Report by PCA Cyber Security
PCA Cyber Security Global Automotive Cybersecurity Report Q4 2025
Key Findings
Q4 2025 automotive vulnerabilities mapped to 19 distinct TTPs in the Auto-ISAC Automotive Threat Matrix
Q4 2025 severity breakdown: 146 Medium, 54 High and 2 Critical automotive vulnerabilities
Local Shell was the most frequent attack vector in Q4 2025, representing over 62% of total automotive entries
In-vehicle and Virtualization target types accounted for 95%+ of Q4 2025 automotive vulnerabilities
14 different attack methods observed in Q4 2025 automotive vulnerabilities
DrainDead portable EV battery siphoning rig was built for approximately €1,200 using a solar inverter and CCS adapter
Ultra-Fast Wireless Charging attack synchronises with the charger's signal within only three cycles, defeating frequency hopping countermeasures
Most EVs in DrainDead testing allowed indefinite battery siphoning with repeated session resets; only some (e.g. Volkswagen group) halted discharging after around 60 seconds
Ethernet and Wi-Fi combined accounted for more than 18% of Q4 2025 automotive attack vectors
Q4 2025 automotive vulnerabilities span 64 unique CWEs
Ultra-Fast Wireless Charging hack drew 76%+ of the power intended for a legitimate EV from inductive chargers
206 unique automotive vulnerabilities identified in Q4 2025, a 19% increase over Q3 2025
64 distinct CWEs mapped in Q4 2025, down from 82 in Q3 2025
Over 100 advertised leaks and ransomware breaches targeted the automotive supply chain on the dark web in Q4 2025
UK SI 2025/1110 mandates UN R155 and R156 for type-approval effective 13 November 2025
EU Delegated Regulation 2025/1455 extends UN R155 to L-category vehicles: new types compliant by 11 December 2027, existing types by 11 June 2029
ControlLoc adversarial attack on AV object trackers achieved up to 98.5% success digitally and over 79% in physical tests against the Baidu Apollo stack
US Tier-1 automotive supplier had approximately 1.9 TB of internal files publicly posted on an extortion site at the end of October 2025
Japanese vehicle manufacturer third-party cloud compromise exposed around 21,000 customer records in December 2025
German aftermarket parts and distribution business had 1.4 TB of internal data advertised on underground forums in December 2025
Around 60% of automotive vendors had already adopted IDS at time of Automotive Cyber Security Connectivity and SDV Week 2025 survey
Japanese vehicle manufacturer's customer management environment breach exfiltrated roughly 900 GB in December 2025