Server Failures Turn Safe Cars Into Costly Dead Weight Cybersecurity incident leaves hundreds of U.S. drivers stranded Drivers in 46 U.S. states were left temporarily stranded in March when breathalyzer devices installed on their cars went inactive. These ignition-interlock devices require a driver, typically one who has been convicted of an alcohol-related driving offense, to breathe into a tube and will prevent the car from starting if the system detects alcohol beyond a state-mandated threshold that’s well below the standard legal blood alcohol limit. A cyberattack on backend systems at Intoxalock, an ignition-interlock provider, prevented devices from verifying compliance. The episode highlights how failures in cloud services can reverberate through the physical world of mobility. Beginning around 14 March, users reported devices rejecting startup attempts or blocking required logins. Affected users took to social-media to complain of missed work shifts, canceled appointments, and cars stuck in driveways—even when drivers successfully passed breath tests. Intoxalock, one of the largest ignition-interlock providers in the United States, later confirmed a cybersecurity incident affecting portions of its backend infrastructure. The company said vehicle-safety systems were not compromised and breath-alcohol measurements remained accurate. The disruption instead stemmed from service outages that prevented service technicians from accessing the in-car systems’ software or routing maintenance logs certifying that the breathalyzers’ sensors were properly tuned. Unless the servers periodically receive up-to-date information on a car, they will not send the signal giving the ignition interlock permission to start the car’s engine. Compliance Systems Meet Connected Infrastructure Ignition-interlock devices periodically connect to backend servers to verify account status, upload logs of breath-test events, and confirm calibration schedules required for legal certification. “Local fallback is critical” –Sam Abuelsamid, Telemetry mobility research When backend communication failed during the cyberattack, some of the devices entered operating states designed to enforce court-mandated compliance