Skip to main content
HomeTopicsAutomotive Cybersecurity

Automotive Cybersecurity

Cybersecurity statistics about automotive cybersecurity

Showing 1-20 of 57 results

102% year-on-year increase in automotive vulnerabilities (Q1 2026 vs Q1 2025)

PCA Cyber Security5/27/2026
CVEsYear-on-Year

14 different attack methods observed in Q4 2025 automotive vulnerabilities

PCA Cyber Security5/27/2026
Attack Vectors

160 Medium, 75 High, and 16 Critical automotive vulnerabilities identified in Q1 2026

PCA Cyber Security5/27/2026
CVSSSeverity

2024 SafePay ransomware breach at a global BPO provider exposed nearly 17,000 employees and customers of a major commercial vehicle manufacturer, disclosed in January 2026 after a 14-month notification delay

PCA Cyber Security5/27/2026
BPOSafePay

206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025

PCA Cyber Security5/27/2026
CVEsQ4 2025

265 unique automotive-specific vulnerabilities identified in Q1 2026

PCA Cyber Security5/27/2026
CVEsQ1 2026

28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025

PCA Cyber Security5/27/2026
CVEsQuarter-on-Quarter

3.7 million of the 12.4 million records exposed in the ShinyHunters automotive marketplace breach were previously unseen in other breaches

PCA Cyber Security5/27/2026
ShinyHuntersData Breach

64 distinct CWEs mapped in Q4 2025, down from 82 in Q3 2025

PCA Cyber Security5/27/2026
CWEs

77 distinct CWEs mapped in Q1 2026, up from 64 in Q4 2025

PCA Cyber Security5/27/2026
CWEs

88% of Q1 2026 automotive vulnerabilities require Low Attack Complexity

PCA Cyber Security5/27/2026
Attack Complexity

An automotive parts marketplace database with over 7.7 million records was exposed via a misconfigured Elasticsearch instance in January 2026

PCA Cyber Security5/27/2026
AftermarketMisconfiguration

Around 60% of automotive vendors had already adopted IDS at time of Automotive Cyber Security Connectivity and SDV Week 2025 survey

PCA Cyber Security5/27/2026
IDSAdoption

BEAST threat actor leaked 700 GB of internal data from a large Chinese automotive group in late February 2026

PCA Cyber Security5/27/2026
Data BreachChina

ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling

PCA Cyber Security5/27/2026
EV ChargingChargePoint

China's amended Cybersecurity Law took effect on 1 January 2026 (passed 28 October 2025) with raised penalties and extraterritorial reach

PCA Cyber Security5/27/2026
RegulationChina

ControlLoc adversarial attack on AV object trackers achieved up to 98.5% success digitally and over 79% in physical tests against the Baidu Apollo stack

PCA Cyber Security5/27/2026
Autonomous VehiclesAdversarial AI

DefenseWeaver multi-agent LLM identified 11 critical attack paths across four automotive projects in TARA testing

PCA Cyber Security5/27/2026
AI/LLMTARA

Delta Alarm cyberattack disabled mobile-app vehicle controls for hundreds of thousands of Russian vehicle owners for up to two weeks in late January 2026

PCA Cyber Security5/27/2026
TelematicsCloud Hijack

Delta Alarm took approximately five days to restore partial functionality and nearly two weeks to fully recover from the cloud control plane attack

PCA Cyber Security5/27/2026
TelematicsIncident Response