

APT Campaigns – 5.4
9 of 57 campaigns (16%), identical absolute count to last period with share falling only as the pool doubled. Financially motivated actors lead, unusual across sectors. Database management software at five instances, the highest count of any sector, pointing to design and supply chain data theft.
Cyber Incidents – 6.2
6 incidents, 12th of 14, but five reached the manufacturer through third parties rather than its own perimeter. Cl0p targeting PTC Windchill and FlexPLM is the only case this period where an actor picked a platform because of the sector using it.
Dark Web Chatter – 4.5
115 mentions, last of 14 and the lowest volume in the report. Data breach discussion is the only category rising uninterrupted, from 3 to 16. Claimed hacks and web exploits fall to zero in the final period.
Vulnerabilities – 4.0
0.60% of industry-linked disclosures, last of 14 with 22 total mentions. No category shows a sustained trend across all three periods. Injection attacks the only final-period increase, relevant to connected vehicle APIs and dealer backends.
Ransomware – 4.7
47 victims, flat at -2.1% Q-on-Q with share holding at 2.08%. W-shaped monthly pattern recovering to near-peak in June and July. Tier 1 suppliers absorbed over three times the victims of any other subsector. 26% gang participation, the lowest observed this period.
The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each week for a quarter. This report focuses on the automotive industry, presenting key trends and statistics in an engaging infographic format.
Welcome to the CYFIRMA infographic industry report, where we delve into the external threat landscape of the automotive industry over the past three months. This report provides valuable insights and data-driven statistics, delivering a concise analysis of attack campaigns, public reports, underground & dark web chatter, vulnerabilities, and ransomware incidents targeting automotive organizations.
We aim to present an industry-specific overview in a convenient, engaging, and informative format. Leveraging our cutting-edge platform telemetry and the expertise of our analysts, we bring you actionable intelligence to stay ahead in the cybersecurity landscape.
CYFIRMA delivers pre-emptive cybersecurity, cyber threat intelligence, and external threat landscape management through its platforms, DeCYFIR and DeTCT. These platforms have been purpose-built over many years to continuously collect, correlate, and analyse large volumes of external threat data, combining proprietary intelligence automation with deep, hands-on cyber threat research.
For the purpose of this report, the analysis draws on intelligence generated from CYFIRMA’s platforms. The data referenced has been processed through automated correlation and enrichment mechanisms, informed and validated by human-led research and investigative expertise, and sourced from both structured and unstructured external intelligence channels.
While this report contains data collected and processed by our in-house AI and ML, all charts, statistics, and analyses are done by human CYFIRMA CTI analysts to ensure the highest quality and provide accurate insights.
Automotive organizations featured in 9 out of the 57 observed campaigns, which is a presence in 16% of all campaigns. Identical to the previous period, where automotive organizations were present in 9 out of 26 campaigns. However, a decline from presence in 35% of observed campaigns.


APT activity targeting Automotive has been continuous. Most of the campaigns have been active and have been updated with new detections as recently as July.

Observed APT campaigns show a notably different actor profile from most sectors this period, with financially motivated actors accounting for a significant share of observed activity. TA505 leads with the highest campaign count, followed by FIN11 and FIN7, reflecting the automotive sector’s exposure to both ransomware-adjacent and data theft operations.
China-linked TICK and Stone Panda also feature, alongside Russia-linked Gamaredon. North Korea-associated Lazarus Group appears in a single campaign. No Iran-linked actors are observed this period, and the overall actor set is narrower than in most other sectors, pointing to more concentrated rather than broad-based targeting.

Victim distribution spans 20 countries, notably more concentrated than in most sectors this period, with every recorded country appearing in at least two observed campaigns. Japan leads in victim count, followed closely by the United States, with South Korea and Taiwan also featuring prominently.
European presence is stronger and more evenly distributed than in most sectors, with the United Kingdom, Spain, France, Hungary, and Ukraine all recording meaningful victim counts. Spain’s relatively high count reflects its significant automotive manufacturing base, while Hungary and Ukraine’s presence aligns with both regional automotive industry concentration and Russia-linked Gamaredon’s known targeting patterns.
Middle Eastern presence is limited to Saudi Arabia, with Southeast Asian countries including the Philippines, Thailand, Singapore, Vietnam, Malaysia, and Indonesia each recording two victims across observed campaigns.

Web applications and operating systems account for the majority of observed attacks this period. Database management software features prominently at five instances, the highest relative count for this category across any sector, pointing to data exfiltration as a primary objective consistent with the automotive sector’s concentration of design, engineering, and supply chain data.
Application infrastructure software appears across three campaigns, reflecting threat actor interest in targeting the underlying platforms supporting automotive operational and enterprise systems. Application server software rounds out the profile in a single instance. The relatively narrow technology distribution, combined with the high database management count, suggests focused intrusion objectives rather than broad infrastructure disruption.

The automotive sector’s external threat landscape is expected to remain at a sustained Elevated level for the next 90 days. Campaign count held steady at 9, while the sector’s share of observed campaigns declined from 35% to 16% as the overall campaign pool doubled. This indicates stable targeting intensity, with the sector maintaining a consistent presence without attracting disproportionate new attention.
Campaign count remained identical at 9 out of 26 and 9 out of 57 observed campaigns, respectively. The apparent concentration in June and July reflects platform update and detection stacking patterns, not a genuine gap in activity. Most campaigns remained active and received new detections as recently as July. A plausible baseline estimate for the next 90 days is 8 to 11 automotive sector campaigns.
Financially motivated actors TA505, FIN11, and FIN7 collectively account for a significant share of observed campaigns and are expected to maintain targeting due to the sector’s concentration of high-value data. This distinguishes the sector from most others and points toward continued ransomware-adjacent and data theft operations.
Database management software recording five instances alongside application infrastructure software across three campaigns suggests structured data access as a primary objective. Organizations with externally accessible databases and unpatched application infrastructure face the highest immediate risk.
Japan leads in victim count, followed by the US, South Korea, Taiwan, and the UK. Europe has broader exposure, with Spain, France, Hungary, and Ukraine all recording meaningful victim counts, likely due to Russia-linked Gamaredon activity.
The narrower actor set and flat campaign trajectory suggest targeting is driven by a stable group of actors with established access, not new entrants. Defenders should monitor for data exfiltration indicators due to the financially motivated actor profile and high database management targeting observed.
Over the past 90 days, DeCYFIR and DeTCT platforms tracked 692 cyber incidents reported publicly. We could identify the industry for 508 of these incidents (73%).
The automotive industry was detected in 6 incidents, which equals 1.18% of the incidents where we knew the industry, ranking 12th out of 14 industries.

The automotive industry was directly identified in 6 of 508 industry-tagged incidents, 1.18%, ranking 12th of 14 sectors. Taken alone, that is a low observed rate. The score sits in the elevated band for three reasons.
First, five of the six incidents are data compromises reaching the manufacturer through a third party rather than through its own perimeter, which is a control gap the sector cannot close by hardening itself.
Second, the wider manufacturing evidence in the same period shows active state-linked exploitation of industrial control systems and an extortion actor deliberately targeting engineering platforms, and automotive shares that infrastructure.
Third, public reporting on this sector is thin and skewed to large listed OEMs, so the observed count almost certainly understates the real rate. Reporting volume was flat across the period, which is what keeps this out of the high band.
Current automotive exposure is data loss, not production disruption. Five of six incidents in the period are breach or privacy events. GM agreed to a 12.75 million dollar California settlement over the sale of driver data, reported on 08 and 11 May. Škoda warned customers of a breach of its online shop on 12 May. Edmunds appeared as a 177,860-account leak claimed by ShinyHunters on 01 June. Nissan disclosed an employee data breach on 29 June linked to Oracle zero-day exploitation, also tied to ShinyHunters. Only one incident, Bajaj Auto in India on 24 June, involved ransomware. No automotive incident in the period describes an attack that reached production systems.
The dominant entry route is third parties, not the OEM perimeter. The Nissan breach originated in an Oracle platform zero-day. The Edmunds and Škoda cases involve consumer-facing platforms rather than corporate networks. The GM matter concerns data handling by the manufacturer and its partners rather than an intrusion at all. The practical consequence is that automotive risk in this period was realised through connected-vehicle data, dealer and e-commerce platforms, and enterprise SaaS, none of which sit inside the plant.
ShinyHunters is the only named actor touching the sector. It appears in two of the six automotive incidents and was the most reported actor across the whole dataset. Its activity is opportunistic mass extortion against exposed platforms and is not automotive-specific. No state-linked actor was reported against an automotive target in the period.
Manufacturing Context
Automotive shares its operational technology, its supplier base and its software estate with discrete manufacturing, so manufacturing evidence is a leading indicator for automotive even when no car maker is named.
Manufacturing recorded 18 incidents in the same window, ranking 10th. Three carried operational impact through ransomware: Foxconn on 13 May via the Nitrogen gang, West Pharmaceutical on 12 May, and Swiss rolling stock maker Stadler on 22 July, where the Everest group demanded 12 million dollars and was refused. Refusal typically precedes full publication, so that dataset should be expected on a leak site.
Two developments in manufacturing are directly transferable to automotive. On 24 July, Cl0p was reported stealing data from PTC Windchill and FlexPLM. These product lifecycle management platforms hold designs, bills of materials, supplier lists and engineering change records, and they are standard across the automotive supply chain. This is the only case in the dataset where an actor appears to have chosen a platform because of the sector using it. Separately, on 22 and 23 July, CISA, the FBI, the EPA and partner agencies updated warnings that Iran-affiliated actors are actively exploiting programmable logic controllers in US critical infrastructure, with manufacturing named in scope. A critical flaw in OT Robot OS disclosed on 20 May grants attackers direct control over industrial robotics, the same class of equipment on any vehicle assembly line.
The FortiBleed campaign applies equally. Credentials for 73,932 FortiGate devices were exposed; attackers then deployed a custom Go-language sniffer on the firewalls to harvest more, and by 02 July the same actors were working with the Inc and Lynx ransomware gangs. These appliances commonly enforce the boundary between office IT and plant OT networks, which makes this an entry route into production regardless of sector.

Third-party and platform breaches will remain the most likely realised loss for automotive. Expect further disclosures originating in enterprise SaaS, dealer systems and connected-vehicle data platforms rather than in OEM networks directly.
Engineering and supplier data extortion is the most likely new threat to reach the sector. The Cl0p PLM campaign gives other actors a working template, and automotive PLM instances hold exactly the data that carries both extortion leverage and industrial espionage value. Internet-facing Windchill and FlexPLM deployments should be treated as a priority for patching and access review now.
Production-halting ransomware remains plausible but is not yet visible in automotive reporting. The manufacturing pattern is consistent, with opportunistic entry, weeks of recovery, and attribution limited to a ransomware brand. Bajaj Auto is the single automotive data point matching it.
State-linked OT targeting is unlikely to name automotive victims in the near term but is unlikely to decrease. Plants with fuel, water, or power-adjacent process infrastructure fall inside the targeting set described in the July advisories.
Regulatory and privacy exposure will continue to generate incidents independent of any intrusion. The GM settlement is a cost event driven by data handling, and connected-vehicle telemetry keeps this category open.
Over the past 90 days, CYFIRMA’s telemetry has identified 115 mentions of automotive organizations out of a total of 16,986 industry-linked mentions. This is from a total of 300k+ posts across various underground and dark web channels and forums.
Automotive organizations placed 14th out of 14 industries in the last 90 days with a share of 0.68% of all detected industry-linked chatter.
Below is a breakdown by 30-day periods of all mentions.


Underground & dark web chatter related to the automotive sector over the last 90 days shows low overall volumes across all threat categories. Ransomware mentions fluctuate modestly before declining in the final period. Data breaches show a consistent upward trend, increasing from 3 to 16 across the window. Data leaks remain relatively stable with minor fluctuation. Claimed hacks and web exploits both decline to zero in the final period after initial activity. DDoS and hacktivism remain minimal throughout, with both reaching zero in the final period.

Automotive registers the lowest overall chatter volume across all 14 sectors in this report. The sector’s limited underground footprint reflects a comparatively narrow digital attack surface in terms of traditional IT infrastructure, though connected vehicle systems, dealer networks, and manufacturing supply chains represent expanding exposure vectors not fully captured in current chatter volumes.
Data Breach: The only category showing an uninterrupted upward trend across the full window, rising consistently from minimal initial levels. Despite low absolute volumes, this is the strongest directional signal in the automotive chatter dataset and warrants monitoring as a potential leading indicator of broader targeting interest.
Ransomware: The highest-volume category overall but showing variable rather than sustained activity. Automotive manufacturing operations share the same low tolerance for production downtime that makes manufacturing broadly attractive to ransomware operators, and the FortiBleed credential exposure and Inc/Lynx ransomware group activity noted in the materials assessment applies equally to automotive production environments running FortiGate at IT/OT boundaries.
Claimed Hacks and Web Exploit: Both decline to zero in the final period. This could reflect reduced attacker interest in public claims, migration to private access broker markets, or simply low baseline activity. Given the broader forum disruption context, zero values in the final period should not be read as confirmed absence of activity.
OT and Connected Vehicle Exposure: The OT Robot OS vulnerability reported in May and the broader expansion of industrial control system attack surface documented across manufacturing and materials sectors applies directly to automotive production environments. Connected vehicle infrastructure introduces additional exposure beyond traditional IT boundaries, though this is not currently reflected in chatter volumes.
DDoS and Hacktivism: Both negligible throughout with no sustained signal.
Sector context: The automotive sector’s chatter profile is too low-volume to support strong trend conclusions in most categories. The rising data breach trend is the one reliable signal, and the sector’s exposure to OT vulnerabilities and ransomware supply chain dynamics documented in adjacent industrial sectors represents the more credible forward risk than current chatter volumes alone would suggest.
Over the past 90 days, CYFIRMA’s telemetry has identified 22 mentions of automotive organizations out of a total of 3,652 industry mentions. This is from over 10k CVEs reported and updated in the last 90 days.
Automotive organizations ranked 14th out of 14 industries in the last 90 days with a share of 0.60% of all detected industry-linked vulnerabilities.
Below is a breakdown by 30-day periods of all mentions.


Reported CVEs in the automotive sector over the last 90 days show low overall volume with mid-period elevation across most categories. Remote and arbitrary code execution vulnerabilities spike mid-period before declining sharply in the final period. Injection attacks emerge in the final period after minimal prior activity. Memory and buffer vulnerabilities appear mid-period before declining. Denial of service, information disclosure, and privilege escalation show minimal and sporadic activity with no sustained trend.

Automotive registers the lowest CVE volume across all 14 sectors in this report, with 22 total mentions across the 90-day window. Overall disclosure volumes remain low, and no category shows a sustained upward trend across all three periods. The moderate score reflects this limited footprint while accounting for the sector’s growing connected vehicle attack surface and shared OT exposure with adjacent industrial sectors.
Remote & Arbitrary Code Execution: The dominant category despite very low absolute numbers, with a mid-period spike that declines sharply in the final period. In an automotive context, RCE vulnerabilities carry particular relevance given exposure of vehicle telematics, over-the-air update mechanisms, and dealer management systems to direct compromise.
Injection Attacks: The one category showing a final-period increase after minimal prior activity. Low in absolute terms but notable as an emerging rather than declining signal in the final period, particularly relevant to connected vehicle APIs and dealer network backend systems.
Memory & Buffer Vulnerabilities: Mid-period emergence followed by decline. Likely reflects vulnerabilities in embedded systems and automotive control unit firmware, which are prevalent in this sector and historically difficult to patch given long vehicle lifecycle timelines.
FortiGate and IT/OT Boundary Exposure: The FortiBleed credential exposure and confirmed linkage between FortiBleed actors and Inc and Lynx ransomware groups applies to automotive manufacturing environments running FortiGate at IT/OT boundaries, as documented in the materials and manufacturing assessments. Automotive production facilities share the same operational technology exposure profile as other industrial sectors.
OT and Connected Vehicle Attack Surface: The OT Robot OS vulnerability reported in May applies directly to automotive assembly environments. Beyond traditional OT exposure, the automotive sector carries an additional and expanding attack surface through connected vehicle platforms, over-the-air update infrastructure, and V2X communication systems. Current CVE disclosure volumes do not yet reflect this exposure fully, as automotive-specific vulnerability research remains less mature than enterprise IT disclosure pipelines.
Remaining Categories: Denial of service, information disclosure, and privilege escalation all show single-period sporadic activity with no sustained signal and do not currently contribute meaningfully to the sector’s CVE risk profile.
In the past 90 days, CYFIRMA has identified 47 verified ransomware victims in automotive organizations. This accounts for 2.08% of all 2,263 ransomware victims during the same period, placing this sector 13th out of 14 industries.

Furthermore, a quarterly comparison shows that the number of victims in automotive organizations has been sustained. It went from 48 to 47 victims, a -2.1% decline. The overall interest, represented by the share, also rose just slightly from 2.05% to 2.08% of all victims.


Monthly activity peaked in January before declining through spring, with a partial recovery in June and July returning victim counts to late-2025 levels. August reflects only the first few days so far.

Activity shifted notably across the three-month period. LockBit5 and Thegentlemen drove the June surge, with Aurora, Termite, and several single-appearance groups also contributing to that month’s elevated count.
July maintained similar volume through a different actor mix, with DragonForce accounting for three victims and Qilin, Incransom, and a cluster of smaller groups filling out the remainder. Nova was the most active group in May but did not record further victims in subsequent months, a pattern shared by several groups that appeared briefly then dropped out. August reflects a partial period with minimal activity recorded to date.

Out of the 87 gangs, 23 recorded victims in the automotive industry in the last 90 days, representing a 26% participation.
Lockbit5 and Thegentlemen had the highest numbers of victims, but the latter had a very low share of their victims in this industry, recording 7.1% and 1.7% of all their victims in the automotive industry.
Termite (25%) stands out as a gang with the highest share of automotive victims.
On average, gangs active in this industry recorded a 10.7% share of their victims from this industry. That is about 1 in 10 victims.

Tier 1 Automotive Suppliers accounted for the largest share of victims by a clear margin, consistent with their central role in production supply chains and the significant operational leverage ransomware creates at this level of the manufacturing hierarchy. Auto Parts Retail, Automotive Dealerships, and Automotive Manufacturers each recorded meaningful activity, reflecting broad targeting across both production and distribution sides of the sector.
R&D and component manufacturing, heavy equipment dealerships, and repair services saw fewer incidents, though the spread across nearly every subsector suggests opportunistic targeting rather than a focused campaign against any single segment.

The geographic distribution heatmap underscores the widespread impact of ransomware, highlighting the countries where victims in this industry have been recorded.

Automotive victimology shows the USA being the most targeted, accounting for 19% of all victims.
Remaining activity is distributed among 19 countries for 38 victims.
India, Turkey, and Mexico recorded the highest elevations in the last 90 days.
The USA, Germany, and France saw the largest declines.
In the last 90 days, 20 countries recorded automotive victims, 1 fewer than the 21 countries in the previous period.

The Automotive sector threat landscape is expected to remain at moderate through the next 90 days. Victim volume held nearly flat quarter-on-quarter at 47 versus 48, and the sector’s share of total ransomware victims remains low at 2.08%, placing it 13th of 14 tracked industries. While the sector is not a primary focus for most active ransomware groups, the concentration of targeting at the Tier 1 supplier level carries disproportionate supply chain consequence risk.
Volume outlook: Monthly activity showed a clear W-shaped pattern across the period, peaking in January, troughing in May, then recovering to near-peak levels in June and July before August dropped sharply as a partial month. This oscillating pattern suggests no sustained escalation but also no structural decline. A baseline of 45 to 55 victims over the next 90 days is the most plausible outcome, consistent with the sector’s demonstrated stability.
Actor behaviour: 23 of 87 active gangs recorded automotive victims, a 26% participation rate indicating limited sector prioritisation across the broader actor set. Lockbit5 and Thegentlemen led by volume, though with low sector share, pointing to opportunistic selection. Termite stands out with 25% of its victims from the automotive sector, making it the group most likely to sustain deliberate targeting going forward. The rotation of active groups across months, with several appearing only once, is consistent with opportunistic rather than campaign-driven activity.
Geographic shift: The geographic profile shifted notably in the current period, with India, Turkey, and Mexico recording the largest elevations while traditional targets including Germany, France, and the UK declined or dropped out entirely. This points to a broadening of targeting into emerging automotive manufacturing markets, a trend likely to persist as production capacity continues shifting to lower-cost regions.
Subsector risk: Tier 1 suppliers remain the primary exposure point, attracting more than three times the victims of any other subsector. Their position as critical nodes in global automotive supply chains makes them structurally attractive targets, and this concentration is unlikely to shift materially in the near term.
APT Campaigns (Sustained): Automotive featured in 9 of 57 observed campaigns (16%), an identical absolute count to the previous period, with share declining from 35% only because the total campaign pool more than doubled. The actor profile differs sharply from most sectors, with financially motivated groups leading: TA505 recorded the highest campaign count, followed by FIN11 and FIN7. No Iran-linked actors appear, and the overall actor set is narrower than elsewhere, pointing to concentrated targeting by groups with established access. Database management software featured across five campaigns, the highest count for that category in any sector this period, indicating design, engineering, and supply chain data as the primary collection objective. Victim distribution spans 20 countries with every one appearing in at least two campaigns, and European exposure is unusually even across Spain, France, Hungary, and Ukraine.
Reported Cyber Incidents (Elevated): 6 incidents recorded, placing automotive 12th of 14, but five of the six are data compromises that reached the manufacturer through a third party rather than its own perimeter. Nissan’s employee data breach originated in an Oracle platform zero-day, while the Edmunds and Škoda cases involved consumer-facing platforms. ShinyHunters is the only named actor touching the sector, and its activity is opportunistic mass extortion rather than automotive-specific. The more consequential development sits in adjacent manufacturing data: Cl0p was reported stealing from PTC Windchill and FlexPLM, product lifecycle platforms standard across the automotive supply chain holding designs, bills of materials, and supplier lists. This is the only case in the dataset where an actor appears to have selected a platform because of the sector using it.
Underground & Dark Web Chatter (Moderate): Automotive registers the lowest chatter volume across all 14 sectors at 115 mentions. Data breach discussion is the only category with an uninterrupted upward trend, rising from 3 to 16 across the window, and is the single reliable directional signal in the dataset. Ransomware is the highest-volume category but fluctuates without sustained direction. Claimed hacks and web exploits both fall to zero in the final period, which, given the broader forum disruption context, should not be read as a confirmed absence. The sector’s limited underground footprint reflects a narrow traditional IT attack surface rather than low exposure.
Vulnerabilities (Moderate): Automotive ranked last of 14 at 0.60% of industry-linked disclosures with 22 total mentions, the lowest CVE volume in the report. RCE remains dominant despite minimal absolute numbers, spiking mid-period before declining sharply. Injection attacks are the only category increasing in the final period, relevant to connected vehicle APIs and dealer network backends. Memory and buffer vulnerabilities emerged mid-period, plausibly reflecting embedded control unit firmware, which is historically difficult to patch given vehicle lifecycle timelines. Current disclosure volumes do not yet reflect connected vehicle and OTA infrastructure exposure, as automotive vulnerability research remains less mature than enterprise IT pipelines.
Ransomware (Moderate): 47 victims, effectively flat against 48 in the prior period, with share holding at 2.08%. Monthly activity followed a W-shaped pattern, peaking in January, troughing in May, then recovering to near-peak levels across June and July. Tier 1 automotive suppliers absorbed the largest share of victims by a clear margin, more than three times any other subsector, carrying disproportionate supply chain consequences given their position as critical production nodes. Gang participation was 26%, the lowest observed this period, with Lockbit5 and Thegentlemen leading by volume but showing low sector share. Termite stands out at 25% of its victims from automotive. India, Turkey, and Mexico recorded the largest elevations while Germany and France declined, pointing to a broadening into emerging manufacturing markets.