As fleets continue adopting connected vehicles, telematics platforms, and AI-powered technologies, cybersecurity is becoming an increasingly important part of fleet operations.
During a recent discussion with Automotive Fleet, Yaniv Maimon, VP of Cyber Research at Upstream, outlined the evolving cyber threat landscape for commercial fleets and explained why fleet managers should begin treating cybersecurity as a business risk rather than solely an IT concern.
Ransomware Remains the Most Common Threat
Among the cyber incidents affecting fleets today, ransomware continues to pose one of the greatest operational risks. Rather than targeting vehicles directly, ransomware attacks typically focus on the organizations that operate them, encrypting critical systems or preventing employees from accessing fleet management platforms and business data.
Third-party technology providers can also become targets.
One example discussed was an outage involving a cloud-based electronic logging device (ELD) provider. When the provider’s systems became unavailable, fleets relying on its service were forced to switch to manual logging, creating operational delays and compliance challenges.
These incidents highlight how dependent fleets have become on connected technologies and cloud-based services.
Cargo Theft Has Entered the Digital Age
Cybercriminals are also changing how they steal freight.
Rather than relying on physical theft, attackers are increasingly using stolen credentials, compromised business systems, or impersonated fleet accounts to redirect valuable shipments.
According to Maimon, these digitally enabled cargo theft schemes have resulted in hundreds of millions of dollars in losses and continue to become more sophisticated.
The growing threat has attracted federal attention as law enforcement agencies monitor the increase in organized cargo theft targeting commercial transportation.
Connected Vehicles Add a New Layer of Attack
Modern vehicles communicate with mobile applications, telematics platforms, and manufacturer cloud services every day. While those connections provide fleets with valuable operational data, they also create additional entry points that attackers may attempt to exploit.
Security researchers have demonstrated vulnerabilities in some vehicle ecosystems that could allow unauthorized users to perform remote functions, such as unlocking doors, starting a vehicle, or accessing its location, if left unaddressed.
Although these scenarios typically require exploiting software vulnerabilities, they demonstrate why cybersecurity must now be considered part of vehicle risk management.
Lessons from Autonomous and Ride-Hailing Fleets
The continued expansion of connected mobility services also offers insight into future cybersecurity challenges.
Maimon pointed to incidents involving ride-hailing and autonomous vehicle platforms where attackers manipulated transportation systems by dispatching large numbers of vehicles to the same location, creating traffic congestion and operational disruptions.
These incidents illustrate how software-based attacks can increasingly affect transportation operations.
Smaller Fleets May Face Greater Challenges
Although cyber threats affect organizations of every size, smaller fleets often operate with fewer cybersecurity resources.
Larger organizations typically have dedicated IT teams, security controls, and established processes for identifying and responding to threats. Smaller businesses, by comparison, may have limited technical staff and fewer protections, making them attractive targets for attackers seeking easier access.
For fleets looking to assess their cybersecurity readiness, Maimon recommended using the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
AI is expected to reshape both cyber defense and cybercrime.
Advanced AI systems are becoming increasingly capable of identifying software and hardware vulnerabilities at unprecedented speed, but they also add a layer of vulnerability.
