Automotive Suppliers Turn Ransomware Into Sector-Wide Risk

The real problem is not just one company outage. Automotive suppliers and data providers sit inside the operating fabric of OEMs and fleets, so a ransomware hit can interrupt valuations, specifications, and downstream workflows across multiple customers at once. Halcyon says ransomware made up 44% of attacks on carmakers in 2025 and more than doubled over the year. Autovista, a UK-based vehicle-data provider, is now recovering from a ransomware incident affecting systems in Europe and Australia, with employee email access temporarily disrupted and no recovery timeline yet. That combination points to a sector where third-party access and cloud-connected services widen the blast radius. Even when the initial target is a supplier, the operational damage can spread across manufacturers, transportation firms, and the partners that depend on their data feeds.

Part of the PlainSec briefing for 2026-04-17

Sources