Internet Security Auditors Blog

Samsung and the Refrigerator That Stopped Cooling: A Warning Sign for the CRA

Written by Alberto Villar Arévalo | Oct 1, 2026, 9:56:34 AM
Madrid, 24 September 2026. Samsung has suspended a SmartThings update after several four-door Bespoke AI refrigerators became locked or stopped cooling in South Korea. According to Notebookcheck, citing South Korean media reports, internal testing software may have been mistakenly distributed to customers. Some users were unable to recover their devices even by disconnecting them from the power supply. The incident also occurred just before Chuseok, increasing the impact on food preservation, technical support operations, and reputation.

A deployment failure is not just a support issue. In a connected product, software, firmware, and their updates are part of the product itself. This case alone does not allow us to conclude that there has been non-compliance with the Cyber Resilience Act (CRA), nor that an exploited vulnerability or a serious cybersecurity incident occurred. It does, however, clearly demonstrate why the processes for developing, testing, approving, distributing, rolling back, and monitoring updates must be governed and verifiable.

The CRA turns that discipline into a regulatory obligation for products with digital elements placed on the European Union market. The Regulation requires cybersecurity risk assessments, security by design and by default, protection of essential functions, vulnerability management throughout the support period, technical documentation, and secure update processes. In addition, since 11 September 2026, the notification obligations under Article 14 for actively exploited vulnerabilities and severe incidents have become applicable. General application of the Regulation will follow on 11 December 2027.

Internet Security Auditors can help transform CRA compliance into an operational and demonstrable programme. Our approach covers applicability assessment and classification, GAP analysis and a prioritized Action Plan, implementation support, review of the secure development lifecycle and update processes, vulnerability management and notification requirements, technical testing and ethical hacking, as well as readiness assessments and internal audits. Waiting until 2027 may mean discovering too late that the gap was not documentary in nature, but rather rooted in product architecture, processes, or controls.
Internet Security Auditors | CRA Compliance Assessment and Support
GAP Analysis & Classification · Action Plan · Implementation · Vulnerability Management & Reporting · Secure Development · Internal Audit · Ethical Hacking
CRA Compliance Assessment and Support


CRA: el software forma parte del producto. Una actualización también.


Infographic created by ISEC based on Regulation (EU) 2024/2847 and Internet Security Auditors' CRA service approach.

References

🗒️Notebookcheck — “The refrigerator is dead”: Samsung’s AI fridges shut down after update, causes outrage (23/09/2026).
🗒️Regulation (EU) 2024/2847 (Cyber Resilience Act) — Articles 6, 13, 14 and Annex I.
🗒️EUR-Lex — Cyber Resilience Act: obligaciones sobre actualizaciones, soporte y gestión de vulnerabilidades.
🔗 Internet Security Auditors — CRA Compliance Assessment and Support.
🔗Internet Security Auditors — CRA: On 11 September, the 24-Hour Clock Starts Ticking.