Automotive cybersecurity incidents surge 20.7% in 2025; ransomware doubles, AI expands attack surface
Upstream Security's 2026 Global Automotive Cybersecurity Report reveals a material escalation in cybersecurity risks across the automotive and smart mobility ecosystem in 2025. The report analyzed 494 publicly disclosed cybersecurity incidents, up from 409 in 2024 and 295 in 2023, representing year-over-year growth of 20.7%. Critically, ransomware-related attacks doubled, accounting for 44% of all incidents in 2025 vs. 22% in 2024, with attackers increasingly targeting vehicle systems directly, not just enterprise IT. In mid-2025, attackers accessed remote vehicle control systems via companion apps, locked owners out of ignition and door locks, and demanded ransom to restore access.
The report identifies two converging forces: (1) AI significantly expands the cybersecurity attack surface, as traditional perimeter defenses no longer suffice when AI systems adapt dynamically and directly influence physical outcomes. (2) Financially motivated, well-resourced, and coordinated attack groups are increasingly targeting the sector, causing a sharp escalation in large-scale incidents. In 2025, attacks impacting thousands to millions of vehicles rose to 61% of all incidents (vs. 40.6% in 2024). Critical and high-severity CVEs accounted for 60% of total automotive CVEs discovered in 2025; cumulative CVEs jumped from 24 in 2019 to 1,597 in 2025.
Backend servers and APIs have become the primary weak points, with 67% of incidents leveraging telematics and cloud systems as attack vectors. 92% of attacks were conducted remotely, with 86% requiring no physical proximity to vehicles. Tier 2 suppliers accounted for 47% of new CVEs, indicating supply-chain fragmentation remains a vulnerability. Upstream monitored 1,871 active cyberthreat actors in 2025 (up from 1,133 in 2024) and tracked over 50 billion API messages per month across 40 million monitored mobility assets.
For OEMs, suppliers, and mobility operators: the doubling of ransomware, rapid expansion of API attack surfaces, and AI-enabled exploit development (where AI now generates not just proof-of-concepts but production exploits) demand immediate hardening of cloud/telematics architectures and acceleration of OTA patching cadence. The shift from low-impact to high-impact incidents (61% of incidents now affect thousands+ vehicles) raises the stakes for safety validation and incident response governance. Architects should plan for multi-layer defense with real-time anomaly detection rather than relying on CVE-based vulnerability scanning alone.