IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Automotive cyber vulnerabilities more than double in Q2

Automotive cyber vulnerabilities more than double in Q2

Tue, 28th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

PCA Cyber Security has published a report showing that high-severity automotive cybersecurity vulnerabilities more than doubled in the second quarter. The analysis covered 345 unique vulnerabilities across the automotive sector.

Of those, 161 were classed as high severity, up from 75 in the first quarter. The report defined high severity as software or hardware flaws that can be exploited to gain control of major vehicle functions, access sensitive personal data, or compromise driver privacy.

The findings point to a broader shift in how security researchers and criminal groups target the sector. Rather than focusing only on individual vehicles, attacks are increasingly aimed at systems with wider reach, including charging networks, mobility platforms, and supply chains.

Entry points

Among 14 hacking entry methods identified during the quarter, Local Shell was the most common, accounting for 28% of vulnerabilities. The technique involves gaining command-line access to a vehicle's onboard computer, often through diagnostic or debug interfaces, to extract data or interfere with systems.

PCA also found that 94% of vulnerabilities identified in the quarter involved low attack complexity. In practice, that means most could be exploited without specialised tools or lengthy preparation.

The combination of rising severity and relative ease of exploitation is likely to heighten concern among carmakers, suppliers, and service providers as vehicles become more connected and software-reliant. The report linked part of that trend to the growing use of artificial intelligence in vulnerability discovery and exploitation.

Wider impact

Several examples in the report show how attacks can extend beyond individual cars. White-hat researchers demonstrated that cloud-based authentication systems used by rentable electric vehicle chargers, shared e-bikes, and e-scooters could be tampered with remotely, raising the possibility of disruption across urban transport infrastructure.

Another case involved a ransomware incident affecting a UK-based automotive data and vehicle valuation provider. Dealers, insurers, and original equipment manufacturers were left without access to important data, causing what the report described as a regional valuation blackout.

Separate research cited in the analysis showed how unencrypted data retrieved from a second-hand car head unit could reveal a previous owner's vehicle history and personal information. The example underlined how risks can persist even after a vehicle component has left its original owner.

Supply chain pressure

Monitoring of cybercriminal forums, dark web marketplaces, and ransomware leak sites showed mounting pressure on automotive supply chains. The report argued that attackers are increasingly targeting suppliers and related businesses as a route into the industry, rather than trying to breach the core networks of major manufacturers directly.

Among the cases highlighted was a claim by the Qilin ransomware group that it had breached a large Japanese automotive components manufacturer through subsidiaries in Europe and North Africa. Another extortion group was said to have listed a Canadian automotive parts retailer and distributor as a victim, alleging it had exfiltrated sensitive data.

The report also referred to an incident in which the World Leaks extortion group published more than 630 GB of data, or more than 200,000 files, stolen from a major Indian electronics contract manufacturer. The files were said to include confidential engineering documents belonging to one of the world's largest electric vehicle manufacturers.

The pattern matters because supply chain attacks can expose product data, engineering designs, and operational systems across several organisations at once. In an industry built on long supplier relationships and shared software components, a breach at one company can have consequences far beyond the original target.

Automotive cybersecurity has become more prominent as manufacturers roll out software-defined vehicles and connected services that depend on external platforms. These systems create more opportunities for remote access, over-the-air updates, and integration with charging, fleet management, and mobility networks, but they also expand the number of points where flaws can emerge.

PCA said the jump in volume and severity means companies need to do more than track common vulnerabilities and exposures. The sector should focus on verifying whether patches are actually present across full software bills of materials, a task made harder as software stacks spread across vehicles, components, and back-end systems.

Vlad Ryabyshkin, Chief Technology Officer at PCA Cyber Security, said: "The increased automation of cyber security vulnerability discovery and exploitation is well-documented. The outcome of that trend is more interesting, and Q2 vulnerabilities give clear clues as to how those outcomes are playing out for the automotive industry. Hackers and ethical researchers are prioritising vulnerabilities with higher risk profiles and maximum blast radius potential. Rampant targeting of OEMs via supply chains risks fuelling the automotive threat landscape further. Manual defences are no longer sufficient - the industry needs active resilience with focus on software composition analysis (SCA) if it's to secure the era of software-defined vehicles."