Automotive Security Leaders Must Take Immediate Action to Mitigate the Surging Cyber Threats – Upstream Report Reveals Critical Gaps

Upstream’s 2025 Automotive & Smart Mobility Cybersecurity Report reveals that 60% of cyber incidents could affect thousands to millions of connected vehicles, with massive-scale attacks more than tripling; the report emphasizes that current regulatory requirements are insufficient to address expanding cyber risks.

Ann Arbor, MI (February 11, 2025)- Upstream Security, the leading provider of cloud-based cybersecurity and data management platform purpose-built for automotive, smart mobility, and IoT ecosystem, today released the 2025 Automotive & Smart Mobility Cybersecurity Report. The annual report, returning for its seventh year, highlights that despite the increased regulatory attention, the number, scale, and severity of cyber attacks continues to grow, showing a false sense of security and resilience. Automakers and mobility stakeholders have to go beyond regulations to address the threats causing serious implications for safety, operational availability and data privacy.

The report revealed that in 2024, 60% of cybersecurity incidents in the automotive and smart mobility sectors affected thousands to millions of mobility assets, including vehicles, EV charging stations, smart mobility apps, and connected devices. Notably, massive-scale incidents—each impacting millions of vehicles—more than tripled, rising from 5% in 2023 to 19% in 2024. This sharp increase highlights the urgent need for organizations to prioritize resilience by extending their cybersecurity efforts beyond regulatory compliance.

The rise of software-defined and autonomous vehicles has introduced new vulnerabilities, leading to a widening cybersecurity gap. Additionally, critical infrastructure in smart mobility devices, like EV chargers and fleet management systems, has expanded the attack surface and magnified the stakes. Mobility-specific ransomware attacks surged in 2024 causing unprecedented disruptions with 108 reported ransom attacks and 214 data breaches. One of the most impactful incidents was a ransomware attack in June on a leading US-based software provider used by 15,000 automotive dealerships which resulted in halted operations for nearly three weeks, estimating losses at $1.02 billion. 

“The cybersecurity landscape across the Automotive and Smart Mobility ecosystem is poised to become more complex than ever,” said Yoav Levy, CEO and co-founder of Upstream. “Cyber threats are evolving faster than the industry is prepared to handle, outpacing regulation-driven measures. Threat actors have already shifted toward large-scale, sophisticated and AI-powered attack methods, targeting not only vehicles but also interconnected systems such as EV charging infrastructure, API-driven apps, and smart mobility IoT devices. This growing attack surface demands a transformative and proactive approach to cybersecurity”.

Cyberattacks in 2024 became more sophisticated and frequent, targeting vehicles and backend systems, as well as smart mobility platforms, devices, and applications. 65% of publicly reported cyber incidents were carried out by black hat actors with malicious intent.  92% of attacks were executed remotely, supporting the surge in scale and impact, of which 85% were long-range and did not require any physical proximity to the targeted asset. The ecosystem experienced a significant surge in telematics and application server attacks in 2024— 43% of incidents in 2023 rising to 66% in 2024. 

In addition to monitoring publicly reported cyber incidents, Upstream’s AutoThreat® team monitors the deep and dark web for threat actors targeting connected vehicles, mobility applications and devices. When zooming in on deep and dark web activities carried out by black hat hackers, 70% activities had the potential to impact thousands to millions of mobility assets and over 76% targeted multiple stakeholders and had a global reach. 

Additional key findings in the report include:

  • 2024 saw 409 new incidents (up from 295 in 2023), contributing to a total of 1,877 documented cases since 2010
  • The dramatic rise in incidents is largely attributed to a sharp escalation in ransomware attacks targeting the mobility sector
  • Data and privacy-related incidents accounted for 60% of 2024 incidents, up 20% from 2023.
  • The percentage of incidents involving car system manipulation and control of vehicle systems increased dramatically in 2024, accounting for over 35% of incidents.

The report further delves into a range of topics including China’s strategic automotive investments and impact on the cyber landscape, EV charging infrastructure risks, 2024’s attack vectors and today’s regulatory reality. Download the full 2025 Upstream Global Automotive & Smart Mobility Cybersecurity Report here.

About Upstream Security

Upstream delivers a cloud-based, AI-powered data management platform purpose-built for connected vehicles, smart mobility, and IoT ecosystem. The Upstream Platform transforms fragmented, distributed mobility data into centralized, structured, and contextualized data lakes, unlocking its full potential. By leveraging this data, Upstream empowers customers with advanced, AI-driven applications across various use cases, including proactive vehicle quality management, cybersecurity detection and response (XDR), fraud prevention, observability, usage-based insurance, and more.

About Upstream Security

Mushkie Meyer
[email protected]
US: +1 914 336 4035
UK: +44 203 769 4034

Newsletter Icon

Subscribe
to our newsletter

Stay up-to-date on the latest trends, emerging risks, and updates

Upstream Wins Prestigious Merit Awards for Automotive Cybersecurity Innovation and Company Excellence

The company is recognized for its AI-driven innovation and unwavering commitment towards transforming automotive cybersecurity Ann Arbor, MI (December 17, 2024) – Upstream Security, the…

More Details

Upstream Unveils AI-Powered Proactive Vehicle Quality Detection Solution Cutting Warranty and Recall Costs

Upstream expands its AI-powered cybersecurity and data management platform with a new solution that enables early detection of vehicle quality issues and accelerates field investigations…

More Details

Upstream Security Achieves AWS Automotive Competency

The AWS Automotive Competency reinforces Upstream’s leadership in AI-powered solutions for connected vehicles and Smart Mobility Ann Arbor, MI — November 19, 2024 — Upstream…

More Details

Upstream Harnesses the Power and Global Scale of Google Cloud to Boost Cybersecurity for Connected Vehicles

Upstream’s Cybersecurity Detection & Response (XDR) for Connected Vehicles and IoT is Now Available on Google Cloud Marketplace and Integrates with Google Security Operations Ann…

More Details

Upstream Security and OTORIO Announce Partnership to Strengthen Cybersecurity Posture Across the Entire Connected Vehicle Lifecycle

Deployed jointly at multiple OEMs, OTORIO and Upstream are helping automotive manufacturers to secure their OT environment, connected vehicles, operational efficiency, and sensitive data, as…

More Details

Upstream Security and Volta Team Up to Safeguard the Future of Electric Fleets

Upstream will monitor and secure ‘Volta Zero’ electric truck during the London to Geneva EV Rally 2024 Ann Arbor, MI, London, UK (June 19, 2024)…

More Details
Skip to content