Home / Blog / Automotive Cybersecurity
Published: August 25, 2026

Automotive Cybersecurity: Protecting the Connected Car from New Threats

Automotive Cybersecurity: Protecting the Connected Car from New Threats

Every new vehicle rolling off a modern assembly line is, in effect, a data center on wheels. Telematics control units, over-the-air update channels, infotainment systems, and cloud-linked mobile apps have turned cars into networked endpoints, and networked endpoints attract attackers. What was once a theoretical risk discussed at security conferences is now a documented, escalating pattern of real-world incidents that shut down factories, exposed millions of records, and forced regulators worldwide to rewrite the rules for vehicle type approval.

The Expanding Attack Surface of the Connected Car

The scale of the problem is no longer anecdotal. Publicly reported cybersecurity incidents across the automotive and smart mobility ecosystem climbed from roughly 220 in 2021 to 494 in 2025, an all-time high that reflects both a genuinely wider attack surface and improved incident tracking by industry researchers. 

Vehicles are only part of the story: backend servers, cloud platforms, dealer management systems, and third-party API integrations have become primary entry points, since compromising a single cloud service can expose data or control pathways across an entire vehicle fleet rather than one car at a time.

Global publicly reported automotive cyber incidents, 2021–2025.
Figure 1: Global publicly reported automotive cyber incidents, 2021–2025.

This growth is not evenly distributed across attack types. Ransomware has moved from a peripheral concern to a dominant one, with its share of total incidents more than doubling between 2024 and 2025 as organized criminal groups recognized that halting a single assembly line can cost an automaker tens of millions of dollars a day. The overwhelming majority of attacks, more than nine in ten, are now executed remotely, meaning attackers rarely need physical proximity to a vehicle or facility to cause damage.

Anatomy of a Modern Automotive Cyberattack

The Jaguar Land Rover Wake-Up Call

No single 2025 event illustrated the stakes more clearly than the cyberattack on Jaguar Land Rover. A breach traced by investigators to Russian-linked hackers forced the automaker to halt global production across plants in the UK, Slovakia, Brazil, India, and China for roughly five weeks starting in late August 2025. With the company normally producing close to 5,000 vehicles a week, the shutdown was estimated to cost JLR itself hundreds of millions of dollars, while the wider ripple effect across its 120,000-strong UK supply chain pushed total economic damage toward an estimated $2.5 billion, contributing to a measurable double-digit decline in UK vehicle output for the year. Around the same period, Stellantis disclosed unauthorized access to a third-party customer service platform, underscoring that suppliers and vendors, not just OEM networks, are now squarely in the blast radius.

Why Backend and Supply-Chain Systems Are the New Frontline

These incidents share a pattern that industry researchers have flagged consistently: attackers increasingly bypass the vehicle itself and target the software supply chain around it, including telematics back ends, dealer platforms, and cloud-based customer relationship systems. Analysis of 2024 incidents found that 60% affected thousands to millions of connected assets in a single event, with the share of massive-scale, multi-victim attacks nearly quadrupling between 2023 and 2024, evidence that a single successful intrusion now scales far beyond one compromised vehicle.
Regulatory Response: From Guidance to Mandate
Regulators have moved from voluntary guidance to binding law. In the United States, the National Highway Traffic Safety Administration first logged a cybersecurity-linked recall in 2015, covering 1.4 million vehicles, and has since issued and updated non-binding Cybersecurity Best Practices for the industry, most recently drawing on research into electric vehicle battery management systems and zero-trust architectures. 

Internationally, the picture is stricter: under UNECE Regulation No. 155 and its companion, R156, more than 60 contracting markets, including the EU, UK, Japan, and South Korea, made a certified Cybersecurity Management System mandatory for all new vehicle types from July 2022, extending that requirement to every new vehicle produced from July 2024. China has followed with its own GB 44495:2024 standard, effective for new vehicle types from January 2026, while the Automotive Information Sharing and Analysis Center, whose membership now represents more than 99% of light-duty vehicles on North American roads, continues to expand its best-practice guides and software bill-of-materials reporting frameworks for its member OEMs and suppliers.

Key milestones in the global automotive cybersecurity regulatory timeline.
Figure 2: Key milestones in the global automotive cybersecurity regulatory timeline.

Building Resilience: Where the Industry Goes From Here

Consulting analyses of the shift toward software-defined vehicles describe cybersecurity as a precondition for the business model itself, not an add-on: an always-connected vehicle that cannot demonstrate resilience against remote compromise cannot legally reach the road in most major markets, and cannot earn consumer trust even where it can. Closing the gap between attacker capability and industry readiness increasingly means treating over-the-air update pipelines, cloud APIs, and third-party integrations with the same rigor historically reserved for the vehicle's own electronic control units, including continuous penetration testing, software bill-of-materials tracking, and zero-trust segmentation between telematics systems and safety-critical networks.

Composition of 2025 automotive and smart mobility cyber incidents by category.
Figure 3: Composition of 2025 automotive and smart mobility cyber incidents by category.

The direction of travel is clear. Cyber risk in the automotive sector has shifted from a compliance checkbox tied to a single vehicle recall to a systemic, supply-chain-wide exposure capable of halting production networks and moving national manufacturing output statistics. Manufacturers, suppliers, and mobility service providers that treat cybersecurity as core vehicle architecture, rather than a bolt-on feature, will be the ones best positioned to absorb the next wave of attacks rather than be defined by it.

Frequently Asked Questions

What is automotive cybersecurity?
It is the set of practices, standards, and technologies used to protect a vehicle's electronic control units, connectivity channels, telematics systems, and the cloud and mobile infrastructure around it from unauthorized access, manipulation, or disruption.
Why have automotive cyberattacks increased so sharply?
Growing vehicle connectivity, over-the-air update channels, and cloud-linked backend systems have expanded the attack surface, while ransomware groups have recognized that halting vehicle production or accessing fleet-wide data can be highly profitable.
Is UNECE R155 compliance mandatory everywhere?
No. It is legally binding only in the roughly 60 contracting markets that have adopted it into their vehicle type-approval systems, including the EU, UK, Japan, and South Korea; the US and China currently operate separate regulatory frameworks, though China has introduced its own comparable standard, GB 44495:2024.
What was the real-world impact of the Jaguar Land Rover attack?
It halted global production for about five weeks in 2025, contributed to an estimated $2.5 billion in wider UK economic damage, and was a significant factor in a double-digit annual decline in UK vehicle manufacturing output.
What can automakers and suppliers do to reduce risk?
Priorities include certified cybersecurity management systems aligned with ISO/SAE 21434, software bill-of-materials tracking, zero-trust segmentation of safety-critical networks, rigorous vetting of third-party and cloud vendors, and active participation in information-sharing bodies such as the Auto-ISAC.