The software update for your next car might turn out to be its greatest security threat.
Modern automobiles have evolved beyond static machines that remain unchanged after their sale. They are increasingly being classified as software-defined vehicles, capable of receiving updates, new features, bug fixes, and security patches wirelessly—similar to smartphones. While over-the-air (OTA) updates simplify vehicle maintenance and reduce costs, cybersecurity experts caution that this same technology may also present significant security challenges for the automotive sector.
Researchers and lawmakers are now advocating for more stringent oversight as vehicles become more reliant on remote software updates. Their concerns extend beyond the potential for hackers to access personal information; they also worry about the risk of someone manipulating the functions of a moving automobile.
The convenience of wireless updates introduces new vulnerabilities
OTA technology enables manufacturers to send software updates, firmware upgrades, and security patches directly to vehicles without requiring owners to visit service centers. Tesla popularized this approach over a decade ago with wireless updates for the Model S starting in 2012. Today, this feature has become widespread among both luxury and mainstream cars.
The benefits for consumers are clear. Automakers can swiftly address software glitches, enhance battery performance, introduce new entertainment features, or improve driving dynamics without needing costly recalls. According to a CNBC report featuring insights from Siraj Ahmed Shaikh, a Professor of Systems Security at Swansea University, OTA updates have emerged as a preferable option to traditional maintenance, as they cut costs and speed up issue resolution. Manufacturers can manage problems nearly instantly rather than waiting for scheduled services.
Cybersecurity experts assert that vehicles with internet connectivity essentially operate as mobile computers.
However, the same connected system that allows for these updates also increases vulnerability to attacks. Cybersecurity analysts argue that internet-enabled vehicles are essentially rolling computers. If hackers were to compromise the update system or gain unauthorized access to a vehicle's software, the repercussions could go far beyond data theft.
Gabriel Lim, a Senior Analyst at Singapore’s S. Rajaratnam School of International Studies, remarked to CNBC that this issue could pose a national security risk. In addition to privacy concerns, governments are increasingly scrutinizing the potential for foreign manufacturers or hostile entities to interfere remotely with vehicle systems. Such apprehensions have led several nations to reevaluate the regulation of connected vehicles.
Governments are starting to take these threats seriously
The conversation around this issue intensified following security tests conducted last year by Norwegian public transport operator Ruter on electric buses. The company discovered that one vehicle's battery and power management system could be accessed remotely via a mobile network. Theoretically, it determined that the manufacturer could disable or immobilize the bus from a distance.
While the inquiry focused on buses produced by the Chinese company Yutong, experts warn that this issue is not confined to any particular automaker or nation. Rather, they view it as a challenge affecting the entire industry due to the increasing use of connected vehicle technologies. These findings led authorities in the United Kingdom and Denmark to initiate their own investigations, with the UK's Department for Transport collaborating with the National Cyber Security Centre to explore potential vulnerabilities.
As cars become more technologically advanced, hackers may also enhance their methods.
Similar concerns are now emerging in policy debates within the United States. Earlier this year, the American Enterprise Institute stated that safeguarding connected vehicles against foreign espionage should be a strategic priority. The think tank proposed stronger security assessments, increased transparency regarding vehicle data collection, and stricter regulations on particular foreign automotive software and hardware.
The implications of these issues extend far beyond just passenger vehicles. OTA technology is gradually being integrated into buses, commercial fleets, railway systems, ships, industrial robots, and drones. As more crucial infrastructure becomes subject to remote updates, experts emphasize that cybersecurity cannot be an afterthought. Wireless updates are indeed making vehicles more intelligent and capable, but they are also redefining what automotive safety means. In this software-driven era, securing a car increasingly involves safeguarding the code that operates it, as the next cyber threat may target not your laptop or smartphone, but the vehicle you are driving.
Other articles
The software update for your next car might turn out to be its greatest security threat.
Experts indicate that over-the-air updates for vehicles are revolutionizing the automotive sector but are also giving rise to new cybersecurity and national security threats that governments must address.
