On the Dash: - Ransomware attacks on the auto industry more than doubled in 2025, accounting for 44% of all cyber incidents. - Suppliers are the weakest link, giving criminals a back door into OEM systems. - Connected vehicles are now a direct target, with attackers seizing remote control of individual cars. Ransomware attacks targeting the automotive sector more than doubled in 2025, according to a new report by cybersecurity firm Halcyon. Ransomware is a type of cyberattack in which criminals infiltrate a company’s systems, encrypt its data, and demand payment to restore access. Those attacks made up almost half (44%) of all cyber incidents across the industry last year, the report found. The consequences have been severe. A ransomware attack halted all of Jaguar Land Rover’s global production for more than three weeks last October, causing an estimated $2.5 billion in economic damage. A year earlier, BlackSuit, a Russia-linked criminal organization, took down operations at approximately 15,000 dealerships for two weeks after attacking the industry’s leading dealership management platform. The collective losses were estimated at $1 billion. Consumer data is also at risk. A compromised automotive IT provider in early 2025 exposed personal information on 2.7 million vehicle owners, including Social Security numbers. Why automakers and dealers are ransomware targets Cybersecurity analysts say criminals are targeting the auto industry for a simple reason: shutting it down is expensive. Automotive manufacturing runs on tight deadlines. When systems go down, the costs quickly add up. The math makes the auto industry one of the most attractive extortion targets for cybercriminals. The industry’s rapid embrace of connected technology made the problem worse. Vehicle platforms, over-the-air software updates, and cloud-based systems all created new targets for the attackers. In 2025, attackers used telematics systems, cloud platforms, or APIs as their primary entry point