News Security Technology

Cyberattacks Targeting Automotive Industry Surge By 50% In Early 2025

Ransomware attacks have proven particularly damaging, accounting for 45% of recorded incidents so far this year

Cybersecurity incidents targeting the automotive and mobility sectors have surged nearly 50% in the first quarter of 2025, according to new research from Upstream Security. The findings reveal a concerning trend of escalating cyber threats directed at vehicles, manufacturers, and service providers.

Upstream researchers recorded 148 publicly disclosed incidents between January and March, a figure that, if sustained, will easily surpass the 409 incidents reported throughout all of 2024. However, experts caution that the real number of attacks is likely much higher.

“What’s published on the Clear Web is just the absolute tip of the iceberg,” said Yaniv Maimon, Vice President of Cyber Services at Upstream. “There’s also a lot of activity that happens in the deep and Dark Web that was not disclosed by the organisations who suffered the attacks.”

Ransomware attacks have proven particularly damaging, accounting for 45% of recorded incidents so far this year. In one notable case, India-based Tata Technologies fell victim to an attack in January, resulting in 730,160 company files (approximately 1.4TB of data) being leaked to the Dark Web by the group Hunters International.

Maimon explained that ransomware groups frequently steal credentials through infostealers, enabling attackers to impersonate dealers or employees of original equipment manufacturers (OEMs). “By using OEM credentials, you can sometimes get access to vehicles. Some OEMs provide their employees with access to customers’ vehicles to see their locations, even run commands in some extreme cases,” he added.

Upstream’s analysis found that 26% of the security incidents reported could have led to direct manipulation of vehicles on the road.

Beyond ransomware, data breaches and privacy violations accounted for 63% of recorded incidents, while 53% carried risks of service or business disruption. Alarmingly, 57% were classified as having “high” or “massive” risk, with the potential to impact thousands to millions of vehicles.

On the Dark Web, the situation appears even graver. Upstream noted that 62% of malicious activities detected could pose high risks to vehicles, with a further 9% representing massive threats.

A notable emerging risk area is electric vehicle (EV) chargers. While EV chargers accounted for 15% of incidents in the first quarter — up from 6% in 2024 — no actual cyberattacks on chargers have been reported yet, only vulnerabilities identified in laboratory settings.

However, Upstream warns that the threat landscape is rapidly evolving. The number of threat actors focusing on the automotive sector has almost quadrupled in the past year, jumping from around 300 to 1,100.

“It’s almost quadrupled,” Maimon said. “You can see a kind of rush of different threat actors toward this industry, because they understand the potential opportunity.”

As the automotive and mobility sectors continue to digitise and connect vehicles, the need for robust, proactive cybersecurity measures has never been more urgent.

Leave a Reply

Your email address will not be published. Required fields are marked *