breach.

Experts warn that stolen Social Security and driver’s license information could be used for identity theft and fraud. (Kurt “CyberGuy” Knutsson)

Who was affected in the Hyundai AutoEver America data incident

AEA manages select IT systems tied to Hyundai Motor America’s employee operations, along with broader technology functions for Hyundai and Genesis across North America. Its role includes supporting connected-vehicle infrastructure and dealership systems.

According to the company, this incident was limited to employment-related data and primarily affected approximately 2,000 current and former employees of Hyundai AutoEver America and Hyundai Motor America. No customer information or Bluelink driver details were exposed. While some filings reference sensitive data types such as Social Security numbers or driver’s license information, the incident did not involve Hyundai customers or the millions of connected vehicles HAEA supports.

Advertisement

Earlier reports suggested that 2.7 million individuals were affected, but Hyundai says that figure is unrelated to the breach. Instead, 2.7 million is the estimated number of connected vehicles that Hyundai AutoEver America helps support across North America. None of that consumer or vehicle data was accessed.

GENESIS PREVIEWS G70 SPORTS SEDAN WITH NEW YORK CONCEPT

Hyundai also clarified that the United States has about 850 Hyundai dealerships and emphasized that the scope of this incident was narrow and contained.

We reached out to HAEA for a comment, and a representative for the company provided CyberGuy with this statement:

“Hyundai AutoEver America, an IT vendor that manages certain Hyundai Motor America employee data systems, experienced an incident to that area of business that impacted employment-related data and primarily affected current and former employees of Hyundai AutoEver America and Hyundai Motor America. Approximately 2,000 primarily current and former employees were notified of the incident. The 2.7 million figure that is cited in many media articles has no relation to the actual security incident. The 2.7 million figure represents the alleged total number of connected vehicles that may be supported by Hyundai AutoEver America across North America. No Hyundai consumer data was exposed, and no Hyundai Motor America customer information or Bluelink driver data was compromised.”

Advertisement

Scammers may now pose as company representatives, contacting people to steal more personal details. (Kurt “CyberGuy” Knutsson)

What you should do right now

  • Monitor your bank, credit card and vehicle-related accounts for suspicious activity.
  • Check for a notification letter from Hyundai AutoEver America or your car brand.
  • Enroll in the two years of complimentary credit monitoring offered by HAEA if you qualify.
  • Enable multi-factor authentication (MFA) on all important accounts, including those tied to your vehicle.
  • Be cautious of emails, texts or calls claiming to be from Hyundai, Kia or Genesis. Always verify through official websites.

Smart ways to stay safe after the Hyundai AutoEver America breach

Whether you were directly affected or just want to stay alert, this breach is a reminder of how important it is to protect your personal information. Follow these practical steps to keep your data secure and reduce the risk of identity theft or scams.

HYUNDAI TO RECALL GENESIS CARS TO FIX BRAKES

1) Freeze or alert your credit

Contact major credit bureaus — Experian, TransUnion and Equifax — to set a fraud alert or freeze. This helps block new accounts from being opened in your name.

2) Protect your vehicle apps

If you use apps tied to your vehicle, update passwords and enable multi-factor authentication. Avoid saving login details in unsecured places. Also, consider using a password manager, which securely stores and generates complex passwords, reducing the risk of password reuse. 

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials. 

Advertisement

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com

3) Watch for fake support messages

Scammers may use news of the Hyundai AutoEver America breach as a way to contact Hyundai, Kia or Genesis owners, pretending to be from customer support or the dealership. They might claim to help verify your account, update your information or fix a security issue. Do not share personal details or click any links. Type the brand’s web address directly into your browser instead of clicking links in messages or emails. Always confirm through the official brand website or by calling the verified customer service number.

4) Use strong antivirus protection

Using strong antivirus software helps block phishing links, malware downloads and fake websites that might appear after a data breach. It can also scan your devices for hidden threats that may try to steal login data or personal files.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

Advertisement

5) Use a data removal service

Data removal tools automatically find and delete your personal information from people-search and data-broker sites. These services reduce the chances that criminals will use leaked data to target you with phishing or social-engineering scams.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

6) Monitor your digital footprint

Consider using identity monitoring services to track your personal information and detect possible misuse early.

Advertisement

Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

7) Keep your devices updated

Regularly install security updates on your phone, laptop and smart car systems to reduce the risk of further attacks.

8) Report suspicious activity the right way

If you notice unusual account activity, fraudulent charges, or suspicious messages that appear tied to this breach, report it immediately. Start by contacting your bank or credit card provider to freeze or dispute any unauthorized transactions. Then, file a report with the Federal Trade Commission (FTC) at IdentityTheft.gov, where you can create an official recovery plan. If you suspect a scam message or call, forward phishing emails to reportphishing@apwg.org and report fake texts to 7726 (SPAM).

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Kurt’s key takeaways

This incident highlights how much personal data is connected to modern cars and how vulnerable those systems can be. When your vehicle is linked to your identity, protecting your data becomes just as important as maintaining the car itself. Stay alert, use the tools available to safeguard your accounts and report any suspicious activity right away.

Should companies like Hyundai AutoEver be doing more to keep customer data secure? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Copyright 2025 CyberGuy.com.  All rights reserved.

Advertisement

Technology

Fox is buying Roku

Published

on

Fox is buying Roku

Fox has announced that it’s acquiring Roku outright, in a deal that values the streaming company at $22 billion.

The deal will see Fox’s TV networks and Tubi streamer combine with Roku’s network of streaming devices, smart TV software, and The Roku Channel. The companies say in a press release that by combining they’ll become the third-largest player in the US TV industry by viewing share.

It doesn’t sound like the plan is to build Roku and Fox into a walled ecosystem. Roku founder and CEO Anthony Wood, who will stay on in the company and join Fox’s board of directors, said in an investor call that Roku “will continue to operate as an open, partner-friendly platform supporting the entire streaming ecosystem.” As for Fox, the press release says the companies are “committed” to the “continued ubiquitous distribution” of Fox’s own content.

”This is a defining moment for Fox, and a natural extension of the deliberate and focused strategy we have been executing for nearly a decade,” Fox CEO Lachlan Murdoch said in a statement. “Today, we take the next step: bringing together the most valuable live content portfolio in video consumption with the preeminent streaming platform through which America watches it.”

“Over the past two decades, we’ve built Roku into the leading TV streaming platform, reaching more than 100 million households globally and reshaping how people discover and enjoy entertainment,” said Roku CEO Wood. “I’m incredibly proud of what our team has built, and the combination with Fox is an extraordinary opportunity to accelerate our vision, scale faster and innovate more aggressively for viewers, partners and advertisers.”

Advertisement

The deal is expected to close in the first half of 2027, but remains subject to regulatory approval, which in the current climate seems unlikely to pose a problem in the US.

Update, June 15th: Added Anthony Wood quote from the investor call.

Continue Reading

Technology

The FBI built a small town to simulate cyberattacks

Published

on

The FBI built a small town to simulate cyberattacks

Last year, the FBI opened a Cyber Range in Huntsville, Alabama, for simulating cyberattacks. Think of it sort of like the famous Hogan’s Alley, but for modern digital crime training. It’s a massive 22,000 square-foot replica of an entire town, complete with a convenience store, gas station, hospital, and even fully furnished houses.

It’s a training facility where the bureau can recreate real-world scenarios for training and research purposes. All of the various buildings and facilities are hooked up the way they would be in a real town. There’s even a small data center with over 200 servers that can be hacked, infected with malware, and studied. But, importantly, all of the systems in the fake town are cut off from the outside world, which means there’s no danger of any malicious code or anything from escaping containment.

Students practice performing forensic investigations on car entertainment systems, hospital computer networks, and corporate security systems. They can see how various cyberattacks might affect power grids or spread through home networks.

While the facility opened last year, the FBI only shared a video this week, giving the public its first glimpse inside.

Continue Reading

Technology

FBI says Russian hackers hijacked old Wi-Fi routers

Published

on

FBI says Russian hackers hijacked old Wi-Fi routers

NEWYou can now listen to Fox News articles!

Your Wi-Fi router may be the least glamorous gadget in your home. It sits on a shelf, blinks in the corner and only gets attention when Netflix freezes. However, that little box controls a lot more than you may think. 

The FBI and Justice Department say a Russian military intelligence hacking group abused vulnerable small office and home office routers to help run an espionage operation. The group is known as APT28, Fancy Bear and Forest Blizzard. It has been linked to Russia’s GRU military intelligence agency.

The hackers changed router settings so internet requests could flow through servers they controlled. That gave them a way to watch for valuable targets, redirect traffic and steal sensitive login information. The Justice Department and FBI say they disrupted the U.S. portion of the network in April. That is good news. Still, law enforcement cannot walk into your house, update your router or change the password printed on an old sticker. That part is on you.

Sign up for my FREE CyberGuy Report

Advertisement
  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.  

FBI WARNS OF HACKERS EXPLOITING OUTDATED ROUTERS. CHECK YOURS NOW

Wires are connected to a router to maintain internet connectivity. (Wolf Von Dewitz/Picture Alliance via Getty Images)

How this router attack worked

This attack focused on SOHO routers. That stands for small office and home office routers. In other words, these are the kinds of devices used by small businesses, remote workers and some homes. The Justice Department says the hackers used weaknesses in older routers to change DNS settings.

DNS is like the address book for the internet. When you type a website name, DNS helps your device find the right online destination. If hackers control that address book, they can send certain requests through their own servers. That can let them spot valuable targets and try to steal passwords, authentication tokens, emails or browsing data.

That to me is scary because the victim may not see anything obvious. Your laptop may still connect. Your phone may still browse. Your router may still look normal. Meanwhile, the traffic can be quietly routed through a bad path. 

Why old routers can become a weak spot

Routers age like any other device. The problem is that many people keep them for years after the manufacturer stops supporting them. That can leave known security holes sitting open.

Advertisement

Many people also never change the router’s admin username and password. That admin login is different from your Wi-Fi password. It controls the router itself. If that login still uses a default password, a hacker has a much easier path inside.

Think of it this way. You may have strong passwords on your bank account, email and phone. But if your router is outdated and poorly protected, your network still has a soft spot.

DON’T USE YOUR HOME WI-FI BEFORE FIXING CERTAIN SECURITY RISKS

A router’s admin settings can become a security weak spot when firmware is outdated or default passwords are never changed. (TP-Link)

Which routers were targeted?

The FBI specifically referred to the TP-Link WR841N in its warning. The UK National Cyber Security Centre also listed other TP-Link models targeted by APT28. The agency says the list may not be complete.

Advertisement

Here are the routers named in the advisory:

  • TP-Link LTE Wireless N Router MR6400
  • TP-Link Wireless Dual Band Gigabit Router Archer C5
  • TP-Link Wireless Dual Band Gigabit Router Archer C7
  • TP-Link Wireless Dual Band Gigabit Router WDR3600
  • TP-Link Wireless Dual Band Gigabit Router WDR4300
  • TP-Link Wireless Dual Band Router WDR3500
  • TP-Link Wireless Lite N Router WR740N
  • TP-Link Wireless Lite N Router WR740N/WR741ND
  • TP-Link Wireless Lite N Router WR749N
  • TP-Link Wireless N 3G/4G Router MR3420
  • TP-Link Wireless N Access Point WA801ND
  • TP-Link Wireless N Access Point WA901ND
  • TP-Link Wireless N Gigabit Router WR1043ND
  • TP-Link Wireless N Gigabit Router WR1045ND
  • TP-Link Wireless N Router WR840N
  • TP-Link Wireless N Router WR841HP
  • TP-Link Wireless N Router WR841N
  • TP-Link Wireless N Router WR841N/WR841ND
  • TP-Link Wireless N Router WR842N
  • TP-Link Wireless N Router WR842ND
  • TP-Link Wireless N Router WR845N
  • TP-Link Wireless N Router WR941ND
  • TP-Link Wireless N Router WR945N

If you see your model on this list, take it seriously. Many of these routers are older. Some may no longer get normal security support. We reached out to TP-Link for comments, but did not hear back before our deadline.

What TP-Link says about the router warnings

A spokesperson from TP-Link Systems Inc. told CyberGuy the company is aware of recent public reporting involving legacy consumer routers, including TP-Link models listed in those reports. The company said the referenced legacy router models reached End of Service and Life status several years ago.

“While these products are outside our standard maintenance lifecycle, TP-Link has developed security updates for select legacy models where technically feasible,” the spokesperson said.

The spokesperson also urged customers using legacy or end-of-service devices to upgrade to currently supported hardware that receives regular security updates.

“As immediate precautions, users should update to the latest available firmware, disable remote management, and restrict device access to trusted internal networks only,” the spokesperson said.

Advertisement

TP-Link added that the security of its customers is its highest priority and said detailed mitigation guidance, along with a list of identified affected legacy products, is available on its official security advisory page.

What this means for you

Most people do not think about their router until the Wi-Fi drops. But your router sits between your devices and the internet. That gives it a powerful position in your home or small business. If a hacker changes the router’s settings, every connected device can feel the impact. That includes your laptop, smartphone, tablet, smart TV and work computer.

This is especially important if you work from home. A weak router can create a risk for your personal accounts and your workplace accounts. The good news is that you do not need to be a cybersecurity expert to lower the risk. You just need to stop treating your router like a forgotten appliance.

ETHERNET VS WI-FI SECURITY COMPARISON REVEALS SURPRISING RESULTS FOR HOME USERS SEEKING PROTECTION

Security agencies say replacing unsupported routers is one of the most important steps users can take after this kind of attack. (TP-Link)

Advertisement

How to protect your router from hackers

The good news is that a few simple router checks can reduce your risk and help keep hackers from quietly changing how your internet traffic moves.

1) Check your router model

Look at the label on your router. You can usually find the model number on the bottom or back of the device. If it matches one of the listed models, check the manufacturer’s support page for firmware updates. If the device is no longer supported, replace it. Do not keep an end-of-life router because it “still works.” A router can still provide Wi-Fi while leaving your network exposed.

2) Update your router firmware

Firmware is the software that runs your router. Updates often fix security problems. Open your router’s app or log in to its admin page. Look for a firmware update section. Turn on automatic updates if your router offers that option. If it does not, set a reminder to check for updates regularly.

3) Change the router admin password

Your router has an admin login. This is separate from your Wi-Fi network password. Change the default admin username and password. Use a long, unique password that you do not use anywhere else. A password manager can help you create and store a strong router password so you do not have to remember it. Also, change your Wi-Fi password if you have shared it widely or kept it for years. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com

4) Disable remote management

Most people do not need to manage a home router from outside the house. Remote management can give attackers another way to reach your router. Log in to your router settings and turn it off unless you truly need it. The wording may vary by brand. Look for “remote management,” “remote access” or “WAN access.”

Advertisement

5) Reboot your router

A reboot will not fix every router problem. However, security agencies often recommend restarting routers as part of basic home network hygiene. Unplug your router, wait about 30 seconds and plug it back in. This can help clear some temporary malicious activity. Still, it does not replace updates, stronger passwords or replacing an outdated device.

6) Watch browser certificate warnings

Do not click through browser warnings that say a site certificate is invalid or unsafe. Those warnings can appear when something is interfering with a secure connection. In this kind of attack, that warning could be a major red flag. Close the page instead. Then check the site by typing the address yourself on a trusted network.

7) Use a VPN for sensitive work

If you handle work files or sensitive accounts from home, use your company-approved VPN. A VPN can help protect traffic when you connect to workplace systems. It can also reduce exposure when you use networks you do not fully control. Still, a VPN isn’t a free pass to ignore router updates. You need safer habits and safer hardware. For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android & iOS devices at Cyberguy.com

8) Use strong antivirus software

Strong antivirus software can help protect your devices if a bad link, a fake login page or a malicious download reaches you. It will not fix a vulnerable router, but it can add another layer of protection for your computer and phone. Look for security software that can detect malware, warn you about phishing sites and help block suspicious activity before it causes damage. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

9) Consider identity theft protection

If hackers steal your login details, the damage can spread beyond your Wi-Fi network. Identity theft protection can help monitor for signs that your personal information is being misused. It may alert you to suspicious activity involving your credit, accounts or personal data so you can act faster. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

Advertisement

10) Use a data removal service

A data removal service can help reduce the amount of personal information about you that is available online. That is important because scammers often combine stolen logins with exposed details from data broker sites. Removing your information from those sites can make it harder for criminals to build a fuller profile of you or your family. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

11) Replace outdated routers

If your router no longer receives security updates, replace it. That may feel annoying. I get it. Nobody gets excited about buying a router the way they might get excited about a new phone. But your router protects everything connected to it. Spending money on a supported device can be cheaper than cleaning up stolen passwords later.

Kurt’s key takeaways

This router warning should make every home and small business owner pause for a minute. The scariest part is how ordinary the target is. We are talking about routers that may be sitting in homes, home offices and small businesses right now. The FBI and its partners disrupted part of the Russian operation. However, that does not magically secure old routers still sitting on shelves. So check your model. Update the firmware. Change the admin password. Turn off remote management. Replace the router if it no longer gets updates. Your router may be boring. But if it gets hijacked, it can become one of the most important security problems in your home.

Would you know how old your router is right now, or is it one of those devices you have not touched since the day it was installed? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading
Advertisement

Trending