Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Major Auto Parts Firm LKQ Hit by Cyberattack

LKQ, a major provider of auto parts, told the SEC that a recent cyberattack caused disruptions at a Canadian business unit.

Car hacking

LKQ Corporation, a major US-based provider of auto parts, informed the SEC late last week that a recent cyberattack caused disruptions at a Canadian business unit.

LKQ provides parts for repairing and accessorizing consumer cars and other vehicles. The company has 1,600 locations across two dozen countries, and a total of 45,000 employees. 

In an 8-K filing with the SEC, the company revealed that it detected unauthorized access to IT systems at a single business unit in Canada on November 13.

The cyberattack caused disruptions at the impacted business unit for “a few weeks”, but the unit is now operating near full capacity and the threat is believed to have been contained. 

“As of the date of this filing, we believe the impacts of the cyber incident are not, and are not reasonably likely to be, material to our financial condition or results of operations for the fiscal year,” LKQ said

“We will be seeking reimbursement of costs, expenses, and losses stemming from the cyber incident by submitting claims to our cybersecurity insurers,” LKQ added.

Advertisement. Scroll to continue reading.

It’s unclear whether the attack was conducted by a ransomware group. No known threat actors have taken credit for the LKQ cyberattack, but that does not completely rule out ransomware (companies that pay a ransom are not named on leak websites).

SecurityWeek has reached out to LKQ for more information and will update this article if the company responds. 

Related: Unpatched Vulnerabilities Allow Hacking of Mazda Cars

Related: Millions of Kia Cars Were Vulnerable to Remote Hacking

Related: Car Dealerships in North America Revert to Pens and Paper After Cyberattacks on Software Provider

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.