Key Takeaways
- Automotive cybersecurity threats are rising sharply: 494 publicly disclosed incidents were analyzed in 2025, a 20.7 % increase from 2024, and cumulative attacks have grown thirteen‑fold since 2017.
- Vulnerability disclosures (CVEs) specific to the mobility ecosystem surged from 24 in 2019 to 450 in 2025, with Tier 2 suppliers contributing the largest share of new CVEs (47 % in 2025) and 60 % of all CVEs rated critical or high severity.
- Large‑scale attacks dominate: 20.4 % of 2025 incidents were “massive” (impacting > 1 million assets), potentially affecting over 20 million vehicles or mobility assets.
- Data‑privacy breaches are the most common incident type (68 % of cases), followed by service/business disruption (34 %)—largely driven by ransomware—and manipulation of electronic control units (22 %).
- Attack vectors are diversifying; back‑end servers now account for 67 % of all cyber incidents, while APIs remain a pervasive entry point, exploited in 16 % of attacks.
- Ransomware activity is accelerating: 218 attacks in 2025 represented 44 % of all incidents, up from 26 % in 2024, with 77 active ransomware groups identified by Q3 2025.
- Emerging AI technologies (ML, LLMs, GenAI, AI agents) and the Model Context Protocol (MCP) expand the attack surface, introducing new complexities that outpace traditional defenses.
- Effective automotive cybersecurity now requires real‑time threat monitoring, continuous updating of regulations and standards, and a shift from protecting individual components to securing the entire vehicle‑ecosystem ecosystem.
Introduction and Scope
Cybersecurity remains one of the most pressing challenges for the automotive industry as vehicles become increasingly software‑defined and connected. The 2026 Upstream Global Automotive Cybersecurity Report—the eighth annual edition—provides a comprehensive view of 2025 threat landscapes, drawing on a database that monitors over 40 million mobility assets and tracks 50 billion API messages per month. The report analyzes 2,651 automotive‑related cyber incidents since 2010, including 494 publicly disclosed cases in 2025 alone. The analysis highlights growth in vulnerabilities, attack scale, damage types, vectors, ransomware prevalence, and the rising influence of artificial intelligence on both offense and defense.
CVE Growth and Severity
Common Vulnerabilities and Exposures (CVEs) that directly affect the automotive and smart‑mobility ecosystem rose from a mere 24 new entries in 2019 to 450 in 2025, pushing the cumulative total to 1,597. Notably, new CVEs added in 2025 constituted 28 % of the overall pool. Upstream’s focus excluded generic IT or open‑source flaws, concentrating instead on flaws impacting OEMs, Tier 1/2 suppliers, EV‑equipment providers, shared‑mobility platforms, and IoT devices.
When broken down by source, Tier 2 suppliers supplied the largest share of vulnerabilities—56 % in 2024 and 47 % in 2025—while OEMs, Tier 1s, and EV‑equipment makers contributed smaller but still significant portions. Severity analysis revealed that in 2025, critical and high‑severity CVEs accounted for 60 % of all newly disclosed vulnerabilities, underscoring the growing risk posed by exploitable flaws in the mobility supply chain.
Cybersecurity Incident Trends by Scale
Upstream classified publicly disclosed incidents by their potential impact on mobility assets into four tiers: Low (<10 assets), Medium (≤1,000 assets), High (thousands of assets), and Massive (millions of assets). In 2025, 494 incidents were analyzed, reflecting a 20.7 % year‑over‑year increase. The distribution showed that Low‑impact incidents fell to 4.3 %, Medium remained steady at 34.4 %, High held at 40.9 %, and Massive rose sharply to 20.4 %.
Translating percentages into absolute numbers illustrates the gravity: the Massive category alone represented roughly 100 attacks each affecting over one million assets, potentially exceeding 20 million compromised vehicles or devices. High‑impact incidents contributed an additional two million+ affected assets, while Medium and Low categories added comparatively minor totals. This shift toward large‑scale attacks marks a stark evolution from the early 2020s, when high‑ or massive‑impact events comprised only 20‑22 % of incidents.
Damage Types Observed
When examining the nature of damage, data‑privacy breaches emerged as the dominant threat, appearing in 68 % of all incidents from 2023‑2025. The value of personal data stored in vehicles—payment cards, location histories, and biometric identifiers—makes this a lucrative target for cybercriminals. Service and business disruption followed at 34 % in 2025, largely propelled by ransomware campaigns that halt production, disable telematics, or cripple back‑end systems.
Manipulation of electronic control units (ECUs) and vehicle control accounted for 22 % of incidents, down from 35 % in 2024, indicating a slight retreat as attackers diversify tactics. Fraud‑related incidents, including odometer tampering and mileage‑fix schemes, represented 12 % of 2025 cases after a gradual decline from 19‑20 % in prior years. Notably, the National Highway Traffic Safety Administration estimates that odometer fraud alone costs U.S. consumers over $1 billion annually.
Attack Vector Diversity
The report underscores that any point of connectivity can serve as an entry point for attackers. Back‑end servers—particularly telematics and application servers—experienced the largest surge, climbing from 35 % of incidents in 2022 to 67 % in 2025. Exploiting vulnerabilities in these servers enables threat actors to reach vehicles while they are in motion, amplifying potential harm.
Application Programming Interfaces (APIs) remain a pervasive vector, facilitating billions of monthly transactions across OTA updates, infotainment, EV‑charging management, and mobile apps. API‑related attacks held steady at roughly 16 % of total incidents in 2025, reflecting both their attractiveness due to low technical barriers and the difficulty of securing countless micro‑services.
Other notable vectors include infotainment systems (11 % in 2025), ECU manipulation (7 %), and EV‑charging infrastructure (8 %), which grew from 4 % in 2023 as electrification expands. Each vector presents distinct challenges, requiring tailored defenses ranging from secure API gateways to hardened charging‑station firmware.
Ransomware Escalation
Ransomware has become a cornerstone of automotive cyber threats. In 2025, 218 ransomware attacks were recorded—44 % of all publicly disclosed incidents—up from 108 attacks (26 %) in 2024. The number of active ransomware groups grew from 49 in 2024 to 77 by Q3 2025, with many offering ransomware‑as‑a‑service (RaaS) that lowers the barrier for affiliates.
Typical intrusion methods involve spear‑phishing, credential theft, VPN exploitation, or compromising third‑party suppliers. Once inside, attackers move laterally across engineering servers, ERP systems, and production networks, exfiltrating sensitive data before encrypting critical assets. The double‑extortion model—combining data theft with system lock‑up—has proven especially damaging for OEMs reliant on just‑in‑time manufacturing.
A case in point is the August 2025 ransomware strike on Jaguar Land Rover, which halted production across U.K., Slovakia, China, and India facilities for over a month, exfiltrated internal code repositories and enterprise data, and was estimated to cost $2.5 billion—the most expensive cyber incident in U.K. history. Such examples illustrate how ransomware can cripple global operations and erode trust.
Artificial Intelligence’s Impact on Cybersecurity
AI is simultaneously a catalyst for innovation and a source of new threat vectors. Machine learning (ML), large language models (LLMs), generative AI (GenAI), and AI agents are being embedded throughout the vehicle lifecycle—from ADAS and autonomous driving to user‑personalization and cloud‑based services.
The Model Context Protocol (MCP), introduced by Anthropic in November 2024, allows LLMs to update their capabilities with real‑time data, thereby enhancing functionality but also expanding the attack surface. MCP‑enabled LLMs can orchestrate novel functions that traditional defenses struggle to anticipate, creating “hard‑to‑secure” surfaces.
GenAI’s reliance on third‑party AI platforms introduces supply‑chain risk: a vulnerability in a single external service can cascade across an entire fleet of vehicles. Moreover, AI‑driven SDV apps generate expansive ecosystems spanning cloud, edge, in‑vehicle, and mobile platforms, multiplying potential entry points for sophisticated attackers.
While AI‑based cyber defenses are improving, adversaries are likewise leveraging AI to automate vulnerability discovery, craft convincing phishing lures, and optimize ransomware deployment. The report concludes that securing AI‑enabled mobility demands a holistic, product‑lifetime defense strategy that spans code, APIs, cloud services, and the broader supply chain.
Summary and Outlook
Overall, the automotive cybersecurity landscape is experiencing exponential growth in both volume and sophistication. Annual incidents have risen from 57 in 2017 to 494 in 2025, while cumulative attacks have surged thirteen‑fold to 2,371. The proliferation of software‑defined vehicles expands the attack surface via APIs, microservices, and cloud back‑ends, which now constitute the dominant attack vector (67 % of incidents).
Vulnerability disclosures continue to climb, with Tier 2 suppliers contributing the largest share and a majority of new CVEs rated critical or high. Large‑scale “massive” impacts now affect over one‑million assets per event, potentially jeopardizing tens of millions of vehicles.
Damage patterns show data‑privacy breaches leading the list, followed closely by service disruption (mainly ransomware), ECU manipulation, and fraud. Ransomware alone accounted for nearly half of all 2025 incidents, underscoring its status as a premier threat.
Finally, the integration of AI technologies—while delivering performance and user‑experience benefits—introduces fresh complexities that attackers are already exploiting. Effective defense will require continuous threat intelligence, regular updates to standards and regulations, real‑time monitoring of billions of API messages, and a shift from protecting isolated components to safeguarding the entire mobility ecosystem. As the industry advances toward fully autonomous, AI‑driven vehicles, cybersecurity must evolve in lockstep to preserve safety, privacy, and trust.

