Excerpt: VicOne’s Q2 2026 report records a 17.8% quarter-over-quarter jump in automotive cybersecurity incidents, with in-vehicle systems seeing the sharpest rise.
VicOne recorded 477 automotive-related cybersecurity incidents in Q2 2026, a 17.8% increase from the 405 logged in Q1, according to the company’s latest Situational Awareness Report published July 17. The quarterly data shows that in-vehicle systems suffered the largest spike, climbing from 129 incidents to 168.
The Americas overtook Europe as the most affected region, with 245 incidents representing over 51% of the global total. Europe recorded 113, down from 161 in Q1, while Asia logged 68.
Ransomware activity declined to 160 incidents from 180 in Q1, but logistics and transportation remained the hardest-hit sector at 64 incidents, or 40% of all ransomware activity. Qilin was the most active named group with 15 claimed attacks, followed by The Gentlemen (14), LockBit (12), and Akira (11). Activity accelerated toward the end of the quarter, with June recording 61 incidents — the highest monthly total.
Enterprise IT systems remained the most frequently affected domain with 230 incidents, but the growth was concentrated in vehicle-adjacent systems. Charging infrastructure saw 28 incidents, connected vehicle backend services logged 18, and vehicle companion apps recorded 2.
Injection-related weaknesses dominated the CWE rankings. SQL injection led with 24 entries, followed by general injection flaws (14) and stack-based buffer overflows (8). The report also flagged AI-related risks, including an AI agent on GitHub enabling automated ECU parameter modification and threat actors adapting prompt-manipulation techniques to evade AI-assisted security analysis.
Several notable Q2 incidents cited in the report include the EvilValet attack against Honda infotainment systems, API vulnerabilities in connected vehicle cloud services, charging infrastructure flaws affecting Autel and Mennekes products, and the AlgoBuster framework targeting UDS Security Access in automotive ECUs.
VicOne emphasized that security teams need visibility across enterprise systems, operational platforms, connected services, charging infrastructure, and in-vehicle software to manage risk in what it calls the “Overlap Era.”