Cyber Threats Against the Automotive Industry

31222101492?profile=RESIZE_400xCyfirma's latest Automotive Industry Report for the second quarter of 2026 rates the sector’s overall cyber risk at 5.0 out of 10, classified as elevated.  Drawing on 90 days of telemetry across five threat categories, the analysis reveals a mixed picture of steady ransomware pressure, third-party-driven incidents, and a distinctive pattern of financially motivated activity.  Ransomware activity produced 47 victims across 20 countries, remaining effectively flat quarter by quarter with the sector’s share of total victims holding at 2.08%.  Monthly figures followed a W-shaped pattern, bottoming in May before recovering to near-peak levels through June and July.[1] 

Tier 1 automotive suppliers absorbed the largest number of victims by a clear margin, more than three times any other subsector. This concentration carries wider consequences because disruption of a single Tier 1 supplier can affect multiple original equipment manufacturer production lines. 

Geographic patterns shifted towards emerging manufacturing markets.  India, Turkey and Mexico recorded the largest increases, while Germany and France saw declines. Among the ransomware groups involved, Termite targeted automotive organizations in a quarter of its attacks, the highest proportional focus observed. Overall gang participation stood at 26 percent, the lowest rate recorded across sectors in the period.

Nine advanced persistent threat (APT) campaigns touched automotive organizations across 20 countries. The actor profile differed from most other industries, with financially motivated groups leading activity ahead of state-sponsored actors. TA505 recorded the highest campaign count, followed by FIN11 and FIN7.

Database management software appeared in five instances, the highest rate of any sector, pointing to interest in design and supply-chain data. 

Reported cyber incidents numbered six. Five of the six cases originated outside the manufacturer’s own perimeter, reaching the organization through enterprise software-as-a-service platforms, dealer systems or connected vehicle data.

One notable adjacent finding involved the Cl0p group stealing information from PTC Windchill and FlexPLM, product lifecycle platforms widely used across the automotive supply chain that store designs, bills of materials, and supplier lists.

Dark web chatter registered the lowest volume of any sector examined, with 115 mentions. Discussion of data breaches rose steadily, while claimed hacks and web exploits fell to zero by the final period. 

Vulnerabilities linked to the industry totaled 22 mentions, again ranking last among the 14 sectors tracked. Injection attacks increased in the final period, relevant to connected vehicle interfaces and dealer endpoints. Component risk scores were APT campaigns 5.4, cyber incidents 6.2, dark web chatter 4.5, vulnerabilities 4.0 and ransomware 4.7.

The report indicates that data loss through third parties and engineering-platform exposure now represent the primary concerns for automotive organizations.  While the sector is not the most heavily targeted overall, the leverage available through Tier 1 suppliers and shared product lifecycle systems means individual compromises can carry outsized operational impact. Continued monitoring of supply-chain platforms and third-party connections remains essential.

Interested in securing your own supply chain against cyber threats?  Please see our solution at https://www.redskyalliance.com/supply-chain  

 

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/automotive-industry-under-elevated-cyber-threat-9608.html

You need to be a member of Red Sky Alliance to add comments!