//php echo do_shortcode(‘[responsivevoice_button voice=”US English Male” buttontext=”Listen to Post”]’) ?>
Cybersecurity is one of the most challenging issues in the automotive industry, despite sustained efforts to develop and deploy comprehensive solutions. New categories of cyberattacks will emerge alongside new vulnerabilities as software-defined vehicles (SDVs) add new software platforms. Artificial intelligence expands cyberattack methods and capabilities while enabling increasingly sophisticated attackers to develop new threats and strategies.
Continuous improvements in cybersecurity technology, products, and services are required. AI-based cyber defense has become increasingly important in the automotive industry, while regulations and standards need to be updated regularly. Effective cybersecurity also requires real-time tracking of new and emerging cyberthreats.
The annual reports published by Upstream Security remain a key reference for tracking developments in automotive cybersecurity. The 2026 Upstream Global Automotive Cybersecurity Report is the eighth annual edition, with 144 pages of data and references. Upstream has a large and growing database of cybersecurity information. It monitors over 40 million mobility assets and tracks more than 50 billion API messages per month. It has also tracked vehicles over 120 billion miles. Upstream said it monitored 1,871 active cyberthreat actors in 2025, up from 1,133 in 2024.
Since 2010, Upstream has analyzed 2,651 automotive-related cyber incidents. In 2025 alone, Upstream analyzed 494 publicly available cybersecurity incidents, up from 409 in 2024 and 295 in 2023.
By MRPeasy 08.01.2026

By Nidec 07.30.2026

By Beenish Zia, Principal Engineer, Intel 07.27.2026
This article summarizes and analyzes key findings from Upstream’s 2026 report on 2025 cyberattack trends. The full Upstream report is available here in English and Japanese.
CVE growth
Common Vulnerabilities and Exposures (CVEs) identify, define, and catalog publicly disclosed vulnerabilities that can be exploited in cyberattacks. The Common Vulnerability Scoring System (CVSS) is an open, standardized method for rating the severity of CVEs. The CVSS helps organizations prioritize and coordinate joint responses based on the vulnerability’s severity, time of introduction, and environmental factors. Vulnerabilities are graded as Critical, High, Medium to Low, or None, based on their CVSS score.
The next figure shows how auto-related CVEs increased in the last seven years, from 24 new CVEs in 2019 to 450 new CVEs in 2025. Cumulative CVEs jumped from 24 in 2019 to 1,597 in 2025. New CVEs added in 2025 accounted for 28% of the total.
Upstream focused only on CVEs that directly affect the automotive and smart mobility ecosystem, such as OEMs, Tiers 1s, shared mobility, mobile IoT devices, and fleets. Upstream excluded CVEs related to generic IT hardware or open-source software components used across the supply chain.

Upstream tracks the source and severity of each automotive vulnerability. The next figure shows the sources and severity of new vulnerabilities in 2024 and 2025. The number of CVEs grew from 422 in 2024 to 450 in 2025. The top pie charts show the sources of vulnerabilities in 2024 and 2025, including auto OEMs, Tier 1s, Tier 2s, suppliers of electric-vehicle equipment, and others. Tier 2s accounted for the largest share of CVEs, at 56% in 2024 and 47% in 2025.

The severity of CVEs in 2024 and 2025 is summarized in the bottom pie charts with four levels included. In 2025, critical and high-severity vulnerabilities accounted for 60% of total CVEs.
Cybersecurity incident trends
Cybersecurity incidents continue to grow in the automotive industry. There is also a trend toward greater damage from cyberattacks as they impact a growing number of vehicles and their related mobility services.
Upstream analyzed publicly disclosed automotive cybersecurity incidents between 2021 and 2025 based on their potential scale of impact on mobility assets. The impact included vehicles, users, mobility devices, and more. Upstream categorized incidents into four levels of impact:
- Low includes incidents with the potential to impact fewer than 10 assets.
- Medium covers incidents impacting up to 1,000 vehicles or mobility assets.
- High includes incidents affecting thousands of vehicles or mobility assets.
- Massive covers incidents with the potential to impact millions of mobility assets.
The following table summarizes Upstream’s analysis of trends from 2021 through 2025 based on these four levels of impact. The top line lists the number of incidents analyzed for each year.
| Publicly Disclosed Cybersecurity Incidents by Potential Scale | |||||
| Cyber Incidents Scale | 2021 | 2022 | 2023 | 2024 | 2025 |
| Cybersecurity incidents analyzed | 238 | 268 | 295 | 409 | 494 |
| Yearly growth of incidents | 10.7% | 12.6% | 20.2% | 38.6% | 20.7% |
| Low: up to 10 mobility assets | 42.5% | 40.4% | 14.6% | 7.5% | 4.3% |
| Medium: up to 1,000 mobility assets | 36.7% | 37.5% | 35.9% | 32.5% | 34.4% |
| High: thousands of mobility assets | 19.6% | 20.6% | 44.1% | 40.6% | 40.9% |
| Massive: millions of mobility assets | 1.2% | 1.5% | 5.4% | 19.4% | 20.4% |
| (Source: Upstream Security, Cybersecurity Reports; Compilation: Egil Juliussen, April 2026) | |||||
In 2021 and 2022, high- or massive-impact incidents accounted for 20% to 22% of total cybersecurity incidents. In 2023, the proportion of incidents with a high or massive impact doubled to nearly 50% and reached 60% to 61% in 2024 and 2025. This shift toward large-scale attacks has major implications for the vehicles and mobility assets affected by cyberattacks.
Translating these percentages into potential numbers of affected vehicles and mobility assets provides a clearer picture. The massive incident category, involving more than 1 million potentially affected mobility assets, is by far the largest. It accounted for 20.4% of 494 incidents in 2025, or 100 cybersecurity attacks, each involving more than 1 million targets. Assuming 1 million assets impacted, this could add up to well over 20 million mobility assets being attacked. The high category, assuming 10,000 mobility assets were attacked, adds up to 2 million+ (494 × 40.9% × 10,000). The medium category adds up to only 166,600 vehicles/mobility assets. The low category is less than rounding errors. The massive category therefore represents the most serious cybersecurity incident group in terms of potential impact.
Cybersecurity incidents by damage type
The next figure shows a breakdown of the most prominent types of automotive-related cyber incidents. The bar chart shows each incident type as a percentage of total cyber incidents from 2023 through 2025. Some incidents have multiple impacts, and the percentages add to over 100%, especially the last two years.
Data privacy breaches were the largest category, accounting for 68% of all incidents. The desirability of this data is driven by the increasing availability of credit-card and related information stored in vehicle and mobility systems. Service and business disruption was the second-highest incident category, at 34% in 2025, driven largely by ransomware attacks.

Manipulation of electronic control units (ECUs) and vehicle control was the third-largest category, accounting for 22% of incidents in 2025, down from 35% in 2024. Fraud-related incidents were similar in 2023 and 2024, at 19% to 20% of incidents, before dropping to 12% in 2025. One of the most common fraud categories on the deep web is mileage fix, formally known as odometer fraud. Every year, about 450,000 vehicles are sold with false odometer readings, costing U.S. buyers over $1 billion, according to National Highway Traffic Safety Administration data.
Cyberattack vector diversity
Cyberattacks in 2025 were more sophisticated and frequent than in previous years. They targeted vehicles and back-end systems, as well as smart mobility platforms, devices, and applications. Attack vectors show that any point of connectivity is vulnerable to cyberattacks. The next figure illustrates the diversity of attack approaches.
Back-end servers, such as telematics and application servers, experienced a large increase in cyber incidents. Server-related incidents grew from 35% in 2022 and 43% in 2023 to 67% in 2025. By exploiting vulnerabilities in back-end servers, a black hat actor could potentially attack vehicles while they are on the road.
Connected vehicles and smart mobility services use a wide range of external and internal APIs, resulting in billions of transactions per month. OTA and telematics servers, OEM mobile apps, infotainment systems, mobility IoT devices, EV charging management, and billing apps all rely heavily on APIs. APIs also present significant and fleet-wide large-scale attack vectors, resulting in a wide range of cyberattacks, including theft of personal information, back-end system manipulation, or remote vehicle control.
API hacking is cost-effective with the ability to execute large-scale attacks. It requires relatively low technical expertise, uses standard techniques, and can be carried out remotely without specialized hardware. API attacks grew from 13% in 2023 to 17% in 2024, before declining slightly to 16% in 2025.

Infotainment-related incidents were significant in 2023, at 15%, up from 8% in 2022, but declined in 2024 and dropped to 11% in 2025.
ECUs run all electronic systems that operate vehicles. Hackers try to manipulate ECUs and take control of their functions, often by running multiple sophisticated systems at the same time. ECU-related cyberattacks contributed 7% of incidents in 2025, down slightly from 9% in 2023.
Safe and secure charging infrastructure is essential to the adoption of EVs. Currently, many chargers, charging infrastructure systems, and related apps are vulnerable to physical and remote manipulation, exposing EV users to fraud and ransomware attacks. Such attacks can also impact charging network reliability. EV charging cyberattacks grew from 4% in 2023 to 8% in 2025.
Growing incidents of ransomware attacks
Organized ransomware groups are increasingly targeting a broad range of automotive and mobility companies, including OEMs, Tier 1 and Tier 2 suppliers, dealerships, and EV charging infrastructure, through ransomware campaigns, data breaches, and supply chain compromises. Ransomware attacks are now a major issue in automotive, with 218 ransomware attacks in 2025, accounting for 44% of all publicly reported incidents. In 2024, there were 108 ransomware attacks, or 26% of 409 cybersecurity incidents.
Upstream identified 49 active ransomware groups in 2024, rising to 77 in the third quarter of 2025. Some ransomware groups now offer ransomware-as-a-service, enabling attacks across industries, including automotive. They gain access via spear-phishing, credential theft, exploitation of VPNs, or compromised third-party suppliers. Once inside, they move laterally across engineering servers, enterprise resource-planning environments, and production networks, copying sensitive data before encrypting systems to halt operations.
This double-extortion strategy, which combines data theft with encryption, is especially devastating for OEMs that rely on just-in-time production and globally integrated IT systems and supply chains. The 2025 incidents show a broad escalation in ransomware targeting automotive OEMs and Tier 1 suppliers, with attackers pursuing operational disruption rather than simple data theft.
Much of the knowledge and tooling used in ransomware attacks is shared through the deep and dark web. Malicious actors increasingly target the automotive and mobility industry. Every part of the supply chain can pose a risk to OEMs, service providers, and mobility devices and applications. Ransomware attacks can severely impact operational availability and production or expose sensitive customer information and system credentials. To extort money, attackers typically maintain a “leak site” on the dark web. This is where they reveal stolen data and share information about their attacks and victims.
In August 2025, Jaguar Land Rover suffered a crippling ransomware attack that disrupted global operations and halted production for over a month across facilities in the U.K., Slovakia, China, and India. The campaign combined ransomware deployment with extensive data theft, making it one of the most severe cyber incidents to impact an automotive manufacturer. The attackers exfiltrated internal code repositories, debug logs, and enterprise data before encrypting systems, forcing the company to shut down critical IT infrastructure and stop vehicle production. According to The Guardian, this incident impacted over 5,000 organizations in the U.K. An NBC news report estimated the cost to Jaguar Land Rover at about $2.5 billion, making it the most expensive cyberattack in U.K. history.
AI impact on automotive cybersecurity
The auto industry is moving toward making AI technologies a core strategy and competitive element of future vehicle systems, services, and lifetime management. The next table summarizes AI cybersecurity threats.
Machine learning (ML), large language models (LLMs), generative AI (GenAI), and AI agents are reshaping mobility and cybersecurity alike while creating new and complex cybersecurity challenges. AI-based cyberattacks require a lifetime, product-focused defense model that spans the cloud, APIs, and all vehicle electronic systems.
| AI Technology: Next Major Cybersecurity Threat | ||
| Key Information | Other Information | |
| AI segments | ML, LLMs, GenAI, AI agents | All AI technologies impact automotive |
| AI and SDVs | AI defines next phase of SDVs; adds complexitySDV complexity creates cybersecurity risks | SDV design uses APIs and microservicesAPI-based microservices: new attack surface |
| LLMs and Model Context Protocol (MCP) | MCP expands LLM functionality and complexity LLMs and MCP create new capabilities MCP enables LLMs to orchestrate new functions | LLM has fixed functions based on trainingBased on real-time and other new dataCreates hard-to-secure attack surfaces |
| GenAI | GenAI promises to improve user interface | Use of third-party AI platforms adds cyber risks |
| Emerging auto AI apps | ADAS and AV real-time decision supportVoice copilots: conversational AI assistantsPersonalization using GenAIOEM-specific, domain-specific LLMs | E2E AI tech in AVs is growing quicklyReplacing command-based voice systemsCabin settings, driving preferences, etc.Engineering, software development, operation, etc. |
| AI regulation | ISO/IEC 42001: Framework for trustworthy AIUS NIST AI Risk Management Framework: 2023 | First standard for AI management systemsIndustry-agnostic map to manage AI risk |
| Summary | AI to be core strategy and competitive product | Requires greatly improved cyber solutions |
| (Source: Upstream Security, 2026 Cybersecurity Report; Compilation: Egil Juliussen, April 2026) | ||
AI defines the next phase of SDVs, driven by its potential benefits and growing revenue opportunities. The complexity of transitioning to SDVs has encouraged OEMs to use AI technology from partners such as Nvidia, Google, Wayve, and others to develop next-generation SDVs, often with ADAS and/or L3/L4 capabilities. SDVs already use APIs and microservices that add cybersecurity attack surfaces. AI expands these risks.
The use of MCP in LLM-based systems introduces new capabilities and added complexity that are harder to defend than API-based software. MCP is an open standard introduced by Anthropic in November 2024. LLMs have fixed capabilities that are frozen when their initial training ends. Using MCP removes this drawback and allows LLM updates based on new data, including real-time data. Hence, MCP will be needed to use LLMs in SDV applications.
GenAI adoption increases supply chain cybersecurity risks. GenAI apps promise improved vehicle user experiences, but their reliance on many third-party AI components and platforms introduces substantial supply chain risks. A vulnerability in a single external service can have cascading effects across an entire fleet. These threats can appear in vehicle-related cloud services and in-vehicle systems.
New, AI-based SDV apps and platforms introduce additional cybersecurity risks. These software-centric systems have large ecosystems across cloud platforms, edge platforms, in-vehicle platforms, and users’ mobile devices. This creates potential cyberattack entry points that can be exploited by sophisticated and experienced black hat attackers.
Recent cyberattacks have shown that potential cyberattack damage can top $1 billion. This makes cybersecurity protection a top priority for managing and operating any automotive and mobility business. AI technology creates new attack surfaces that increase risks and potential costs. AI-based cyber defense will improve, but the attackers’ use of AI will also advance.
The growing use of external services and third-party AI platforms removes the traditional vehicle perimeter defense and extends the attack surface across a distributed ecosystem of cloud servers, mobile apps, and interconnected APIs. Hence, automotive cybersecurity must evolve from protecting individual components to defending and securing the entire product ecosystem.
Summary
Automotive cybersecurity is a growing segment on multiple levels, from the number of vulnerabilities and attackers to the increasing sophistication of attacks and the response efforts of the automotive cybersecurity industry players. The growth in annual and cumulative automotive cybersecurity incidents is summarized in the following figure, based on Upstream’s data collection and analysis.
The left bar chart shows annual automotive cybersecurity incidents, which grew from 57 attacks in 2017 to 494 in 2025. The right bar chart shows cumulative cyberattacks, rising from 177 in 2017 to 2,371 by year-end 2025—a thirteenfold increase.

Several technology trends are having a significant impact. SDVs introduce large amounts of software code, increasing the potential attack surface across APIs and cloud servers. AI is also becoming a major factor in cybersecurity, both for launching attacks and for discovering, analyzing, and defending against a flood of sophisticated attack vectors.
The growing impact of information and tools from the deep and dark web became evident in 2024, when the number of ransomware attacks reached 108 incidents, accounting for 26% of the 409 total incidents recorded that year. Ransomware attacks nearly doubled to 218 in 2025, representing 44% of the total 494 attacks.
The diversity of cybersecurity attack vectors continues to grow. Back-end servers for telematics, connected car apps, and mobility apps have become the largest attack vector, accounting for 67% of all cyberattacks in 2025, up from 48% in 2023.
A major factor driving vulnerability growth is the increasing use of APIs to enable communication between different software platforms and apps and everything software-related. API-based communications occur billions of times per month, and a minuscule percent of vulnerabilities can quickly add up to major security risks.
In this year’s report, Upstream focused on the growing threat posed by the use of AI in SDV development. The growing adoption of ML, LLMs, GenAI, and AI agents is redefining mobility and transportation operation and usage, from user interfaces to autonomous vehicles. This greatly expands cybersecurity challenges and risks across all aspects of operations, from engineering and design to manufacturing and marketing. These evolving cybersecurity threats require the highest level of attention across the automotive and transportation industries.
The next figure provides a timeline summarizing how increasing vehicle connectivity has enabled increasingly sophisticated cyberattacks, with more to come in future years. The bottom of the figure shows that vehicles without wireless connectivity are isolated from remote attacks, although on-premises attacks may still be possible.
Telematics emerged just before 2000 and has expanded dramatically over the past 25 years. Initially, automotive connectivity attracted little attention from the black hat community, but that changed by 2015. Over the past decade, telematics has become an increasingly attractive target for cyberattacks.

The SDV age is now well underway, and cyberattack targets are increasing dramatically, with cloud servers and APIs as the primary focuses. As the automotive industry adopts AI technologies, opportunities for cyberattacks are expected to jump again. MCP is worth mentioning: It expands the capability of LLMs by allowing functional updates based on real-time data, but it also increases software complexity and makes LLMs harder to defend against cyberattacks.
Recent reports that Anthropic’s Mythos AI model can identify software vulnerabilities with exceptional efficiency-reinforce warnings highlighted by Upstream Security. Currently, Mythos is available only to selected software companies so they can find and fix many new software platform vulnerabilities before they are exploited by black hat hackers. It is only a matter of time before capabilities similar to Mythos are available for automotive cyberattacks, which should serve as a wakeup call to the automotive industry—and all other industries—and consumers using internet-based apps.
Read also:
Waymo Dominates California AV Test Data
Nvidia: Star Attraction at CES 2026
AI Drives AV Momentum at CES 2026
AI AND BIG DATA, AUTOMOTIVE (EV/AV), CYBERSECURITY
UPSTREAM
