Modern cars are no longer machines that stay the same after they leave the showroom. Increasingly, they’re becoming software-defined vehicles that receive new features, bug fixes, and security patches wirelessly, much like smartphones. But while over-the-air (OTA) updates have made vehicle maintenance easier and cheaper, cybersecurity experts are warning that the same technology could also become one of the automotive industry’s biggest security challenges.
Researchers and policymakers are now calling for stronger oversight as connected vehicles become increasingly dependent on remote software updates. Their concern isn’t just about hackers stealing personal data. It’s about someone potentially interfering with the operation of a moving vehicle.
The convenience of wireless updates comes with new risks
OTA technology allows manufacturers to remotely deliver software updates, firmware upgrades and security patches without requiring owners to visit a dealership. Tesla popularized the concept more than a decade ago when it began rolling out wireless updates for the Model S in 2012. Today, the feature has become commonplace across premium and mainstream vehicles alike.
For consumers, the advantages are obvious. Carmakers can quickly fix software bugs, improve battery management, add new infotainment features or even enhance driving performance without issuing expensive recalls. According to a CNBC report quoting Siraj Ahmed Shaikh, Professor of Systems Security at Swansea University, OTA updates have become an attractive alternative to traditional servicing because they reduce costs and shorten deployment times. Instead of waiting for scheduled maintenance, manufacturers can address issues almost instantly.

However, the same always-connected architecture that enables these updates also creates a larger attack surface. Cybersecurity analysts argue that internet-connected vehicles effectively function as rolling computers. If attackers were to compromise the update infrastructure or gain privileged access to vehicle software, the consequences could extend well beyond data theft.
Gabriel Lim, Senior Analyst at Singapore’s S. Rajaratnam School of International Studies, told CNBC that the issue represents a potential national security concern. Beyond questions surrounding user privacy, governments are increasingly examining whether foreign manufacturers or hostile actors could theoretically interfere with vehicle systems remotely. Those concerns have prompted several countries to reassess how connected vehicles should be regulated.
Governments are beginning to take the threat seriously
The debate intensified after Norwegian public transport operator Ruter conducted security tests on electric buses last year. The company reported that one vehicle’s battery and power management system could be accessed remotely through a mobile network connection. In theory, it concluded, the manufacturer could disable or immobilize the bus remotely.
Although the investigation focused on buses manufactured by Chinese company Yutong, experts caution that the problem isn’t unique to any single automaker or country. Instead, they see it as an industry-wide challenge tied to the growing adoption of connected vehicle platforms. The findings prompted authorities in both the United Kingdom and Denmark to launch their own investigations, with the UK’s Department for Transport working alongside the National Cyber Security Centre to examine potential vulnerabilities.

Similar concerns are also beginning to shape policy discussions in the United States. Earlier this year, the American Enterprise Institute argued that protecting connected vehicles from foreign espionage should become a strategic priority. The think tank recommended stronger security reviews, greater transparency around vehicle data collection, and tighter restrictions on certain foreign-made automotive software and hardware.
The implications stretch well beyond passenger cars. OTA technology is increasingly finding its way into buses, commercial fleets, rail systems, ships, industrial robots and drones. As more critical infrastructure becomes remotely updateable, experts say cybersecurity can no longer be treated as an afterthought. Wireless updates are undoubtedly making vehicles smarter and more capable. But they’re also changing the definition of automotive safety. In the software-defined era, protecting a car increasingly means protecting the code running inside it, because the next cyberattack may not target your laptop or smartphone. It could target the vehicle you’re driving.

