Report by PCA Cyber Security

PCA Cyber Security Global Automotive Cybersecurity Report Q4 2025

22 FINDINGSPublished Jan 1, 2026
View Original Report →

Key Findings

Q4 2025 automotive vulnerabilities mapped to 19 distinct TTPs in the Auto-ISAC Automotive Threat Matrix

Automotive CybersecurityTTPsAuto-ISAC ATM

Q4 2025 severity breakdown: 146 Medium, 54 High and 2 Critical automotive vulnerabilities

Automotive CybersecurityCVSSSeverity

Local Shell was the most frequent attack vector in Q4 2025, representing over 62% of total automotive entries

Automotive CybersecurityLocal ShellAttack Vectors

In-vehicle and Virtualization target types accounted for 95%+ of Q4 2025 automotive vulnerabilities

Automotive CybersecurityIn-VehicleVirtualization

14 different attack methods observed in Q4 2025 automotive vulnerabilities

Automotive CybersecurityAttack Vectors

DrainDead portable EV battery siphoning rig was built for approximately €1,200 using a solar inverter and CCS adapter

Automotive CybersecurityEV ChargingDrainDead

Ultra-Fast Wireless Charging attack synchronises with the charger's signal within only three cycles, defeating frequency hopping countermeasures

Automotive CybersecurityEV ChargingWireless

Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds

Automotive CybersecurityEV ChargingDrainDead

Ethernet and Wi-Fi combined accounted for more than 18% of Q4 2025 automotive attack vectors

Automotive CybersecurityEthernetWi-FiAttack Vectors

Q4 2025 automotive vulnerabilities span 64 unique CWEs

Automotive CybersecurityCWEsQ4 2025

Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers

Automotive CybersecurityEV ChargingWireless

206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025

Automotive CybersecurityCVEsQ4 2025

64 distinct CWEs mapped in Q4 2025, down from 82 in Q3 2025

Automotive CybersecurityCWEs

Over 100 advertised leaks and ransomware breaches targeted the automotive supply chain on the dark web in Q4 2025

Automotive CybersecurityDark WebRansomwareSupply Chain

UK SI 2025/1110 mandates UN R155 and R156 for type-approval effective 13 November 2025

Automotive CybersecurityRegulationUNECE R155UK

EU Delegated Regulation 2025/1455 extends UN R155 to L-category vehicles: new types compliant by 11 December 2027, existing types by 11 June 2029

Automotive CybersecurityRegulationEUL-Category

ControlLoc adversarial attack on AV object trackers achieved up to 98.5% success digitally and over 79% in physical tests against the Baidu Apollo stack

Automotive CybersecurityAutonomous VehiclesAdversarial AI

US Tier-1 automotive supplier had approximately 1.9 TB of internal files publicly posted on an extortion site at the end of October 2025

Automotive CybersecurityTier-1 SupplierExtortion

Japanese vehicle manufacturer third-party cloud compromise exposed around 21,000 customer records in December 2025

Automotive CybersecurityThird-Party CloudCRMJapan

German aftermarket parts and distribution business had 1.4 TB of internal data advertised on underground forums in December 2025

Automotive CybersecurityAftermarketGermanyExtortion

Around 60% of automotive vendors had already adopted IDS at time of Automotive Cyber Security Connectivity and SDV Week 2025 survey

Automotive CybersecurityIDSAdoption

Japanese vehicle manufacturer's customer management environment breach exfiltrated roughly 900 GB in December 2025

Automotive CybersecurityCRM BreachJapan