Desk live·
ForensicPost
Ransomware/Analysis/File 25-1120

Automotive Ransomware More Than Doubled, and the Cars Are Next

Reported ransomware attacks on the automotive industry more than doubled in 2025, with one analysis putting the sector footprint at 44%. The vehicles themselves are now in scope.

Constructed geometry · not a chart of case data
TargetAutomotive sector
ActorMultiple
S. Rosler11 min readConfidence: medium3 sources reviewed

Published analysis reports that ransomware attacks on the automotive industry more than doubled during 2025, with one assessment describing a 44% and expanding sector footprint. The same research notes that vehicles themselves are increasingly treated as targets rather than only the companies that build them.

Three Attack Surfaces, One Industry

The sector presents an unusual combination. There is corporate IT, like any large business. There is operational technology on the assembly line, where an outage stops production, as at 25-0902. And there is the product — a connected vehicle with an update channel, a telematics link and a manufacturer that retains the ability to reach it after sale.

Very few industries carry all three. It is why the automotive files in this database sit across sections that do not normally overlap, from 26-0121 to 26-0318.

The Dealer Network Is The Soft Edge

Between the manufacturer and the customer sits a network of independently owned dealerships holding customer identity data, finance applications and, increasingly, remote access to vehicles for servicing.

They carry the manufacturer’s brand and almost none of its security capability. That structure — brand concentration with security fragmentation — is the one this desk filed at 26-0611 and 26-0715b, and it is where the sector’s customer data actually sits.

On "More Than Doubled"

A doubling of reported attacks in a year in which the sector’s most prominent incident dominated international coverage should be read with the caution filed at 25-0808. Attention drives disclosure, and disclosure drives counts.

The structural argument above does not depend on the percentage being right. The three attack surfaces exist regardless of how many incidents were counted.

This is an analysis file

Built on published sector research, listed below. Counts are of reported incidents and are sensitive to disclosure conditions. Corrections: corrections@forensicpost.com.

Sources
  1. Forty-four percent and rising: ransomware footprint is expanding in the automotive industryHalcyon
  2. Auto industry ransomware attacks more than doubled in 2025WardsAuto
  3. Auto sector faces historic cyber threats to business continuityCybersecurity Dive
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary