Wireless software updates are transforming vehicle maintenance, but they are also creating new pathways for cyberattacks, data breaches and potentially dangerous remote interference.
The modern automobile is no longer simply a mechanical product. It is a connected computing platform equipped with software, sensors, mobile communications and cloud-based services. As manufacturers compete to introduce new digital features, over-the-air technology—commonly known as OTA—has become an essential part of the automotive industry.
OTA systems allow automakers to deliver software, firmware, security patches and new functions directly to internet-connected vehicles. Instead of visiting a dealership or repair center, drivers can receive an update in much the same way that a smartphone downloads a new operating system. Tesla helped popularize this approach in the automotive market when it began delivering OTA updates to Model S vehicles in 2012.
The advantages are significant. Manufacturers can correct software defects more quickly, reduce the cost of certain service campaigns and distribute security patches before a known vulnerability is widely exploited. Drivers may also receive improvements to navigation, battery management, entertainment systems and vehicle performance without replacing physical components.
However, the same digital connection that makes an update convenient can also become an attack route.
A Trusted Channel Can Become an Attack Channel
An OTA system must establish a connection among the vehicle, the manufacturer’s cloud infrastructure, update servers and, in many cases, technology supplied by outside vendors. A weakness at any point in that chain could allow an attacker to intercept communications, steal credentials, alter an update or distribute malicious code.
The greatest danger is not necessarily an individual hacker targeting a single automobile. Because updates are often managed centrally, compromising one manufacturer or service provider could potentially expose an entire fleet.
Automotive cybersecurity data illustrates the scale of the broader problem. Upstream Security’s 2026 report analyzed 494 publicly reported automotive and smart-mobility security incidents from 2025. It found that 67% originated in telematics systems or cloud infrastructure, while 61% had the potential to affect thousands or even millions of mobility assets. Data and privacy breaches were among the most frequent consequences.
This means that the security perimeter of a vehicle extends far beyond the car itself. Mobile applications, web portals, dealership systems, cloud APIs, charging infrastructure and third-party suppliers may all provide indirect pathways into the automotive ecosystem.
The possible consequences range from inconvenience to physical danger. A malicious update could disable digital services, collect location information, drain a battery, interfere with charging or make a vehicle temporarily unusable. In a more serious scenario, attackers might attempt to reach systems connected to acceleration, steering, braking or power management.
Cybersecurity in this context is therefore not just a data-protection issue. It is a road-safety issue.
The Norwegian Bus Test
Concerns about remote vehicle access attracted international attention after Norwegian public transport operator Ruter tested two electric buses in an isolated underground facility in 2025.
The company examined a newly delivered bus made by China’s Yutong and an older vehicle produced by Dutch manufacturer VDL. According to Ruter’s findings, the Yutong bus allowed manufacturer access for software updates and diagnostics, including access involving its battery and power-management systems. The operator concluded that the connection could theoretically be used to stop the bus or make it inoperable.
There was no evidence that the manufacturer had actually interfered with the buses. The test nevertheless demonstrated how legitimate maintenance capabilities could create security and national-resilience concerns when remote access is insufficiently controlled. Ruter subsequently announced stricter cybersecurity requirements and additional protections against unauthorized activity.
The findings also prompted scrutiny in Denmark and the United Kingdom. Importantly, the underlying issue is not exclusive to vehicles from one country. Any connected vehicle may be vulnerable when manufacturers, suppliers or attackers have excessive access to critical systems.
For privately owned cars, an attack might affect individual drivers. For buses, delivery fleets, emergency vehicles or other public infrastructure, a shared vulnerability could disrupt transportation across an entire city or region.
Why Eliminating OTA Updates Is Not the Answer
Despite these risks, abandoning OTA technology would not necessarily make vehicles safer.
Connected cars require security patches throughout their operating lives. Without a remote update mechanism, manufacturers may have to depend on dealership visits or traditional recalls. That approach can delay critical fixes, particularly when drivers ignore recall notices or cannot quickly reach a service center.
The safer approach is to design OTA systems so that every update is authenticated, carefully limited and recoverable.
Updates should be cryptographically signed so that a vehicle accepts software only from an authorized source. Secure-boot technology should verify the software before it runs. Safety-critical networks should be separated from infotainment and other internet-facing systems, reducing the possibility that a breach of a convenient feature becomes a compromise of vehicle controls.
Manufacturers should also use staged deployments rather than sending an update to every vehicle simultaneously. A new version can first be tested on a small group, monitored for abnormal behavior and then expanded gradually. Vehicles need a safe rollback mechanism so they can return to a previously verified version when an update fails.
Local operators should retain the ability to isolate vehicles from external networks, particularly in public transportation and critical fleets. Detailed system logs, continuous monitoring, independent security testing and transparent vulnerability-disclosure programs are also necessary.
Supply-chain oversight is equally important. Automakers may integrate software from hundreds of vendors, and they cannot secure an update system without knowing what code and components are inside their vehicles. A detailed software bill of materials can help manufacturers identify which models are affected when a supplier discovers a vulnerability.
Standards Are Emerging, but Implementation Matters
International standards already provide a foundation for improving automotive cybersecurity.
UN Regulation No. 156 establishes requirements for vehicle software updates and manufacturers’ software-update management systems. ISO/SAE 21434 addresses cybersecurity risk management throughout the vehicle lifecycle—from design and development to production, maintenance and eventual decommissioning.
In the United States, the National Highway Traffic Safety Administration recommends protecting the integrity of OTA updates, update servers, transmission channels and the overall installation process. Its guidance also tells manufacturers to consider compromised servers, insider threats, interception attacks and weaknesses in communication protocols.
Standards, however, are only as effective as their implementation. Automakers must treat cybersecurity as a continuous responsibility rather than a certification exercise completed before a vehicle enters production. Cars may remain on the road for 15 years or longer, while cyber threats can change within weeks. Manufacturers therefore need long-term support policies, rapid incident-response capabilities and clear commitments about how long each vehicle will receive security updates.
Cybersecurity Is Now Part of Vehicle Safety
OTA technology represents one of the automotive industry’s most useful innovations. It can reduce maintenance costs, accelerate repairs and allow manufacturers to respond rapidly to software vulnerabilities. But it also transforms every connected vehicle into a remotely reachable device.
The central question is not whether cars should receive wireless updates. It is whether automakers can build update systems that drivers, businesses and governments can trust.
As vehicles become increasingly software-defined, cybersecurity must be treated with the same seriousness as brakes, airbags and structural integrity. An update should never be installed merely because it reaches the vehicle. It should be accepted only after the vehicle can verify where it came from, what it will change and whether it can be safely reversed.
The future of connected transportation will depend not only on what software can do, but also on how securely that software reaches the road.