Report: Ownership Structures as an Overlooked Security Risk in the Digital Age


1. Background and Problem Statement

ZeroQuantumZero (ZQZ) addresses a problem that is only addressed to a limited extent elsewhere: the risk inherent in ownership structures behind critical digital infrastructure – including electric vehicles (EVs). According to ZQZ, ownership relations and conflicts of interest constitute a serious but overlooked security risk in a rapidly digitizing world.

ZQZ’s point is that the risk lies not only in the technology itself, but in the political and economic landscape in which it operates. When large investors with ties to intelligence sectors hold positions in critical infrastructure, the boundaries between data, power, and security become fluid. This report examines this issue with particular focus on the role of BlackRock, but apply to numerous of related investment and pension funds.


2. The UN Report: “From Economy of Occupation to Economy of Genocide”

In June 2025, the UN Special Rapporteur on the situation of human rights in the occupied Palestinian territories, Francesca Albanese, published the report “From Economy of Occupation to Economy of Genocide” (report A/HRC/59/23). The report names 48 companies that, according to the UN, are accused of contributing to sustaining the israeli occupation and the ongoing war in Gaza.

The report identifies the American multinational investment firms BlackRock and Vanguard as the largest investors behind several of the mentioned companies. BlackRock, the world’s largest asset manager, is described as a central actor in financing what the report calls a “genocide economy”.


3. BlackRock’s Investments: Data and Context

According to the UN report, BlackRock is among the largest institutional investors in a range of companies that supply technology and equipment to the israeli military and intelligence apparatus. The following table summarizes the highlighted connections:

CompanyDescribed Relation to israelBlackRock Ownership (approx.)
Palantir TechnologiesProvides AI and data analytics to the israeli military, including for developing surveillance technologies and target lists.8.6%
MicrosoftProvides israel with access to cloud and AI technologies used for surveillance and control of the Palestinian population.7.8%
Amazon / Alphabet (Google)Supports israel in collecting and storing biometric data and surveillance systems.6.6%
IBMTrains israeli military and intelligence personnel and administers databases with biometric information on Palestinians.8.6%
Lockheed MartinPrimary supplier of F-35 fighter jets to israel.7.2%
CaterpillarSupplies heavy machinery used for demolishing Palestinian homes and constructing settlements.7.5%
CyberArk SoftwareIsraeli cybersecurity company sold to Palo Alto Networks in 2025. BlackRock was among the largest investors.3.9% (adjusted 2025)

In addition to these equity positions, BlackRock invests heavily in Israeli high-tech, including companies such as Tower Semiconductor and Nova Ltd (semiconductor and measurement equipment), and offers its clients an iShares MSCI israel ETF, which provides direct exposure to the israeli economy, including arms manufacturer Elbit Systems. BlackRock has also purchased Israeli government bonds, including US$68 million in connection with war financing.


4. The israeli Cyber and Defense Industry

israel actively markets itself as a global leader in cyber and defense technology. According to the Director General of the Ministry of Defense, Major General (res.) Amir Baram, israel has evolved from a “Cyber Nation” to a true “Defense-Tech Nation”. In 2024 alone, the Ministry of Defense invested 1.2 billion shekels in startups, and over 130 of the 300+ startups cooperating with the ministry’s R&D department actively participated in the war effort. Tel Aviv now ranks as the world’s third largest Defense-Tech hub.

The connection between military intelligence and the private cybersecurity industry is particularly close in israel. Units such as Unit 8200 (signal intelligence) and Unit 81 (cyber weapons development) function as incubators for cyber talent, and many of israel’s most successful cybersecurity companies – including Check Point, CyberArk, Palo Alto Networks, and Armis – were founded by former members of these units.

The city of Beer al-Sabe (Beersheba) hosts the Advanced Technologies Park, where israeli cyber warfare operations against countries such as Iran are developed and coordinated, with close cooperation between the military (Unit 8200), private cyber firms, and academic institutions such as Ben-Gurion University.


5. Relevance to EV Security

The connection between BlackRock’s investment profile and ZQZ’s concern for EV security can be illustrated as follows:

5.1 Conflicts of Interest and Potential Backdoors

The israeli intelligence sector and its technological arms (including NSO Group with Pegasus spyware) are specialists in exploiting vulnerabilities. When the same actors – or their investors – have significant influence over the software in modern vehicles (through investments in the broader tech sector), it raises the question of whether backdoors have been deliberately built in or deliberately overlooked.

5.2 The Dark Side of Digitalization

Rapid digitalization creates an enormous attack surface. When the central actors on this surface simultaneously have close ties to intelligence environments, it is a legitimate question whether our infrastructure – including cars – is designed to be private or to be accessible to certain actors.

5.3 ZQZ’s Position

According to its own description, ZQZ positions itself as an independent counterweight that offers analysis without the same ties to the automotive industry, tech giants, or financial investors.


6. Proposals for the Way Forward

Based on the documented entanglement between financial interests, technology development, and the intelligence sector, a credible system for independence and transparency will require an interplay between several layers:

6.1 Mandatory, Independent Third-Party Audits (with “Clean Room” Principle)

6.2 Radical Transparency in Ownership and Data Flows

6.3 Stronger Legislation and Enforcement


7. A Realistic Perspective

The question is whether such a model is politically and economically realistic. The short answer is that it will face massive opposition from the very same forces it seeks to control – financial institutions and tech companies with enormous lobbying power.

Nevertheless, it is necessary to make the demand. ZQZ’s warning points to a fundamental democratic problem: When critical infrastructure (such as cars) can be effectively transformed into surveillance and attack tools by actors with opaque interests, it becomes a question of who truly holds power in the digital society.

Without independent oversight, we risk handing over that power to an increasingly closed circle of financial and technological actors. The alternative is to accept that our digital infrastructure may be designed not for our privacy and security, but for the benefit of those who control it.


8. Conclusion

This report has documented how major financial institutions like BlackRock are deeply entangled with the israeli intelligence and defense sectors through significant investments in technology companies, arms manufacturers, and infrastructure suppliers. This entanglement, as highlighted by both the UN report and ZQZ’s analysis, creates inherent conflicts of interest that pose a serious security risk in the era of digitalization – particularly concerning electric vehicles, which are becoming increasingly connected and data-intensive.

The solution lies not in a single measure, but in a comprehensive approach combining mandatory independent auditsradical transparency, and stronger enforcement. While politically challenging, this approach is essential if we are to ensure that the digital infrastructure of the future serves the public interest rather than opaque corporate and intelligence agendas.


9. The reality of the future

A Realistic case Perspective: The Pager Attack and the Weaponization of the Supply Chain

9.1 Introduction: From Theory to Reality

The concerns raised in the previous report about opaque ownership structures and conflicts of interest in critical digital infrastructure are not hypothetical. They have a recent, stark, and devastating real-world precedent. On September 17 and 18, 2024, israel executed a sophisticated attack in Lebanon, weaponizing thousands of pagers used by Hezbollah operatives . This operation serves as a chilling case study, transforming the theoretical risk of digital infrastructure being turned into a weapon into a brutal reality.

9.2 Background and Execution

In February 2024, concerned that israeli intelligence had compromised their cellphones, Hezbollah leader Hassan Nasrallah publicly urged his fighters to switch to pagers—a lower-tech, supposedly more secure method of communication . This move, intended to improve operational security, instead opened the door to a major israeli intelligence operation.

On September 17, 2024, at approximately 3:30 PM local time, thousands of pagers simultaneously exploded across Lebanon, primarily in Hezbollah strongholds . The attacks resulted in at least 12 fatalities and injured nearly 3,000 people, with a devastating pattern of injuries primarily affecting the eyes, face, and hands—as victims were looking at their pagers when they detonated .

The following day, a second wave of explosions targeted walkie-talkies, killing an additional 20 people and wounding 450

9.3 The Attack Mechanism

The pagers used were the “Gold Apollo AR924” model, a Taiwanese-branded device. However, Gold Apollo stated that the pagers were actually manufactured by a Hungarian company called BAC Consulting . Reporters later discovered that BAC Consulting was no longer a functioning business, suggesting that Israeli intelligence (widely believed to be Mossad) had created a front company, inserted itself into the supply chain, and manufactured the pagers directly.

The pagers were rigged with 1 to 2 ounces of a high explosive hidden within the device, likely chemically disguised to resemble the pager’s battery during security screening . The operation involved two key elements of supply chain manipulation:

  1. Physical Sabotage: Inserting an explosive payload and a detonator into the devices during manufacturing.
  2. Software Manipulation: Compromising the software to allow for a coordinated, remote signal to trigger the explosives simultaneously

10. Implications for the Digital Infrastructure and EV Security

The pager attack is a profound demonstration of the concerns raised by ZeroQuantumZero (ZQZ). It reveals a critical vulnerability: the global supply chain is not secure. Any digital or communication device can be weaponized, either through physical sabotage or software compromise, especially if an adversary can gain access during the production process

10.1 Key Takeaways

  1. The Supply Chain as an Attack Vector: The pager attack is a textbook example of a supply chain attack. The physical manipulation of devices is now a proven reality .
  2. Implications for EV Security: If pagers can be turned into weapons, so too can electric vehicles. EVs are packed with sensors, cameras, and software that could be compromised. The potential for an EV to be used as a weapon of surveillance or kinetic warfare, as ZQZ warns, is no longer a hypothetical threat.
  3. The Role of Ownership: The report shows that Hezbollah’s attempt to move to “low-tech” devices was a failure. The control of the supply chain, manufacturing, and distribution was more important than the technology itself. This reinforces ZQZ’s central argument: ownership structures and control over production are the most critical factors, not just the technology itself.
  4. The Need for Independent Auditing: The attack succeeded because Hezbollah had no mechanism to independently audit the production of the pagers. They trusted the supply chain, which was compromised. The global nature of the supply chain means that a single nation-state, such as israel, can have extensive leverage.

11 Key Takeaways on EV fragrance system as attack vector

ZeroQuantumZeros concerns (Rapport EV/A6/UK) about EV fragrance systems being exploited to disperse lethal substances is valid and has a basis in documented research and existing automotive patents. The core of the risk lies in how these systems function and are managed.

11.1 The Technical Basis for the Risk

In-vehicle fragrance systems are becoming more common as a luxury feature . The fundamental risk is that a vehicle’s fragrance dispenser is an active diffusion system . It is designed to store a chemical substance and release it into the cabin upon command.

If a bad actor could gain control of this system—by physically swapping the fragrance cartridge or/and by compromising the vehicle’s software—the system’s intended function of releasing a scent could be perverted to release a harmful agent. Search results confirm that this is not a far-fetched idea but a scenario that has been considered in both academic and corporate research.

11.2 Evidence from Research and Patents

There are several pieces of evidence that this type of weaponization is a known and researched possibility:

11.3 Risk to EVs vs. Traditional Cars

Modern EVs might have a higher risk profile due to their deep integration with always-on, internet-connected computer systems. A successful cyber-attack on an EV’s central computer, as mentioned in the security research, could potentially be used to trigger a harmful release without physical access to the vehicle .

11.4 Conclusion

ZQZ’s scenario is not just a theoretical thought experiment. It is a risk that has been:

  1. Researched: Academic work has conceptualized both the offensive and defensive uses of this technology .
  2. Patent-Protected: A major automaker, Toyota, has patented a system that uses the fragrance dispenser to release a harmful chemical (tear gas) . (ownership)
  3. Identified as a Cyber-Attack Vector: Recent security researchers have identified vehicle fragrance systems as a potential entry point for cyber-attacks .

This makes the “fragrance system” a tangible example of the broader threat posed by the digitalization of vehicles, where a feature designed for comfort can be exploited as a significant security vulnerability.

Several biological agents have proven capable in laboratory tests in Ukraine, israel, UK, UAE, among others.

UK and israel has successfully tested “slow speed” agents that takes delayed effect and thereby blur the time and place of exposure.