PCA Cyber Security
Reports
All Statistics
ShinyHunters vishing attack against an online automotive marketplace help desk exfiltrated 12.4 million user records (6.1 GB) in mid-February 2026
Quarkslab bypassed the 16-byte RH850 debug password protection using voltage fault injection
China's amended Cybersecurity Law took effect on 1 January 2026 (passed 28 October 2025) with raised penalties and extraterritorial reach
BEAST threat actor leaked 700 GB of internal data from a large Chinese automotive group in late February 2026
3.7 million of the 12.4 million records exposed in the ShinyHunters automotive marketplace breach were previously unseen in other breaches
DefenseWeaver multi-agent LLM identified 11 critical attack paths across four automotive projects in TARA testing
Ethernet represented over 25% of all automotive attack vector entries in Q1 2026
Incransom ransomware group published a 200 GB leak from a Tier-1 electronics component supplier in January 2026
88% of Q1 2026 automotive vulnerabilities require Low Attack Complexity
Pwn2Own Automotive 2026 in Tokyo produced 76 unique zero-days and $1.047 million in payouts
160 Medium, 75 High, and 16 Critical automotive vulnerabilities identified in Q1 2026
Synacktiv chained an information leak with an out-of-bounds write to achieve a full win against Tesla infotainment via USB at Pwn2Own Automotive 2026
An automotive parts marketplace database with over 7.7 million records was exposed via a misconfigured Elasticsearch instance in January 2026
US SELF DRIVE Act of 2026 requires the Secretary of Commerce to brief Congress on connected vehicle supply chain security within 180 days
2024 SafePay ransomware breach at a global BPO provider exposed nearly 17,000 employees and customers of a major commercial vehicle manufacturer, disclosed in January 2026 after a 14-month notification delay
Kenwood DNR1007XR aftermarket head unit exposes a Linux login prompt over UART at 115200 bps via a hidden board-edge connector
265 unique automotive-specific vulnerabilities identified in Q1 2026
28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025
In-vehicle and Backend systems accounted for more than 81% of Q1 2026 automotive vulnerability targets
PCA identified 14 unique methods of entry in the Q1 2026 automotive threat landscape
Pwn2Own Automotive 2026 had a record 73 entries
Quarkslab's audit of EVerest open-source EV charging stack found 6 high-severity, 6 medium-severity, 5 low-severity and 3 informational issues
Ransomware group exfiltrated nearly 1 TB of data from a major Asian vehicle manufacturer's customer and dealership environment in early January 2026 via a third-party vendor
Delta Alarm cyberattack disabled mobile-app vehicle controls for hundreds of thousands of Russian vehicle owners for up to two weeks in late January 2026
Delta Alarm took approximately five days to restore partial functionality and nearly two weeks to fully recover from the cloud control plane attack
US Commerce Department rule prohibits Chinese and Russian connected-vehicle software starting Model Year 2027
US connected vehicle hardware restrictions arrive for Model Year 2030 or January 1, 2029 for non-model-year components
US connected vehicle rule covers vehicles under 10,001 pounds
Q1 2026 automotive vulnerabilities map to 25 distinct TTPs in the Auto-ISAC Automotive Threat Matrix
77 distinct CWEs mapped in Q1 2026, up from 64 in Q4 2025
102% year-on-year increase in automotive vulnerabilities (Q1 2026 vs Q1 2025)
Q1 2026 automotive vulnerabilities span 77 unique CWEs
Web and Local Shell combined for 33% of Q1 2026 automotive attack vectors
Ultra-Fast Wireless Charging hack drained 76% of EV power on the Alpitronic HYC50 commercial DC fast charger
ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling
Q4 2025 automotive vulnerabilities mapped to 19 distinct TTPs in the Auto-ISAC Automotive Threat Matrix
Q4 2025 severity breakdown: 146 Medium, 54 High and 2 Critical automotive vulnerabilities
Local Shell was the most frequent attack vector in Q4 2025, representing over 62% of total automotive entries
In-vehicle and Virtualization target types accounted for 95%+ of Q4 2025 automotive vulnerabilities
14 different attack methods observed in Q4 2025 automotive vulnerabilities
DrainDead portable EV battery siphoning rig was built for approximately €1,200 using a solar inverter and CCS adapter
Ultra-Fast Wireless Charging attack synchronises with the charger's signal within only three cycles, defeating frequency hopping countermeasures
Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds
Ethernet and Wi-Fi combined accounted for more than 18% of Q4 2025 automotive attack vectors
Q4 2025 automotive vulnerabilities span 64 unique CWEs
Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers
206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025
64 distinct CWEs mapped in Q4 2025, down from 82 in Q3 2025
Over 100 advertised leaks and ransomware breaches targeted the automotive supply chain on the dark web in Q4 2025
UK SI 2025/1110 mandates UN R155 and R156 for type-approval effective 13 November 2025