38 Statistics on Automotive Cybersecurity Breaches. A Q2 2026 Update
Automotive security flaws continued to go up in Q2 2026.
Worse, more of them were critical, and both adversaries and researchers increasingly targeted the systems that manage large numbers of vehicles instead of individual cars.
Below is a full breakdown of the quarter's numbers: the vulnerability landscape, EV charging and telematics research, underground activity and leaks, and the regulatory deadlines that took effect.
All figures come from PCA Cyber Security's Q2 2026 Global Automotive Cybersecurity Report. PCA Cyber Security is the leading automotive threat intelligence provider.
Note: Subscribe to our free cybersecurity newsletter for a weekly feed of live cybersecurity statistics.
Automotive Vulnerabilities Q2 2026
More automotive security vulnerabilities were found this quarter, with a larger share of them being serious or critical.
- 345 unique automotive-specific vulnerabilities were discovered in Q2 2026 (PCA Cyber Security, Q2 2026).
- Q2 2026 vulnerabilities rose 30% vs. 265 identified in Q1 2026 (PCA Cyber Security, Q2 2026).
- Q2 2026 vulnerability volume rose 220% year on year, up from 157 in Q2 2025 (PCA Cyber Security, Q2 2026).
- High severity findings more than doubled in Q2 2026, from 75 in Q1 to 161 (PCA Cyber Security, Q2 2026).
- Q2 2026 severity broke down as 165 Medium, 161 High, and 14 Critical vulnerabilities, with only 5 classed as Low (PCA Cyber Security, Q2 2026).
- Q2 2026 vulnerabilities span 100 unique Common Weakness Enumerations, up from 77 in Q1 2026 (PCA Cyber Security, Q2 2026).
- Improper Input Validation (CWE-20) was the most frequent weakness in Q2 2026, followed by Use After Free (CWE-416) and NULL Pointer Dereference (CWE-476) (PCA Cyber Security, Q2 2026).
- 94% of Q2 2026 vulnerabilities require only Low Attack Complexity, up from 88% in Q1 2026 (PCA Cyber Security, Q2 2026).
- Local Shell overtook Ethernet as the leading automotive attack vector in Q2 2026, representing over 28% of entries (PCA Cyber Security, Q2 2026).
- Web and Local Shell combined for 45% of Q2 2026 automotive attack vectors (PCA Cyber Security, Q2 2026).
- In-vehicle and Backend systems jointly accounted for over 96% of Q2 2026 vulnerability targets (PCA Cyber Security, Q2 2026).
- Q2 2026 vulnerabilities mapped to 15 distinct TTPs in the Auto-ISAC Automotive Threat Matrix (PCA Cyber Security, Q2 2026).
- Exploit OS Vulnerability (ATM-T0026) remained the most-mapped technique in Q2 2026, tied to memory safety bugs in kernel drivers and system components (PCA Cyber Security, Q2 2026).
- Exploit via Radio Interface (ATM-T0012) was driven by flaws in Bluetooth and Wi-Fi stacks that let an attacker seize an ECU within radio range (PCA Cyber Security, Q2 2026).
- Command and Scripting Interpreter (ATM-T0018) covered injection into exposed web and management interfaces on dealer, telematics, and EV charging platforms (PCA Cyber Security, Q2 2026).
EV Charging and Fleet Research
In Q2 2026, researchers moved from looking at mostly individual EV chargers towards systems that control thousands of chargers at once.
- Research presented at Black Hat Asia 2026 showed weak device identifier schemes and unauthenticated cloud backends could let an attacker disable public EV chargers at fleet scale (PCA Cyber Security, Q2 2026).
- A live demonstration switched a public EV charger in Shanghai from available to disabled within seconds through the vendor's own iOS app (PCA Cyber Security, Q2 2026).
- Rentable EV chargers and shared e-bikes and e-scooters exposed UART and debug ports that let an attacker extract shared authentication keys from firmware (PCA Cyber Security, Q2 2026).
In-Vehicle Systems Research
In Q2 2026, researchers kept breaking into infotainment units, telematics boxes, and diagnostic tools. Some were able to take over a device outright while others accessed a vehicle's full history or manipulated diagnostic information.
- A salvaged BYD Seal telematics control unit still held unencrypted GNSS logs, letting researchers reconstruct the vehicle's whole history down to a crash confirmed through a public Facebook post (PCA Cyber Security, Q2 2026).
- The same BYD Seal teardown recovered hardcoded Wi-Fi credentials, a passwordless guest account, and enabled ADB, TCP, and Telnet (PCA Cyber Security, Q2 2026).
- Honda's USB firmware update path on a 2021 Civic head unit accepted images signed with the public AOSP test key, letting an attacker run arbitrary code through brief physical USB access (PCA Cyber Security, Q2 2026).
- The BYD Dolphin DiLink 3 head unit exposed CAN bus read and write access, a permission bypass, an unlocked bootloader, and a root CarPlay service listening on every network interface (PCA Cyber Security, Q2 2026).
- The BYD Dolphin research also documented over 200 CAN signal identifiers and a broken COTA over-the-air authentication scheme (PCA Cyber Security, Q2 2026).
- Researchers derived eight attack scenarios against the ISO 15765-2 CAN transport layer beneath UDS diagnostics, three of which succeeded on a 2021 Hyundai Elantra (PCA Cyber Security, Q2 2026).
- The successful ISO 15765-2 attacks stalled a diagnostic session, hid stored fault codes, or returned altered sensor readings to the scan tool (PCA Cyber Security, Q2 2026).
Underground Activity and Leaks
In Q2 2026, cybercriminals were more interested in automotive suppliers and subsidiaries than in major car manufacturers. The biggest losses involved valuable company information (e.g., designs and tech) rather than customers' personal data.
- Qilin ransomware listed a major Japanese Tier-1 automotive components manufacturer, with the compromise centered on European and North African subsidiaries (PCA Cyber Security, Q2 2026).
- The World Leaks extortion group published over 630 GB of data, more than 200,000 files, stolen from an Indian electronics contract manufacturer (PCA Cyber Security, Q2 2026).
- The World Leaks dump included confidential engineering data belonging to a leading US electric vehicle maker, including files referencing a charge port controller (PCA Cyber Security, Q2 2026).
- A UK automotive data and vehicle valuation provider suffered a ransomware attack that took customer-facing applications offline across Europe and Australia for weeks (PCA Cyber Security, Q2 2026).
- A threat actor shared a driver database from a Venezuelan ride-hailing app containing 11,929 driver records at 4 GB compressed, including home addresses and license plates (PCA Cyber Security, Q2 2026).
- An Australian automotive parts and battery importer had data exposed through a compromised network-attached storage device (PCA Cyber Security, Q2 2026).
- New extortion brands Netrunner and Lamashtu both listed automotive supply chain victims in Q2 2026 without offering sample data, a pattern typical of newer crews still building credibility (PCA Cyber Security, Q2 2026).
Automotive Cybersecurity Regulation
In Q2 2026, several automotive cybersecurity regulations came into effect.
- UN R155 and R156 became mandatory for new GB vehicle types from 1 June 2026 (PCA Cyber Security, Q2 2026).
- ISO/DTS 5112, the CSMS audit guidance tied to ISO/SAE 21434, reached the formal approval stage on 28 April 2026 (PCA Cyber Security, Q2 2026).
- The EU Cyber Resilience Act's vulnerability and incident reporting obligations begin 11 September 2026 (PCA Cyber Security, Q2 2026).
- India proposed AIS-189 and AIS-190 rules covering vehicle cybersecurity and software updates in late June 2026 (PCA Cyber Security, Q2 2026).
- CISA and federal partners urged hardening of internet-exposed automatic tank gauge systems on 2 June 2026, following observed compromise activity (PCA Cyber Security, Q2 2026).
- The EU unveiled a tech sovereignty package on 3 June 2026, spanning a Chips Act 2.0, a Cloud and AI Development Act, and an Open Source Strategy (PCA Cyber Security, Q2 2026).