Report by PCA Cyber Security

PCA Cyber Security Global Automotive Cybersecurity Report Q1 2026

35 FINDINGSPublished May 1, 2026
View Original Report →

Key Findings

ShinyHunters vishing attack against an online automotive marketplace help desk exfiltrated 12.4 million user records (6.1 GB) in mid-February 2026

Automotive CybersecurityShinyHuntersVishingHelp Desk

Quarkslab bypassed the 16-byte RH850 debug password protection using voltage fault injection

Automotive CybersecurityHardwareFault InjectionRenesas

China's amended Cybersecurity Law took effect on 1 January 2026 (passed 28 October 2025) with raised penalties and extraterritorial reach

Automotive CybersecurityRegulationChina

BEAST threat actor leaked 700 GB of internal data from a large Chinese automotive group in late February 2026

Automotive CybersecurityData BreachChina

3.7 million of the 12.4 million records exposed in the ShinyHunters automotive marketplace breach were previously unseen in other breaches

Automotive CybersecurityShinyHuntersData Breach

DefenseWeaver multi-agent LLM identified 11 critical attack paths across four automotive projects in TARA testing

Automotive CybersecurityAI/LLMTARANDSS 2026

Ethernet represented over 25% of all automotive attack vector entries in Q1 2026

Automotive CybersecurityEthernetAttack Vectors

Incransom ransomware group published a 200 GB leak from a Tier-1 electronics component supplier in January 2026

Automotive CybersecurityIncransomTier-1 Supplier

88% of Q1 2026 automotive vulnerabilities require Low Attack Complexity

Automotive CybersecurityAttack Complexity

Pwn2Own Automotive 2026 in Tokyo produced 76 unique zero-days and $1.047 million in payouts

Automotive CybersecurityPwn2OwnZero-DaysEV Chargers

160 Medium, 75 High, and 16 Critical automotive vulnerabilities identified in Q1 2026

Automotive CybersecurityCVSSSeverity

Synacktiv chained an information leak with an out-of-bounds write to achieve a full win against Tesla infotainment via USB at Pwn2Own Automotive 2026

Automotive CybersecurityTeslaPwn2OwnUSB

An automotive parts marketplace database with over 7.7 million records was exposed via a misconfigured Elasticsearch instance in January 2026

Automotive CybersecurityAftermarketMisconfiguration

US SELF DRIVE Act of 2026 requires the Secretary of Commerce to brief Congress on connected vehicle supply chain security within 180 days

Automotive CybersecurityRegulationSELF DRIVE Act

2024 SafePay ransomware breach at a global BPO provider exposed nearly 17,000 employees and customers of a major commercial vehicle manufacturer, disclosed in January 2026 after a 14-month notification delay

Automotive CybersecurityBPOSafePayHR/Payroll

Kenwood DNR1007XR aftermarket head unit exposes a Linux login prompt over UART at 115200 bps via a hidden board-edge connector

Automotive CybersecurityInfotainmentKenwood

265 unique automotive-specific vulnerabilities identified in Q1 2026

Automotive CybersecurityCVEsQ1 2026

28% increase in automotive vulnerabilities in Q1 2026 compared to Q4 2025

Automotive CybersecurityCVEsQuarter-on-Quarter

In-vehicle and Backend systems accounted for more than 81% of Q1 2026 automotive vulnerability targets

Automotive CybersecurityIn-VehicleBackend

PCA identified 14 unique methods of entry in the Q1 2026 automotive threat landscape

Automotive CybersecurityAttack Vectors

Pwn2Own Automotive 2026 had a record 73 entries

Automotive CybersecurityPwn2Own

Quarkslab's audit of EVerest open-source EV charging stack found 6 high-severity, 6 medium-severity, 5 low-severity and 3 informational issues

Automotive CybersecurityEV ChargingEVerestQuarkslab

Ransomware group exfiltrated nearly 1 TB of data from a major Asian vehicle manufacturer's customer and dealership environment in early January 2026 via a third-party vendor

Automotive CybersecurityRansomwareThird-Party Vendor

Delta Alarm cyberattack disabled mobile-app vehicle controls for hundreds of thousands of Russian vehicle owners for up to two weeks in late January 2026

Automotive CybersecurityTelematicsCloud HijackCyber-Physical

Delta Alarm took approximately five days to restore partial functionality and nearly two weeks to fully recover from the cloud control plane attack

Automotive CybersecurityTelematicsIncident Response

US Commerce Department rule prohibits Chinese and Russian connected-vehicle software starting Model Year 2027

Automotive CybersecurityRegulationUS CommerceConnected Vehicles

US connected vehicle hardware restrictions arrive for Model Year 2030 or January 1, 2029 for non-model-year components

Automotive CybersecurityRegulationHardware

US connected vehicle rule covers vehicles under 10,001 pounds

Automotive CybersecurityRegulationConnected Vehicles

Q1 2026 automotive vulnerabilities map to 25 distinct TTPs in the Auto-ISAC Automotive Threat Matrix

Automotive CybersecurityTTPsAuto-ISAC ATM

77 distinct CWEs mapped in Q1 2026, up from 64 in Q4 2025

Automotive CybersecurityCWEs

102% year-on-year increase in automotive vulnerabilities (Q1 2026 vs Q1 2025)

Automotive CybersecurityCVEsYear-on-Year

Q1 2026 automotive vulnerabilities span 77 unique CWEs

Automotive CybersecurityCWEsQ1 2026

Web and Local Shell combined for 33% of Q1 2026 automotive attack vectors

Automotive CybersecurityWebLocal ShellAttack Vectors

Ultra-Fast Wireless Charging hack drained 76% of EV power on the Alpitronic HYC50 commercial DC fast charger

Automotive CybersecurityEV ChargingAlpitronic

ChargePoint Home Flex flaw (ZDI-26-197) allows unauthenticated network-adjacent remote code execution as root via OCPP message handling

Automotive CybersecurityEV ChargingChargePointRCE