Tokyo, Japan – VicOne, a leading company in automotive cybersecurity and a subsidiary of Trend Micro Incorporated (Tokyo, Japan; CEO Eva Chen), has announced the release of its "VicOne 2026 Automotive Cybersecurity Report," which sheds light on the current state of automotive cybersecurity.
The report reveals that the automotive industry is entering a new phase defined as the "Overlap Era." While traditional vehicle platforms still dominate, the rapid advancement of Software-Defined Vehicles (SDVs), increased connectivity, and the integration of AI are leading to a transitional period where new and old technologies coexist within the same vehicle ecosystem. This era presents overlapping risk areas, necessitating a comprehensive cybersecurity approach that extends beyond technical solutions to encompass governance and decision-making processes.
Key Highlights from the Report
・Total number of automotive cybersecurity incidents reported in 2025: 610 (approximately 2.8 times the previous year)
・Total number of automotive-related vulnerabilities disclosed in 2025: 1,384 (approximately 1.5 times the previous year)
・The attack surface has shifted from enterprise IT systems (37.7%) to in-vehicle systems (39.7%), with those closer to the driver becoming primary targets.
・Japan saw a dramatic surge in incidents, increasing over eightfold from 5 to 41, accounting for approximately half of all incidents in Asia.
・While 89% of automotive-related vulnerabilities are publicly disclosed in the CVE database, the remaining 11%, including zero-days, remain outside of governance management.
The report can be downloaded from: https://vicone.com/jp/reports/2026-automotive-cybersecurity-report
Overview of Automotive Cyber Threats Based on 2025 Data
Attacks Expanding to OEMs and Vehicle Bodies – 610 Incidents, a 2.8-fold Increase Year-over-Year
In 2025, the automotive industry reported 610 cybersecurity incidents, a significant increase of approximately 2.8 times compared to the previous year's 215 incidents. In addition to attacks previously targeting dealerships, attacks directly targeting OEMs have also risen. The number of vulnerabilities discovered in 2025 grew to 1,384, about 1.5 times that of the previous year. In 2025, vulnerabilities affecting two Japanese OEMs were successively revealed, allowing vehicle tracking and remote control through backend and communication systems. As connectivity advances, risks directly impacting vehicle safety and privacy are becoming a reality.
<img src=
FACT BOX
- Source: PR TIMES
- Category: News