Escalated Cybersecurity Risks from the Spread of Automotive OTA
Concerns are growing over the vulnerability of vehicle systems to cyberattacks as over-the-air (OTA) software update technology rapidly expands in the automotive industry. Experts warn that enhanced security audits and policy interventions are urgently needed, with new cybersecurity concerns emerging around transportation infrastructure. OTA enables wireless delivery of software, firmware, patches, and data to internet-connected devices. Tesla introduced OTA updates to its Model S in 2012, and the technology has since spread across the automotive industry. Researchers highlight risks beyond data privacy, noting potential threats to vehicle control systems by external actors, prompting investigations in Norway, Denmark, and the UK. A U.S. think tank warned that automotive industry protection is critical to limiting foreign government cyber espionage capabilities, suggesting restrictions on foreign hardware/software, additional security reviews, and expanded data disclosure requirements. Practical vulnerabilities were revealed when Norway's Luter Bus Company discovered potential OTA risks in two buses, including theoretical capabilities for manufacturers to disable vehicles. The UK and Denmark subsequently launched their own investigations, with the UK Transport Department collaborating with the National Cyber Security Centre. While the buses in question were manufactured by Chinese firm Wutong, officials emphasized the issue is not limited to specific manufacturers or countries.