Published analysis reports that ransomware attacks on the automotive industry more than doubled during 2025, with one assessment describing a 44% and expanding sector footprint. The same research notes that vehicles themselves are increasingly treated as targets rather than only the companies that build them.
Three Attack Surfaces, One Industry
The sector presents an unusual combination. There is corporate IT, like any large business. There is operational technology on the assembly line, where an outage stops production, as at 25-0902. And there is the product — a connected vehicle with an update channel, a telematics link and a manufacturer that retains the ability to reach it after sale.
Very few industries carry all three. It is why the automotive files in this database sit across sections that do not normally overlap, from 26-0121 to 26-0318.
The Dealer Network Is The Soft Edge
Between the manufacturer and the customer sits a network of independently owned dealerships holding customer identity data, finance applications and, increasingly, remote access to vehicles for servicing.
They carry the manufacturer’s brand and almost none of its security capability. That structure — brand concentration with security fragmentation — is the one this desk filed at 26-0611 and 26-0715b, and it is where the sector’s customer data actually sits.
On "More Than Doubled"
A doubling of reported attacks in a year in which the sector’s most prominent incident dominated international coverage should be read with the caution filed at 25-0808. Attention drives disclosure, and disclosure drives counts.
The structural argument above does not depend on the percentage being right. The three attack surfaces exist regardless of how many incidents were counted.
Built on published sector research, listed below. Counts are of reported incidents and are sensitive to disclosure conditions. Corrections: corrections@forensicpost.com.