The rise of connected and software-defined vehicles is giving automakers more features to manage, but it is also creating a much larger cybersecurity challenge.
According to Upstream Security’s analysis of 494 automotive cyber incidents worldwide, 92% of publicly reported attacks in 2025 were carried out remotely, while 67% involved telematics or cloud systems. About 61% of incidents had the potential to affect thousands or even millions of mobility assets.
The figures highlight why cybersecurity testing can no longer focus only on a vehicle’s electronic control units (ECUs) or in-car networks.
The Attack Surface Is Expanding
Modern vehicles are increasingly connected to mobile applications, APIs, telematics platforms, cloud infrastructure and external software services.
Upstream found that 86% of the remote attacks recorded in 2025 did not require physical access to the targeted vehicle or system.
This means a weakness in a cloud service or API could potentially become an entry point into a much wider automotive ecosystem.
Software-defined vehicles add another layer to the challenge. Over-the-air (OTA) updates allow manufacturers to introduce new features and security fixes remotely, but they also create connections between vehicles, cloud systems, update servers and software delivery pipelines.
A weakness anywhere along that chain could create cybersecurity risks.
Suppliers Add Another Layer Of Risk
Automakers also depend on a growing network of suppliers and third-party technologies, including operating systems, communication libraries, open-source software and cloud services.
Software Bills of Materials (SBOMs) can help manufacturers understand which components are being used and identify affected systems when new vulnerabilities emerge.
However, secure individual components do not necessarily guarantee a secure overall system. Vulnerabilities can emerge when different technologies interact.
Apriorit CEO Klaudia Zaika said automotive cybersecurity testing needs to consider the wider ecosystem surrounding the vehicle, including cloud services, APIs and third-party components.
AI Brings New Challenges
Artificial intelligence is adding another dimension to automotive cybersecurity.
AI-powered driver assistance and autonomous systems rely on data from cameras, radar, lidar and other sensors. Manipulating that information could affect how a vehicle interprets its surroundings.
Other potential risks include compromised AI models, poisoned training data and attacks on systems used to update AI technology.
AI-powered infotainment and in-vehicle assistants could also introduce new security concerns if they are connected to vehicle data, navigation, user accounts or external services.
Testing Must Become Continuous
With vehicles receiving regular software updates and relying on increasingly complex digital ecosystems, cybersecurity testing is becoming an ongoing process rather than a once-off exercise.
Standards including ISO/SAE 21434 and UNECE R155 provide frameworks for managing automotive cybersecurity risks. However, manufacturers also need to continually monitor software dependencies, third-party components and new attack paths as vehicle technology evolves.
Main Image: ET Auto










