Cybersecurity & Data Security Research: Intelligent Connected Vehicles Enter the Era of “Systematic Offense-Defense and AI-Defined Security”.
Centering on the panorama of intelligent connected vehicle cybersecurity and data security in 2026, this report analyzes core topics including vehicle full-domain attack scenarios and more attack surfaces brought by AI, vulnerability status analysis, full-link protection system, data classification & grading, and cross-border compliance. Furthermore, it systematically presents cutting-edge industry progress in compliance certification, technology implementation, and supply chain security governance through security protection practices of 41 enterprises of diverse types, covering 7 data security companies (Agile Technology, Eagle Cloud, etc.), 7 representative OEMs (Seres, NIO, BYD, etc.), 8 automotive security hardware suppliers (UniSentry Intelligent Technology, ThinkTech, etc.), 7 automotive security software suppliers (Software Security Technology, Anban Tech, etc.), and 12 Internet of Vehicles (IoV) security service providers (Vecentek, Callisto Technology, GoGoByte, etc.). Meanwhile, the report reveals new risks introduced by AI deployment on vehicles such as supply chain poisoning and prompt hijacking, summarizes security solutions for intelligent connected vehicles, and forecasts industrial development trends.
Highlights
?Compliance upgrade driven by policies: From passing inspections to systematic operation
?Frequent supply chain breaches: Security governance must cover full domains and full lifecycle
?AI as a double-edged sword: Attack surfaces extend to the intent layer; defense requires “countering AI with AI”
?Cybersecurity evolves from passive response to active threat hunting
?Data security shifts from privacy compliance to full-link governance; cross-border data management becomes a mandatory task
?Security needs to be transformed from a cost center into a core competitive edge
In 2026, the intelligent connected vehicle industry stands at a critical turning point. On one hand, the full enforcement of national mandatory standards represented by GB 44495/44496 marks the official transition of the industry from compliance exploration to in-depth compliance management. On the other hand, the deployment of large AI models on vehicles and normalized cross-border data flows are rapidly expanding vehicle attack surfaces, posing unprecedented security challenges. For automakers, simple passive compliance or single-point defense can no longer address complex cyber threats; transforming into systematic offense-defense operations featuring full-lifecycle, full-supply-chain, and AI-driven active defense has become inevitable.
I. Compliance Upgrade Driven by Policies: From "Passing Inspections" to Systematic Operation
In 2026, China’s regulatory framework for automotive cybersecurity and data security has formed a closed loop. Based on mandatory standards including GB 44495-2024 Technical Requirements for Vehicle Cybersecurity and GB 44496-2024 General Technical Requirements for Software Update of Vehicles, plus the implementation of the Guidelines for Outbound Transfer Security of Automotive Data (2026), compliance requirements for automakers have been upgraded from previously recommended reference standards to enforceable bottom-line rules. Enterprises need to comprehensively reshape their security strategies, organizational structures, and operational workflows.
Regulation is also enforced through heavy fines. In May 2026, European data protection authorities imposed a fine of 100 million euros (approximately 801 million RMB) on the operator of ride-hailing app Yango for transferring users’ personal data to Russia without implementing protective measures required by EU laws. In the same month, General Motors was fined nearly 90 million RMB for collecting and selling driving data without user consent, marking the largest penalty since the enactment of the California Consumer Privacy Act. The logic behind these penalties is clear: data is not the asset taken or sold arbitrarily by automakers.
Faced with stringent regulatory pressure, leading automakers are accelerating the shift from passive compliance to active risk prevention and control. Seres serves as a typical example. It has built an in-depth defense system covering "cloud-pipe-device-chip", and obtained China’s first batch of Automotive Data Security Management System Certification and Level 3 National Data Security Maturity Model (DSMM) Certification, proving its industry-leading systematic security capabilities. Meanwhile, with its self-developed "iDDog" intelligent security platform, BYD follows a three-step logic of "diverting, purifying, and activating data" to break down data silos and build high-quality data infrastructure. It has deployed three major AI agents to boost efficiency in security operations, internalizing compliance requirements into robust operational capabilities. The "5 Compliance Inspections" initiated by the China Association of Automobile Manufacturers (CAAM) continue to advance; 49 vehicle models from 13 enterprises in the third batch and 43 vehicle models from 9 enterprises in the fourth batch have passed inspections. Requirements such as anonymization of human facial data collected outside vehicles and in-vehicle processing of cockpit data are becoming standard configurations in the industry.
Facts have proven that compliance is merely a starting point. Transforming security capabilities into sustainable operational internal strengths constitutes the competitive edges for enterprises to navigate industrial cycles.
II. Frequent Supply Chain Breaches: Security Governance Must Cover Full Domains and Full Lifecycle
If one were to ask for the most painful lesson of the automotive industry in 2025, the answer would likely be: Attackers no longer attempt brute-force intrusions, but infiltrate through trusted partner channels. The supply chain of intelligent connected vehicles is extremely complex; a single vulnerability in any link may trigger catastrophic consequences analogous to a dike collapsing due to an ant’s nest.
In March 2025, hacker "Rey" leaked about 700 internal Jaguar Land Rover documents on the dark web, including source code, development logs, and employee databases—this was merely a prelude. In August of the same year, hacker group "Scattered Lapsus$ Hunters" intruded the company’s global production systems, forcing full suspension of UK manufacturing plants and mandatory leave for 33,000 employees. Also in August, a design subsidiary under Nissan suffered a ransomware attack by threat actor "Qilin", resulting in the theft of 4TB of core design data. Cloud storage service provider Snowflake was breached, causing collateral damage to 165 downstream enterprises including auto parts retailer Advance Auto Parts. By late 2025, global wiring harness giant Yazaki Group had 350GB of data stolen by ransomware threat actors, containing complete documentation for components supplied to BMW and Nissan. The case of Thai OEM TRU is even more typical: 1TB of data was stolen, ESXi servers were targeted for encryption, ERP and logistics systems suffered widespread offline outages, and partial production lines were forced to switch to manual scheduling.
Collectively, these incidents reveal three clear shifts in attack patterns:
Target physicalization: Threat actors have escalated from data theft to intellectual property exfiltration and direct production paralysis;
Supply chain-oriented attack paths: Over half of all incidents are executed indirectly through cloud service providers, IT subsidiaries, and third-party suppliers, rendering supply chains the weakest link;
Targeted ransomware: Malicious actors specifically target high-value data such as design blueprints.
These exposed vulnerabilities have driven upgrades to industry countermeasures. Automakers are universally recognized as the primary responsible parties for supply chain security, transferring accountability to Tier 1 suppliers by signing Cybersecurity Interface Agreements (CIA). ISO/SAE 21434 certification has become a mandatory entry threshold for Tier 1 suppliers; without this "security letter of credit", enterprises cannot access core supply chains. For businesses targeting European markets, TISAX certification is an unavoidable requirement. Nevertheless, the overall landscape remains characterized by "leading OEMs take initiative while small and medium-sized suppliers lag behind". For small and medium Tier 2 and Tier 3 suppliers, most automakers only conduct documentary audits, with extremely low coverage of on-site verification and incomplete traceability chains.
Building a full-domain, full-lifecycle supply chain security system has been an industry consensus. Geely provides an exemplary benchmark. It constructed one of China’s first national CNAS-accredited IoV cybersecurity laboratories, and conducts over 200 regular test items across 12 core testing dimensions including system security, communication security, and data security from an attacker’s perspective, feeding research outcomes back into forward R&D workflows. In December 2025, Geely officially launched its Global Full-Domain Security Center and the Full-Domain Security 2.0 technical system. The 2.0 system expands its perspective from "whole-vehicle security" to an ecological view of "human-vehicle-road-cloud-satellite". While retaining four core security domains: life safety, health safety, property safety, and privacy safety, it iterates and upgrades nine major security systems to build a full-scenario, full-lifecycle protection network.
Meanwhile, the granularity of security acceptance evaluations for supply chain manufacturers is continuously refined, with several rigorous requirements implemented: Third-party components must not contain unaddressed high-risk vulnerabilities disclosed more than 6 months prior; high-risk vulnerabilities must be fixed and re-verified within 72 hours; OTA update packages must be signed with OEM proprietary keys, dual signatures by suppliers and OEMs are required in certain scenarios, and vehicle terminals must identify and intercept upgrade packages with missing, forged, or tampered signatures. For instance, Seres has streamlined its 300 Tier 1 suppliers down to 100, establishing deep embedded security collaboration with CATL and Bosch to narrow its security management radius to controllable scope. At the underlying hardware layer, for example, ThinkTech’s Alioth TTA8 series MCUs integrate ASIL-D functional safety and EVITA FULL cybersecurity, filling domestic gaps in chassis domain master control chips and guaranteeing independent controllability and security of supply chains at the source.
The essence of supply chain security lies in extending the security boundary from "my vehicle" to "every line of code, every chip, and every supplier within my vehicle"—full domain and full lifecycle coverage are indispensable, with no links to be omitted.
III. AI as A Double-edged Sword: Attack Surfaces Extend to the Intent Layer, and Defense Requires “Countering AI with AI
The deployment of large models on vehicles brings not only smarter cockpits but also an entirely new attack dimension. AI-specific risks including supply chain poisoning, prompt hijacking, and excessive proxy are rapidly migrating to vehicle terminals. When vehicle large models connect tool chains for navigation, payment, charging, and vehicle control, attack chains originally limited to cloud chatbots can be intactly ported to vehicles. Particularly within MCP-connected ecosystems, high-risk attack vectors such as tool poisoning directly threaten IVI systems running Linux and Android.
Novel agents represented by OpenClaw excel at forming a closed loop from intent understanding to task completion thanks to their high-level system privileges. However, in vehicle environments, this translates to a persistent digital entity within the system that holds partial access rights to vehicle data and permissions to invoke vehicle control commands. Prompt injection can induce agents to execute unintended operations; a tampered third-party navigation plugin may act as a persistent Trojan horse leaking driving habits; benign hallucinations in Q&A scenarios can escalate to dangerous operations such as critical data deletion in proxy scenarios. What is even more thorny is the regulatory conflict: standards including ISO 26262, UN R155/R156, and GB 44495 mandate deterministic, predictable, testable, and traceable system behavior, while agents inherently feature non-determinism and emergent characteristics. The industry’s solution is "empowerment rather than full delegation": deploy permission sandboxes and functional fences to restrict agents to infotainment and other low-risk domains; all vehicle control requests must be mandatorily arbitrated by a security middleware layer; high-risk operations must be confirmed via HMI, ensuring humans remain within the loop for all safety-critical decisions.
As attack surfaces evolve, defense mechanisms must advance in tandem. The industry’s solution is straightforward: counter AI with AI.
Faced with the "spear" brought by AI, the industry must forge an even sharper "shield". For example, Anban Tech centers its new intelligent connected vehicle security paradigm on "AI large model-driven agent protection + vehicle communication protocol security + closed-loop supply chain security". It shifts security capabilities from traditional post-hoc patching to full-lifecycle proactive governance:
Leverage large models to parse full vehicle EE architecture documents, cross-model databases, and VSOC asset inventories via natural language, automatically identifying ECUs, sensors, communication interfaces, and other critical assets to map asset correlation frameworks. The LLM-powered intelligent TARA platform automatically generates security targets, security requirements, threat scenarios, and attack paths, enabling automated, visualized risk assessment.
During risk remediation, the platform combines impact severity, attack feasibility, and risk rating matrices to automatically generate remediation decisions and push work orders, forming an operational workflow of "AI detection – AI analysis – AI decision – AI closed-loop", drastically shortening vehicle security assessment cycles.
QAX AISOC is a representative example of this approach. It embeds 8 agents responsible for eight operational links: data collection, threat detection, intelligent judgment, intelligent investigation, intelligent response, incident eradication, optimization feedback, and report generation. Based on the OODA loop, it establishes an autonomous defense system transforming security operations from "human-initiated threat hunting" to "automated threat notification". Practical data demonstrates that a global luxury automaker utilizing AISOC has reduced the analysis and assessment time for a single alert to less than 9 seconds, with valid alert identification accuracy reaching 93.1%, a 2.7x improvement over traditional manual mode.
TARA, a traditional security analysis link, is also being rebuilt with AI. GoGoByte DefenseWeaver embeds the GoGoAI Agent, incorporating all new risk vectors such as models, training and inference data, prompt entry points, knowledge bases and tool invocation chains into the scope of TARA. Its judgment holds that risks stem not merely from code vulnerabilities, but also from misleading models, contaminated data and misused tools. This tool serves clients including FAW Bestune and Luxshare Precision, as well as national inspection institutions like CATARC, China Merchants Testing Vehicle Technology Research Institute and the CEPREI, boosting TARA efficiency by 80%. Callisto S3-TARA adopts a different approach: over ten agents work collaboratively to screen optimal solutions from 16 candidate Chains of Thought (CoT), supported by a data foundation built upon more than 100,000 causal chain datasets, over 3 million security scenario samples and over 1 million knowledge base Q&A pairs.
Automakers haven't been sitting idle, either. BYD’s iDDog platform implements three AI agents targeting email phishing, terminal data leakage, and abnormal traffic, cutting security incident response time from 45 minutes to 5 minutes. Li Auto collaborated with Volcano Engine to develop an AI intelligent assistant capable of automatically creating work orders, scanning code, remediating vulnerabilities, and conducting re-verification upon receiving instructions in Feishu group chat, enabling one-stop closed-loop resolution with human authorization. AI native has transitioned from conceptual slogans to daily security operations.
IV. Cybersecurity Evolves from Passive Response to Active Threat Hunting
Within the cybersecurity domain, traditional passive defense idea can no longer keep pace with rapidly evolving attack vectors. 206 automotive security incidents and 238 newly discovered vulnerabilities were recorded in 2025 alone. Threat actors have escalated objectives from data theft to intellectual property exfiltration, and even direct paralysis of production and manufacturing operations. Automakers therefore must build combat-ready cybersecurity systems with active threat hunting capabilities covering threat detection, analysis, response and remediation.
The solution proposed by defenders lies in systematic defense. Seres deploys a multi-layer in-depth defense architecture of "cloud-pipe-device-chip", collaborating with QAX to deploy intrusion detection systems across CAN bus, on-board hosts, and Ethernet layers. Its VSOC platform monitors about 200,000 vehicles and issues "cybersecurity compliance certificates" for vehicle models exported to EU. Its intelligent security system covers over 200 vehicle usage scenarios and more than 400 security functions. In April 2026, it released Security 4.0, evolving from passive and active safety to intelligent security.
Professional security providers have also upgraded their toolkits. ACT VSOC+, a next-generation intelligent connected vehicle security operation platform, embodies this philosophy. Powered by an AI streaming computing engine, it delivers a 500% performance improvement in threat detection, constructs a vehicle security digital twin modeling over 2,800 vehicle signals, and enables triple precise threat localization across ECUs, signals, and scenarios, shortening threat detection and response cycles from day-level to minute-level.
At the underlying protocol security layer, TICPSH’s SmartRocket TestSec automated intelligent fuzzy penetration testing tool executes deep fuzzy attacks and penetration testing against mainstream vehicle protocols including SOME/IP, DoIP, and CAN/CAN FD to proactively uncover latent vulnerabilities, shifting the security defense line forward to the R&D testing phase. UniSentry Intelligent Technology’s SecIC-HSM firmware serves nearly 30 OEMs, achieving AES throughput of 4.8Gbps on Infineon AURIX TC4X, enabling parallel execution of OTA update verification and secure on-board communication (SecOC) without interrupting CAN bus transmission. These solutions help automakers make the leap from mandatory compliance to proactive security.
Consensus has formed across OEMs and suppliers: isolated standalone security products cannot resolve systemic security issues, and multi-layer in-depth defense and active immune systems represent the correct solutions.
V. Data Security Shifts from Privacy Compliance to Full-Link Governance, and Cross-Border Data Management Becomes A Mandatory Task
Data is the "blood" of intelligent vehicles, with its security spanning the full lifecycle of collection, transmission, storage, utilization, sharing, and destruction. The unique characteristic of automotive data security is that data carries both privacy and compliance attributes while directly supporting perception training, map services, model iteration, remote operations, and accident traceability. Improper collection, transmission, utilization, or tampering of data carries consequences extending far beyond regulatory fines, potentially exerting adverse impacts on vehicle behaviors.
On February 3, 2026, eight ministries including the Ministry of Industry and Information Technology and the Cyberspace Administration of China jointly issued the Guidelines for Outbound Transfer Security of Automotive Data (2026). The guidelines categorize outbound data into three tiers: general, important, and sensitive, while defining nine exemption scenarios including quality assurance maintenance data, OTA update data, and security vulnerability remediation materials. Clear filing thresholds are established: enterprises must conduct cross-border data transfer security assessments if transmitting important data overseas, or sharing personal information of over 1 million individuals / sensitive personal information of over 10,000 individuals with foreign entities. For China’s automotive industry, which recorded a 65.3% year-on-year export growth in the first half of 2026, these guidelines eliminate the gray zone for cross-border data flows, shifting industry practices from tentative exploration to definitive compliance. Overseas regulation has simultaneously tightened: the 12-step GDPR compliance roadmap applies to export-focused OEMs; Japan’s revised APPI Act introduces profit-based penalty calculations for the first time; South Korea’s PIPA has entered a strict governance phase. Cross-border data flow governance has become a mandatory multi-jurisdictional compliance task.
Automakers have their own ways of responding. NIO’s Sentry Mode remote view function implements end-to-end encryption and real-time data desensitization, automatically blurring license plates and human faces, with footage even NIO itself cannot decrypt, making it China’s first OEM to deliver compliant remote view function. Its self-developed NPCC framework, the industry’s first device-cloud integrated AI agent security framework, enforces "immediate data erasure post-computation" for sensitive data. Leapmotor adheres to an in-vehicle processing principle: in-vehicle cameras only collect feature points for local computing without cloud uploads, with all transmission traffic protected via AES-256 end-to-end encryption. ZEEKR’s "Data Safe" system implements zero-trust tiered access control, activating data circuit breakers within 20 seconds upon detection of unauthorized abnormal access, with physical data destruction capabilities for storage media. Xpeng partnered with Alibaba Cloud to deploy post-quantum security algorithms on its new model P7, covering digital keys, remote vehicle control, and OTA for all vehicle modes.
Data security service providers have refined their solutions. Eagle Cloud Hub AI-DLP expands governance subjects from humans to dual entities of "human staff + AI staff", implementing unified identity management, consistent security policies, and standardized auditing for both, with refined control over data leakage vectors including external distribution, downloads, copying, and screen capture. Its clients include Geely Holding, Li Auto, Leapmotor, and Seres. Agile Technology’s EDLP solution features an innovative architecture with deep integration of encryption and DLP. Starting from the source of data, it builds a full closed-loop prevention and control system covering "identification – classification – encryption – access control – audit", ensuring the security of core commercial secrets such as design drawings and R&D data amid the AI era. In May 2026, Agile Technology just won a 5,000-node data security project bid from a leader in the automotive industry.
For cross-border data compliance, CATARC delivers a full four-step service workflow: path planning – risk assessment – policy formulation – assessment declaration, enabling OEMs to clarify complete data flow routes and implement preventable, controllable, traceable compliance.
VI. Security Needs to Be Transformed from A Cost Center into A Core Competitive Edge
With clear trends identified, how to implement engineering? Drawing on the practices of leading companies, there are several actions automakers should take immediately:
Embed systems into core workflows rather than treating them as superficial compliance documentation. Build full-lifecycle CSMS/SUMS systems centered on ISO/SAE 21434 standards, shifting TARA threat modeling forward to concept and design phases to realize security left-shifting. Mandate SBOM and code security requirements for suppliers, cascading security accountability down via Cybersecurity Interface Agreements (CIA).
Transform VSOC (Vehicle Security Operations Center) from a mere alert dashboard into a core operations hub. Concrete efficiency improvement measures are as follows: shift alert governance from volume reduction to root-cause closed-loop management by tagging all alerts with root causes; replace static risk grading with dynamic weighting models; cut the 15-minute manual analysis time for each alert via one-click context encapsulation. Develop scenario-based emergency response cards and deploy semi-automated SOAR (Security Orchestration, Automation and Response) playbooks for high-frequency scenarios to auto-preserve evidence and generate reports automatically. Build an underlying vehicle security data center to eliminate the need for operators to log into five or six separate systems just to retrieve a single VIN. At the team level, establish SOP libraries and knowledge bases, and replace annual large-scale drills with regular small-scale practice sessions.
Implement full-link data security engineering. Data classification and grading serve as the foundation, with encryption, desensitization, access control and cross-border monitoring as core operational tools. Adopt a four-step workflow for cross-border businesses: route planning → risk assessment → policy formulation → compliance declaration, shifting from ad-hoc project responses to normalized continuous operation.
Deploy AI in appropriate scenarios. Utilize AI TARA platforms to boost threat modeling efficiency, leverage AI SOC systems to reduce alert analysis overhead, and adopt digital twin technology to refine risk granularity, while enforcing permission sandboxes and functional fences for vehicle agents, retaining mandatory human approval gates for all high-risk operations.
Security development must shift from a "cost center" to a "core capability". Compliance serves as the foundation, while security operations determine the upper limit. As the industry advances deeper into the AI-defined vehicle era, this principle will grow increasingly weighty.