The 2024 EC80 safety recall corrected a safety issue. The same fix also closed a cybersecurity gap, but fleets were not aware of that aspect of the update.
That is the finding National Motor Freight Traffic Association Inc. cybersecurity researcher Ben Gardiner will present at Black Hat USA 2026.
As Gardiner puts it, the EC80 recall was "a commendable effort to fix safety issues by the vendor and also an improvement to cybersecurity, although this was not communicated to the fleets."
NMFTA will release a white paper and a VehicleSec paper preprint to coincide with the presentation, with deeper technical detail to follow at DEF CON.
NMFTA remains committed to focusing on all sides of cybersecurity, including asset-based, non-asset and cyber-enabled cargo theft.
At the NMFTA 2026 Cybersecurity Conference in Long Beach, California, scheduled for Sept. 29 to Oct. 1, Gardiner will also present a deep dive into this research titled "Project Update: EC80." The session will walk through how electrical noise on the J2497 powerline can corrupt memory and knock an ECU offline, and what that reveals about deeper vulnerabilities in the powerline communication these trucks rely on.
This will be part of a new dedicated technical track built around the asset itself in this year’s agenda.
Samsara Chief Information Security Officer Sean Herron will explore the telematics attack surface in a session on offensive-security lessons that help prevent operational disruption and cargo theft. Bosch's Ivan Granero will show how AI can pull vehicle, telematics and IT security data into a single investigative view across mixed protocols. Gardiner, alongside fellow NMFTA researcher Anne Zachos, will lead hands-on training for TCAT, NMFTA's forthcoming Trucking Cybersecurity Assessment Tool.
These sessions all make a point worth highlighting: The ECUs, telematics units and legacy protocols moving freight today were largely engineered for speed and efficiency, not security in a connected world. Bringing that hardware into the light and giving fleets the tools to assess it themselves is the work this track is built to advance.
Additional sessions will include an immersive, hands-on incident response tabletop exercise. Program highlights also include a full walkthrough of a ransomware attack from initial compromise through containment and recovery, led by Malleum's Ahmed Shah.
Cyber-enabled cargo theft will be a focus as well, featuring a panel discussion on how criminals exploit load boards and carrier identities to steal freight. Reinforcing that this is not an issue unique to the U.S., a cross-border briefing will detail how remote-management tools, malware and phishing are chained together to redirect loads across North America and Europe.
Artificial intelligence will also play a prominent role at this year’s event. Attendees will hear how deepfakes, voice cloning and AI-assisted social engineering target carriers and brokers, and how threat intelligence can move from inbox reports into real operational defense for fleets of any size.
NMFTA's internal team will deliver its annual State of NMFTA update and close the program with a "Call for Collaboration," an open invitation to help shape the research agenda that surfaced the EC80 findings.
The race between bad actors seeking to disrupt transportation sector organizations and those who defend them has never been more heated. From the back office to the ECU, the risks are real. Research is key to uncovering vulnerabilities, and discussion is key to improving collective security posture across the sector.

























