logo
Why automakers are reluctant to discuss EV charger cyber risks

Why automakers are reluctant to discuss EV charger cyber risks

Yahoo11-03-2025

Automakers are reluctant to discuss their cybersecurity efforts in the electric vehicle charging infrastructure sector because doing so would expose potential weaknesses and invite scrutiny, according to an executive at an automotive cybersecurity specialist.
'No automaker wants to be the one to say, 'We have a problem here.' That immediately raises concerns about liability and consumer trust,' said Giuseppe Serio, who is responsible for global and strategic initiatives at Upstream.
Cybersecurity incidents against automotive and smart mobility targets surged 39 percent to 409 in 2024, according to Upstream.
The company created its report on the problem by analyzing academic research, verified social media accounts of government law enforcement agencies, the Common Vulnerabilities & Exposures (CVE) database and media coverage of the attacks. Upstream's analysts also monitor the deep and dark web to track threat actors operating behind the scenes of automotive cyberattacks, the company said in its report.
There were on average 34 incidents a month last year involving the two sectors across Europe, the U.S. and China, according to Upstream.
In Europe, Germany experienced the highest number of incidents at 31. France followed with 14 attacks, while the U.K. had 16 incidents. Italy and Spain also saw notable activity, with 12 and 10 attacks, respectively, according to Upstream's data.
As EV adoption accelerates, so do the risks — ransomware attacks on smart mobility infrastructure surged, contributing to an overall 38 percent increase in documented incidents.
Sign up for the Automotive News Europe Focus on Electrification newsletter, a weekly wrap-up of the latest electric vehicle news, including interviews and global EV sales data.
A cyberattack on a Lithuanian EV charging system shut down operations for hours, with attackers stealing data from 20,000 customers, according to Vilnius-based new portal Delfi.
Upstream's Serio said automakers prefer to focus on security in areas where they have direct control, such as in-vehicle systems and telematics, rather than openly addressing risks associated with third-party charging networks.
'Once you acknowledge a security risk, you are expected to have a solution,' he said. 'But in the case of EV charging, automakers don't fully own the infrastructure, making it difficult to offer definitive assurances.'
Serio added that public disclosure of cybersecurity vulnerabilities could impact regulatory discussions and industry partnerships.
'If an automaker admits to a security gap, regulators might demand immediate action, which could disrupt product timelines and require costly fixes,' he said.
Instead, several automakers prefer to work behind the scenes, collaborating with charge point operators and industry groups to strengthen security without drawing public attention.
A statement from BMW provided to Automotive News Europe said ensuring customer payment data is adequately secured for charging transactions is a shared responsibility between automakers, electric mobility service provider and charge point operators.
It noted that BMW Group's entire battery-electric vehicle range fulfills the highest safest standard to date.
'BMW conducts its own penetration testing, where its cybersecurity experts attempt to hack the vehicles to uncover vulnerabilities,' the statement continued.
BMW said its 'security by design' principle means automotive security is implemented continuously throughout the vehicle's life cycle, starting from the design phase — an approach now legally required in many countries.
'BMW collects anonymized live data from its vehicles, provided the customer has given consent,' the statement said. 'This enables BMW to identify anomalies and take appropriate action.'
Since 2019, BMW vehicles have been fully updatable over the air, allowing BMW to fix critical cybersecurity vulnerabilities quickly and appropriately throughout the vehicle's life cycle.
A similar statement provided to ANE from Mercedes-Benz noted the company received cybersecurity management system certification in 2021 from the German motor transport authority (KBA).
'All our architectures meet the requirements and are or will be certified in accordance with UN R155 in time,' it said. 'We map the potential cyberthreats, we review future products and services and then design the right architecture and technologies to mitigate prioritized threats.'
Serio said Upstream's findings underscore the urgent need for stronger cybersecurity protections, particularly in EV charging networks, noting security remains an afterthought in the race for market expansion.
'New technologies often prioritize growth over security, and EV charging infrastructure is no exception,' he said.
The rapid adoption of charging networks has created a fragmented ecosystem with multiple stakeholders — including energy providers, charge point operators, automakers, and payment processors —leading to vulnerabilities attackers can exploit.
Gartner Vice President of Research Pedro Pacheco said the EV charging infrastructure presents significant cybersecurity risks, with denial-of-service attacks being the most common threat.
'If a charger loses connectivity, it often becomes unusable, meaning drivers cannot complete payments or access charging services,' he said.
Other threats include data theft and the potential for attackers to use charging stations as entry points into vehicle systems.
What is the biggest enemy of security? Complexity
Serio said the complexity of the charging ecosystem itself is a major risk factor.
'There is a saying in cybersecurity: The biggest enemy of security is complexity,' he said.
Each component in the charging process, from the vehicle interface to the back-end payment system, represents a potential entry point for attackers.
If even one element is weak, it could compromise the entire system.
'Attackers look for the weakest link,' he said. 'A single vulnerability can allow bad actors to hijack sessions, steal payment data, or even disrupt the electrical grid,' Serio said.
Regarding accountability, he noted that while multiple entities are involved, charge point operators have primary responsibility for security.
'Since they control access to the charging stations, charge point operators are the ones that must ensure security across the entire system,' he said.
However, automakers also have a role to play by securing vehicle-side connections and ensuring safe communication protocols between the EV and the charger.
'Automakers must recognize that charging stations introduce a new attack vector, much like telematics systems or connected infotainment units,' he said.
Serio stressed the urgent need for dedicated regulations.
'There is no global cybersecurity standard for EV charging infrastructure,' he said, noting that while automotive cybersecurity regulations exist, similar measures for charging networks remain insufficient.
The U.K. is one of the few countries treating EV charging as critical infrastructure, a model Serio believes should be replicated globally.
'We haven't yet seen the big epiphany moment in EV charging security like we did in the auto industry,' he said. 'But it's only a matter of time before a major incident forces regulators to act.'
Gartner's Pacheco highlighted the role of regulations such as the EU's NIS2 directive, which mandates cybersecurity protections for critical infrastructure, including EV charging networks.
'The main goal of this regulation is to ensure that critical infrastructure remains resilient in the face of cyberattacks,' he said.
Pacheco said automakers and charge point operators often take a reactive rather than proactive approach to cybersecurity.
'Like most risk management issues, cybersecurity tends to receive more attention after a major incident,' he said.
The biggest challenge, he said, is defending against zero-day attacks — new and previously unknown threats.
He said proactive cybersecurity strategies, strong industry collaboration, and a culture of cyber awareness are essential to preventing catastrophic disruptions to EV charging infrastructure.
'Once an entirely new cyberattack emerges, organizations must act immediately to update their security management systems,' Pacheco said.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

New Mexico Foundation's new CEO makes quite an impression
New Mexico Foundation's new CEO makes quite an impression

Yahoo

time29 minutes ago

  • Yahoo

New Mexico Foundation's new CEO makes quite an impression

One of my tasks as the business reporter at The Santa Fe New Mexican is to keep tabs on what's happening in the state's nonprofit community, which explains why I spoke last week with Justin Kii Huenemann, the new president and CEO at the New Mexico Foundation for a profile in our June 4 edition. Justin Kii Huenemann Justin Kii Huenemann, the new president and CEO of the New Mexico Foundation, says the organization faces unique challenges and opportunities as the only statewide community foundation in New Mexico. The Santa Fe-based community foundation lists collaboration and sustainability as two key elements in its core values, and it is clear that Huenemann plans to continue emphasizing both during his tenure. Citing his upbringing on the Navajo Nation near Tsaile, Ariz., he talked about how the landscape of that area has shaped his perspective on the world as an adult. Not surprisingly, he said he tends to take the long view in his approach to managing organizations, especially those that have experienced a recent leadership void. 'The sky's not falling,' he said, describing the message he likes to convey to his new staff in those situations. Huenemann had to hit the ground running in his new position, but he nevertheless made time to spend at least an hour conversing with each member of his staff within two weeks of his arrival. He described himself as an active listener, adding that the most important job of his foundation is to avoid creating barriers for its partners. But the thing he said that impressed me the most was when he described community foundations as 'a privileged environment within a privileged sector,' a reminder to himself to remain cognizant of how different a given situation can look to someone on the outside. As someone who spent the last 10 years living just off the Navajo Nation in San Juan County, a remote and often overlooked corner of New Mexico, I felt like I understood well what he was trying to say. And I have little doubt that Huenemann's term at the foundation will be a successful one.

Proposed RENT Ordinance aims to rein in unfair rental practices
Proposed RENT Ordinance aims to rein in unfair rental practices

Yahoo

time30 minutes ago

  • Yahoo

Proposed RENT Ordinance aims to rein in unfair rental practices

Jun. 9—The Albuquerque City Council is set to consider sweeping new rules that would overhaul the rental process citywide, aiming to protect tenants from hidden fees, housing instability and unresponsive landlords. The bill, known as Renter's Empowerment and Neighborhood Transparency (RENT) Ordinance, would enshrine several protections around almost every part of the renting experience. The bill addresses nearly all aspects of the rental process and would impact every landlord and renter in the city. Statistics from the American Community Survey show that about 44% of households in Albuquerque rent. But it's far from guaranteed to pass. "I think that this council has proven in the past that they're not interested in helping renters very much," said Councilor Tammy Fiebelkorn, who is sponsoring the bill on behalf of the mayor's office. "But recently, we did get two pieces of tenant protections passed." Those two pieces were an ordinance mandating landlords provide cooling for tenants and a bill that created a code enforcement position to respond directly to renters' issues. The bill also faces opposition from landlord advocates. "While the stated intent of this legislation may be to protect tenants, in practice, it burdens responsible landlords, increases operational and legal risk, and would discourage housing investment in Albuquerque," said Alan LaSeck, executive director of the Apartment Association of New Mexico. LaSeck went on to say the proposals ignore the realities of managing rental housing and would lead to reduced availability, higher costs and greater conflict. "Rather than fostering cooperation between tenants and owners, they threaten to drive housing providers out of the market, shrinking our housing supply, increasing rents and worsening the very problem we're trying to solve," LaSeck said. What's in the RENT Ordinance? Shanna Schultz, policy and government affairs administrator for the city, said the bill comes at a time when Albuquerque continues to grapple with a housing crisis. A 2024 Denver-based Root Policy Research report, titled "Albuquerque Region Housing Needs Assessment," found a significant shortage of units for low-income renters. The same report found that residents were spending more than a third of their monthly income on housing and that occupied units, such as apartments and single-family homes, often had more residents than rooms available. "I think we know that building more homes is essential, but that's not enough on its own. It's not the only tool in the toolkit," Schultz said. "We also need to protect the people who are already living in homes." Schultz, who authored the policy proposal, noted that the bill's transparency provisions were among its most significant changes. The RENT Ordinance would require landlords to disclose all costs of a rental agreement in plain language in their published listings. That includes anything on a background check that could disqualify an applicant, as well as minimum credit score or income requirements. "This can help renters avoid surprise charges and do things like budget more confidently, which is very important in this economy right now," Schultz said. There are several other key provisions, including those around repairs. The ordinance grants the tenant the right to arrange for necessary maintenance by a licensed and insured professional. The tenant can also deduct the cost of the repair from their rent payment or receive reimbursement from the landlord when the landlord fails to make a repair. Landlords would also be prohibited from charging fees and additional rent for companion animals, defined in the bill as typical pets not used for commercial purposes. In all, the bill makes changes to rules around security deposits, relocation assistance, the rental application process, evictions, credit reporting requirements, move-in and move-out procedures and methods of payment. It's set to go before the Land Use, Planning and Zoning Committee on June 11. If it advances, it's unlikely to go before the full council until at least August, Schultz said. "Why would landlords also be interested in this? And I think the answer to that is that clear rules reduce confusion and conflict," Schultz said.

London-listed Spectris soars 20% on fresh takeover interest from Advent
London-listed Spectris soars 20% on fresh takeover interest from Advent

Yahoo

time40 minutes ago

  • Yahoo

London-listed Spectris soars 20% on fresh takeover interest from Advent

-- Shares of Spectris PLC (LON:SXS) surged by over 20% in London trading following a Bloomberg News report that private equity firm Advent is considering a takeover of the UK-based precision and testing equipment maker. The potential acquisition comes as Spectris shares had previously dropped about 18% this year, valuing the company at around £2 billion ($2.8 billion). Spectris, which employs 7,600 people across more than 30 countries, specializes in developing high-tech instruments, testing equipment, and software for various industries, including life sciences, automotive, electronics, and semiconductors. Asia is a significant market for Spectris, contributing to about 36% of its revenue last year, with Europe and North America following closely. This news of potential acquisition interest comes after a failed takeover attempt by Bain Capital and Advent International in 2018, which was abandoned amid the political uncertainties brought on by Brexit. Under the leadership of CEO Andrew Heath, Spectris has been streamlining operations since 2018, focusing on its core business in the scientific and dynamics divisions. This strategic shift followed a decline in first-quarter sales due to weakened demand in key sectors such as automotive and semiconductors. Despite the challenging market conditions, Spectris has been optimistic about mitigating the impacts of tariffs and achieving strong growth in adjusted operating profit by 2025. Related articles London-listed Spectris soars 20% on fresh takeover interest from Advent AppLovin would be more valuable without its 1P games, Morgan Stanley argues Morgan Stanley downgrades Lululemon on weak US growth outlook

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store