
Automotive cybersecurity has become a core part of vehicle safety, software development, and connected mobility as cars evolve into increasingly software-defined platforms. Modern vehicles communicate with cloud services, mobile applications, telematics platforms, charging networks, dealerships, and external infrastructure, creating valuable digital capabilities while expanding the number of potential attack surfaces. Cybersecurity is therefore no longer limited to protecting individual electronic control units inside a vehicle.
In practical terms, automotive cybersecurity protects over-the-air software updates, connected fleet operations, infotainment systems, advanced driver-assistance systems, keyless entry, vehicle APIs, and EV charging infrastructure. These protections matter because a vulnerability in a centralized platform can potentially affect thousands or even millions of connected assets rather than a single vehicle. With automotive cybersecurity spending, regulatory requirements, and reported cyber incidents continuing to increase, the period provides an important view of how quickly the industry’s risk environment is changing. The following statistics examine market growth, connected-car security, attack trends, ransomware, data breaches, regulations, and cybersecurity investment.
Editor’s Choice
- Global automotive cybersecurity revenue is projected to increase from $7.7 billion in 2025 to $8.8 billion in 2026.
- The market could reach $24.8 billion by 2033, representing a 15.9% CAGR over the 2026-2033 forecast period.
- Researchers tracked 494 automotive and smart mobility cybersecurity incidents in 2025, or about 41 incidents per month.
- The number of tracked automotive cybersecurity incidents increased 21% from 2024 to 2025.
- Ransomware represented 44% of publicly reported automotive and smart mobility incidents in 2025, up sharply from roughly 26% in 2024.
- Data and privacy-related incidents accounted for 68% of incidents in 2025, compared with 60% in 2024.
- The U.S. connected car security market is forecast to expand from $808.4 million in 2025 to $1.41 billion in 2032, with an 8.3% CAGR.
- Asia-Pacific generated 35.8% of global automotive cybersecurity revenue in 2025, ahead of other regions in the cited market assessment.
- China is projected to record a 15.7% CAGR in automotive cybersecurity spending from 2025 to 2035, while the corresponding U.S. growth rate is projected at 9.9%.
- V2X cybersecurity is forecast to expand at a 12.3% CAGR between 2025 and 2035, taking the segment from $1.5 billion to $4.8 billion.
Recent Developments
- Researchers documented 494 automotive and smart mobility cybersecurity incidents during 2025, up from 409 incidents during 2024.
- That increase equates to approximately 21% year-over-year growth in publicly analyzed automotive cybersecurity incidents.
- The average monthly number of reported incidents increased from around 34 in 2024 to 41 in 2025.
- Ransomware became substantially more prominent in 2025, accounting for 44% of publicly reported incidents, compared with about 26% in the previous year.
- More than 71% of attacks in 2025 were attributed to black-hat threat actors, showing that financially or maliciously motivated attacks continued to dominate the threat landscape.
- Data and privacy incidents increased their share of tracked attacks from 60% in 2024 to 68% in 2025.
- During 2024, about 92% of automotive cyberattacks were remote, reinforcing the importance of securing backend systems, connected services and wireless interfaces.
- Attacks involving telematics and application servers represented 66% of tracked incidents in 2024, up from 43% in 2023.
- API-related incidents accounted for about 17% of automotive attacks in 2024, placing backend connectivity among the industry’s most important emerging attack surfaces.
- Regulatory coverage also expanded. South Korea scheduled mandatory cybersecurity requirements for new vehicle types from Aug. 14, 2025, while India’s AIS-189 roadmap set an implementation date of Oct. 1, 2025 for new vehicle types.
Automotive Cybersecurity Market Growth
- The global automotive cybersecurity market is projected to grow from $3.24 billion in 2025 to $7.94 billion by 2030, reflecting rapidly rising demand for vehicle security solutions.
- In 2026, the market is expected to reach $3.89 billion, up approximately 20% from its 2025 level.
- The market is projected to expand at a strong 19.5% CAGR from 2026 to 2030, indicating sustained double-digit growth throughout the forecast period.
- By 2028, the automotive cybersecurity market is estimated to surpass $5.5 billion, as connected and software-defined vehicles increase cybersecurity requirements.
- Between 2025 and 2030, the market is expected to grow by roughly $4.70 billion, reaching nearly 2.5 times its 2025 size.

Automotive Cybersecurity Market Forecast 2026–2035
- Global automotive cybersecurity revenue is estimated at $8.8 billion in 2026 under one broad market forecast.
- The same forecast projects revenue of $24.8 billion by 2033, supported by an expected 15.9% CAGR.
- Another forecast places the automotive cybersecurity market at $4.4 billion in 2026 under a narrower market definition.
- That forecast projects a rise to approximately $6.8 billion by 2030.
- Revenue is then projected to reach roughly $7.5 billion in 2031 as more connected and software-defined vehicle platforms enter production.
- By 2035, the narrower forecast puts the global market at $11.7 billion, approximately three times its 2025 level.
- The 2025-2035 market trajectory corresponds to an 11.6% CAGR.
- China is projected to grow faster than the global average, with a 15.7% CAGR from 2025 to 2035.
- India follows closely with a projected 14.5% CAGR, while France is projected at 12.2%, the U.K. at 11.0%, and the U.S. at 9.9%.
- A broader automotive cybersecurity and software-defined vehicle security estimate projects the combined market from roughly $6 billion in 2025 to $28 billion by 2032, implying annual growth in the 24%-26% range.
Connected Car Security Market Statistics
- The U.S. connected car security market generated an estimated $808.4 million in 2025.
- U.S. market revenue is projected to reach $868.2 million in 2026, an increase of about $59.8 million in one year.
- By 2030, the U.S. connected car security market is forecast to reach approximately $1.20 billion.
- The market could rise further to $1.41 billion by 2032, representing an 8.3% CAGR across the stated forecast period.
- Security for telematics control units generated about $290.5 million in U.S. revenue in 2025, making it the largest of the listed application categories.
- Telematics control unit security revenue is projected to rise to $309.9 million in 2026 and $484.3 million by 2032.
- Infotainment security accounted for about $257.1 million in 2025 and is projected to reach $275.3 million in 2026.
- Security for communication modules generated about $195.4 million in 2025 and is forecast to reach $210.4 million in 2026.
- ADAS and autonomous-driving security represented a smaller $65.4 million in 2025, but the segment carries the fastest listed CAGR at 11.9%.
- By 2032, U.S. ADAS and autonomous-driving cybersecurity revenue is projected to reach $144.1 million, more than double its 2025 level.
Regional Automotive Cybersecurity Market Share
- Asia-Pacific held the largest regional position in one global assessment, accounting for 35.8% of automotive cybersecurity revenue in 2025.
- China held the largest country-level market position within that Asia-Pacific assessment in 2025.
- China is projected to post a 15.7% CAGR from 2025 through 2035, one of the highest growth rates among major automotive markets.
- India’s automotive cybersecurity market is projected to expand at a 14.5% CAGR from 2025 to 2035, compared with 12.3% during 2020-2024.
- France is forecast to grow at a 12.2% CAGR through 2035, up from its estimated 10.5% growth rate during 2020-2024.
- The U.K. market is forecast to expand at an 11.0% CAGR between 2025 and 2035, compared with 9.2% during 2020-2024.
- The U.S. automotive cybersecurity market is projected to grow at 9.9% annually from 2025 through 2035, following an estimated 8.3% CAGR during 2020-2024.
- In the more specialized V2X cybersecurity segment, China is forecast to grow at 16.6% annually, India at 15.4% and Germany at 14.1% between 2025 and 2035.
- The corresponding V2X cybersecurity growth forecasts are 12.9% for France, 11.7% for the U.K. and 10.5% for the U.S..
- North America, Asia-Pacific and Europe remain the three principal growth regions cited across automotive cybersecurity and V2X security forecasts, although Asia-Pacific currently leads in revenue share in the broad 2025 market estimate.

Automotive Cybersecurity Market by Component and Solution
- Hardware solutions in the connected-car security market generated about $2.6 billion in 2025 and could reach $8.5 billion by 2035, representing a 12.91% CAGR.
- Software solutions generated approximately $1.4 billion in 2025 and are forecast to reach $5.3 billion by 2035, growing at 14.66% annually.
- Cloud security represented about $700 million in 2025 and could expand to $3.1 billion by 2035, making it the fastest-growing security category in that forecast at 15.39% annually.
- Endpoint security accounted for roughly $800 million in 2025 and is projected to reach $2.7 billion by 2035.
- Application security generated an estimated $600 million in 2025 and could reach $2.5 billion by 2035, supported by rising software complexity in infotainment, telematics, and vehicle applications.
- In automotive in-vehicle communication security, software and services represented 55.19% of 2025 revenue, equivalent to about $557.67 million.
- Hardware security modules accounted for the remaining 44.81%, or about $452.83 million, in that specialized 2025 market.
- The broader automotive cybersecurity hardware market reached approximately $2.3 billion in 2025, up from $2.1 billion in 2024, and could rise to $5.8 billion by 2034.
- Embedded automotive cybersecurity is projected to capture 73.29% of the market in 2026, illustrating the industry’s continued emphasis on security controls installed directly inside the vehicle.
- Automotive OEMs represented 49.62% of cybersecurity end-user revenue in 2025, while Tier 1 and Tier 2 supplier demand is projected to expand at a 15.1% CAGR through 2035.
Automotive Cybersecurity Market by Vehicle Type
- Passenger vehicles accounted for approximately 61.4% of global automotive cybersecurity revenue in 2025 under one market segmentation.
- A separate industry model estimated passenger cars at roughly 70% of the market in 2025, showing how shares differ depending on market scope and vehicle classification.
- Passenger cars also held the largest vehicle-type revenue position in another 2025 global assessment, ahead of commercial and electric vehicles.
- SUVs are projected to account for 43.86% of automotive cybersecurity revenue in 2026 within a body-style-based segmentation.
- Commercial vehicles are forecast to record the highest vehicle-type CAGR in one current market assessment as fleet electrification and always-on telematics increase security requirements.
- Electric vehicles represent one of the fastest-expanding cybersecurity categories because EV architecture combines battery-management software, charging interfaces, mobile applications, and cloud platforms.
- In the specialized EV cybersecurity market, software represented 42.3% of 2025 spending, exceeding hardware at 35.4% and services at 22.3%.
- EV cybersecurity services are projected to grow at 18.6% annually, faster than EV-focused software at 15.9% and hardware at 14.8%.
- Network security captured 34.7% of the EV cybersecurity market in 2025, reflecting the need to protect vehicle networks, V2X channels, and charging communication.
- Cloud security for EVs accounted for 13.8% of the market in 2025 but carries a projected 19.4% CAGR, the fastest rate among the listed EV security categories.
Automotive Cybersecurity Market by Application
- ADAS and safety systems accounted for an estimated 30% of automotive cybersecurity revenue in 2025 in one segmentation, making them the largest application category in that analysis.
- In a separate connected-car security dataset, telematics control units generated approximately $1.3 billion in 2025 and are forecast to reach $4.5 billion by 2035.
- Infotainment security generated around $1.1 billion in 2025 and could rise to $3.8 billion by 2035.
- ADAS and autonomous-driving cybersecurity generated approximately $800 million in 2025 and is projected to reach $3.4 billion by 2035.
- ADAS and autonomous-driving security carries a projected 16.09% CAGR, the fastest application growth rate in that connected-car security forecast.
- In the U.S., telematics control unit security is projected to increase from $290.5 million in 2025 to $309.9 million in 2026.
- U.S. infotainment cybersecurity revenue is projected to reach $275.3 million in 2026, rising further to $440.1 million by 2032.
- Communication-module security in the U.S. is forecast at $210.4 million in 2026 and $344.7 million by 2032.
- U.S. ADAS and autonomous-driving cybersecurity is projected to reach $72.6 million in 2026, with an 11.9% CAGR through 2032.
- Infotainment remains the largest application segment in one global 2025 assessment and is also expected to record the fastest application CAGR from 2026 to 2033 in another current forecast.

Automotive Cyber Threats and Attack Vectors
- Researchers analyzed 494 publicly reported automotive and smart-mobility cybersecurity incidents in 2025.
- Approximately 67% of 2025 incidents originated from telematics and cloud environments, making backend connectivity the dominant attack surface.
- About 71% of incidents were attributed to black-hat threat actors in 2025, up from 65% in the prior year.
- Roughly 61% of incidents had the potential to affect thousands to millions of mobility assets in 2025.
- Massive-scale incidents represented 20% of reported incidents in 2025, highlighting the ability of centralized systems to create fleet-wide exposure.
- In 2024, 92% of automotive cyberattacks occurred remotely, showing that attackers rarely needed physical access to the targeted vehicle or system.
- Of those 2024 attacks, 85% were long-range attacks that required no physical proximity to the targeted mobility asset.
- Telematics and application servers accounted for 66% of incidents in 2024, compared with 43% in 2023.
- API-related attacks reached 17% of incidents in 2024, after increasing by nearly 30% from the preceding period.
- More than 76% of black-hat activity observed on deep and dark web channels in 2024 targeted multiple stakeholders and had potential global reach.
Automotive Ransomware Attack Statistics
- Ransom-related incidents represented 44% of all publicly reported automotive and smart-mobility cybersecurity incidents in 2025.
- The number of automotive ransom incidents more than doubled from 2024 to 2025, signaling a substantial escalation in financially motivated attacks.
- A separate threat-intelligence dataset identified 161 verified automotive ransomware victims in 2025.
- That total represented a 77% year-over-year increase from 91 automotive ransomware victims in 2024.
- The 2025 total also stood 45% above the 111 victims recorded in 2023.
- Automotive organizations represented 2.32% of 7,099 ransomware victims recorded across all industries in the same 2025 dataset, up from 1.74% a year earlier.
- The United States accounted for 39% of automotive ransomware victims in 2025, with 63 verified cases, compared with 38 in 2024.
- Automotive ransomware affected organizations in 34 countries during 2025, up from 20 countries in 2024.
- One leading ransomware group accounted for 27 automotive victims in 2025, while another accounted for 17 and a third for 11.
- In early 2026, researchers identified 59 automotive ransomware victims within one 90-day period, a 55.3% increase from the preceding comparable period of 38 victims.
Types of Cyberattacks on Connected Vehicles
- Data and privacy breaches were the most prominent cyberattack impact on connected vehicles in 2025, accounting for 68%, significantly higher than any other category.
- Ransomware and ransom attacks represented 44%, highlighting the growing exposure of connected vehicle systems and automotive organizations to financially motivated cyber threats.
- Service and business disruption accounted for 34% of cyberattack impacts, showing that roughly one-third involved interruptions to automotive operations, services, or connected systems.
- Other attack types represented 32%, indicating that connected vehicles also face a broad range of cybersecurity threats beyond data breaches, ransomware, and operational disruption.
- The 24-percentage-point gap between data and privacy breaches (68%) and ransomware attacks (44%) underscores how strongly data-related incidents dominated the connected vehicle threat landscape.

Vehicle Hacking Incidents and Trends
- Publicly tracked automotive and smart-mobility incidents increased from 295 in 2023 to 409 in 2024, a rise of about 38.6% in one year.
- The incident count then increased from 409 to 494 in 2025, representing another year-over-year rise of roughly 20.8%.
- Taken together, publicly analyzed annual incidents increased by approximately 67.5% between 2023 and 2025.
- Malicious black-hat activity rose from 65% of attacks in 2024 to 71% in 2025, a six-percentage-point increase.
- High-impact attacks continued to expand in scale: by 2025, three in five incidents had the potential to affect thousands to millions of mobility assets.
- API weaknesses remained a notable vehicle-hacking route in 2025, with documented cases allowing attackers to use identifiers such as license plate information to reach connected vehicle functions through backend systems.
- A 2025 ransom incident showed attackers could access remote vehicle command-and-control functions through a companion application, including ignition and door-lock functionality.
- Automotive ransomware exposure increased geographically from 20 affected countries in 2024 to 34 countries in 2025, showing that serious automotive cyber incidents no longer concentrate in a few mature vehicle markets.
- The number of countries represented among ransomware victims therefore increased by 70% in one year, based on the change from 20 to 34.
- Deep and dark web monitoring found that 70% of malicious activities observed in 2024 could potentially affect thousands to millions of mobility assets, underscoring why attackers increasingly favor scalable digital access over single-vehicle physical attacks.
Automotive Data Breach Statistics
- Data or privacy breaches resulted from 68% of reported automotive and smart-mobility cybersecurity incidents in 2025.
- Researchers recorded 494 publicly reported incidents in 2025, meaning the 68% share equates to roughly 336 incidents involving data or privacy consequences if applied across the reported dataset.
- Meanwhile, 67% of 2025 incidents originated from telematics and cloud environments, highlighting how customer and vehicle information can face exposure far beyond the physical car.
- 61% of incidents in 2025 had the potential to affect thousands to millions of mobility assets, while 20% qualified as massive-scale incidents. Centralized data infrastructure can therefore turn one intrusion into fleet-wide exposure.
- In the first quarter of 2026, researchers observed 405 automotive ecosystem cybersecurity incidents, up 7.1% from 378 in the fourth quarter of 2025.
- Enterprise IT systems accounted for 210 of those 405 Q1 2026 incidents, or about 51.9%, making corporate infrastructure the largest observed attack domain.
- In-vehicle systems generated another 129 Q1 2026 incidents, representing approximately 31.9% of the quarter’s total.
- Connected vehicle backend services accounted for 18 incidents in Q1 2026, while vehicle companion applications accounted for two. Together, these categories demonstrate how vehicle-connected customer services remain part of the data-risk landscape.
- A major 2024 cyberattack disrupted software used by more than 15,000 U.S. dealerships, illustrating how a compromise at one automotive technology provider can affect thousands of retail locations at once.
- That disruption contributed to an estimated $1 billion in collective dealership sales losses during June 2024, showing that automotive data and systems incidents can create substantial financial effects even without compromising vehicle controls.
Keyless Entry and Remote Access Vulnerabilities
- Government crime-survey estimates found that 58% of vehicle theft offenses in the year ending March 2024 involved manipulation of a remote-locking-device signal.
- Authorities in London estimate that electronic devices contribute to approximately 60% of vehicle thefts in the city.
- For comparison, remote-locking signal manipulation accounted for 36% of vehicle thefts in 2019-20, indicating how strongly electronic theft techniques have grown over several years.
- One regional police force recorded 116 keyless or relay theft crimes in 2024, compared with 162 in 2023, 54 in 2022, 24 in 2021 and 12 in 2020.
- Despite the 2024 decline in that region, its 116 cases were nearly 10 times the 2020 total of 12.
- Another police jurisdiction documented 72 keyless vehicle thefts in 2024, triple the 24 cases it recorded in 2023.
- Across 2020-24, that jurisdiction identified 106 keyless thefts, with approximately 68% occurring in 2024 alone.
- A separate region recorded 489 keyless thefts in 2023 and 295 in 2024, a year-over-year reduction of roughly 39.7% but still nearly 300 cases in one year.
- Earlier testing of 237 keyless vehicles from 30 brands found that 230 could be unlocked and started through relay attacks, equivalent to roughly 97% of the models tested at that time.
- National crime estimates recorded 129,727 motor-vehicle theft offenses in the year ending December 2024, within 364,208 police-recorded vehicle-related theft offenses overall. Although not all involved cyber techniques, the figures show the large vehicle population to which electronic theft methods can apply.

Over-the-Air (OTA) Update Security Statistics
- The global automotive OTA update market reached an estimated $5.8 billion in 2025 under one current market definition and is projected to rise to $7 billion in 2026.
- That represents an estimated 20.7% increase from 2025 to 2026, highlighting the rapid expansion of remote vehicle software management.
- OTA revenue could reach $32.4 billion by 2033, representing a 24.6% CAGR between 2026 and 2033.
- Software OTA accounted for 76.4% of global OTA revenue in 2025 in that market assessment, substantially exceeding firmware-focused update revenue.
- Passenger vehicles represented 65.9% of OTA revenue in 2025, indicating that remote updates have moved well beyond premium or experimental vehicle programs.
- Infotainment systems accounted for 30.7% of OTA revenue in 2025, making them the largest listed application segment.
- North America generated 30.9% of global OTA revenue in 2025, while Asia-Pacific is projected to record the fastest regional growth through 2033.
- A separate 2026 forecast values the OTA market at $5.8 billion in 2026 and projects $29 billion by 2035, equivalent to a 19.5% CAGR.
- Another August 2026 assessment estimates OTA revenue at $5.32 billion in 2026, up from $4.13 billion in 2025, and projects $21.96 billion by 2034.
- As of September 2026, 58 parties apply UN Regulation No. 156, which establishes requirements for vehicle software updates and software update management systems.
Automotive Cybersecurity Regulations and Standards
- UN Regulation No. 155 entered into force on Jan. 22, 2021, establishing an international regulatory framework for vehicle cybersecurity and cybersecurity management systems.
- As of Sept. 9, 2026, 59 parties apply UN Regulation No. 155.
- The regulation initially entered into force within the framework of a vehicle agreement that covered 54 countries at the time, showing that its geographic reach has continued to broaden.
- UN Regulation No. 156 also entered into force on Jan. 22, 2021, and focuses specifically on software updates and software update management systems.
- By Sept. 8, 2026, UN Regulation No. 156 had 58 participating parties, one fewer than the cybersecurity regulation.
- Uzbekistan began applying both Regulations No. 155 and No. 156 on Oct. 20, 2025, illustrating their continued expansion beyond the original participant group.
- Mongolia began applying Regulation No. 155 on April 29, 2026, further extending the cybersecurity framework during the current year.
- Amendments to Regulation No. 156 were formally notified on June 12, 2026, showing that software-update regulation continues to evolve as automotive software practices change.
- A dedicated implementation workshop for Regulations No. 155 and 156 ran for two days, May 15-16, 2025, with particular attention to cybersecurity and software-update compliance for multistage vehicles.
- In the U.S., federal automotive cybersecurity best practices remain nonbinding guidance rather than a UN-style vehicle cybersecurity type-approval framework. The first edition appeared in 2016, an updated draft followed in 2021, and the finalized updated guidance followed in 2022.
Automotive Cybersecurity Spending and Investment
- Global automotive cybersecurity spending is projected to rise from $6.88 billion in 2026 to $18.86 billion by 2033, showing substantial investment growth across the automotive sector.
- The market is expected to cross the $10 billion milestone in 2029, reaching approximately $10.60 billion as automakers increase spending on vehicle security.
- By 2030, global automotive cybersecurity investment is forecast to reach $12.27 billion, nearly 78% higher than the 2026 level.
- Spending is projected to accelerate further from $14.17 billion in 2031 to $16.39 billion in 2032, representing an annual increase of more than $2 billion.
- Between 2026 and 2033, the market is expected to expand by approximately $11.98 billion, meaning global spending could reach about 2.7 times its 2026 level.
- The consistent year-over-year growth indicates that automotive cybersecurity is becoming an increasingly important investment area as connected and software-driven vehicles require stronger security infrastructure.

Frequently Asked Questions (FAQs)
The global automotive cybersecurity market is estimated at $6.88 billion in 2026 and is projected to reach $18.86 billion by 2033.
The market is forecast to grow at a 15.5% CAGR from 2026 to 2033.
Researchers recorded 405 cybersecurity incidents in Q1 2026, up 7.1% from 378 incidents in Q4 2025.
Europe ranked first with 161 incidents, followed by the Americas with 140 and Asia with 72.
As of Sept. 9, 2026, 59 parties apply UN Regulation No. 155 on vehicle cybersecurity and cybersecurity management systems.
Conclusion
Automotive cybersecurity in 2026 extends beyond protecting individual vehicle systems. The industry now has to secure cloud platforms, software updates, mobile applications, telematics, charging networks, dealerships and external service providers alongside the vehicle itself. With the market projected at $8.8 billion in 2026, 494 publicly reported automotive and smart-mobility incidents recorded in 2025, and ransomware accounting for 44% of incidents, cybersecurity has become a continuous vehicle-lifecycle requirement.
International requirements are also expanding, with 59 parties applying UN Regulation No. 155 and 58 applying Regulation No. 156 by September 2026. As connected and software-defined vehicles become more common, manufacturers, suppliers, dealerships, fleet operators and technology providers will need stronger security across development, production, software updates and long-term vehicle operation.