Desk live·
ForensicPost
Ransomware/Analysis/File 26-0121

Attacks on Automotive and Smart Mobility Organisations More Than Doubled in 2025

Attacks on automotive and smart mobility organisations more than doubled in 2025. The sector now carries a factory, a supply chain and a connected fleet, each with its own exposure.

Constructed geometry · not a chart of case data
TargetAutomotive manufacturers
ActorMultiple
S. Rosler10 min readConfidence: medium2 sources reviewed

Reported attacks against automotive and smart mobility organisations more than doubled in 2025. Read alongside the JLR file in 26-0119, the trend has an obvious cause and a less obvious shape.

Three Estates, One Company

A modern vehicle manufacturer runs three quite different technology estates. There is the factory — operational technology, robotics, plant systems. There is the enterprise — planning, engineering, dealer networks and supplier integration. And there is the fleet: hundreds of thousands of connected vehicles receiving software updates over the air.

Each has a different threat model, a different regulatory regime and, in most companies, a different team. Very few organisations of any kind manage three estates of that scale well simultaneously.

The Fleet Is The Novel One

Factory and enterprise exposure is shared with every large manufacturer. What is specific to this sector is a delivery channel that pushes executable code to vehicles in customers’ possession.

That channel exists for good reasons — recalls become updates, defects get fixed without a workshop visit. It also means the update infrastructure is a control system for a large number of moving objects, and its compromise has a consequence category the rest of this database does not contain.

Where The Incidents Actually Are

It is worth being clear that the recorded incidents are overwhelmingly in the first two estates. The events with billion-pound consequences have been enterprise IT outages stopping production, not vehicle compromise.

Attention within the sector has historically run the other way, toward vehicle security research, because it is more interesting and generates better demonstrations. The losses are in the boring estate.

How we reported this

This is an analysis file built on published sector research, listed below. Growth figures are vendor-derived with varying methodologies. Corrections: corrections@forensicpost.com.

Sources
  1. Automotive cyber threats: ransomware trends in 2026Bitsight
  2. AI doubled auto industry cyberattacks: UpstreamWardsAuto
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary