In an era where software defines everything from smartphones to household appliances, the automotive industry has embraced over-the-air (OTA) technology with remarkable enthusiasm. What began as a novel feature in early electric vehicles has evolved into a standard capability across much of the modern fleet. Yet as vehicles become rolling computers connected to the internet, experts warn that the very convenience of wireless updates could open dangerous doors to cyberattacks with potentially life-threatening consequences.
OTA technology allows manufacturers to deliver software, firmware, security patches, and feature enhancements directly to vehicles without requiring a visit to a dealership or service center. Tesla popularized the approach with its Model S in 2012, using it to improve performance, add new capabilities, and address issues remotely. Today, the practice extends far beyond luxury EVs. Major automakers including General Motors, Ford, BMW, Mercedes-Benz, and many others routinely push updates to millions of connected cars worldwide.
The benefits are substantial. OTA updates reduce recall costs, accelerate the deployment of safety improvements, and enable continuous enhancement of vehicle features. Owners enjoy everything from improved battery management and navigation refinements to new driver-assistance functions — all delivered seamlessly while the car sits in the driveway. For manufacturers, it streamlines operations and creates ongoing revenue opportunities through subscription-based services.
However, this connectivity comes with significant risks. Analysts and cybersecurity researchers increasingly highlight how OTA systems expand the attack surface of vehicles. Modern cars contain dozens of electronic control units (ECUs) managing everything from engine performance and braking to infotainment and autonomous driving features. Many of these systems communicate via internal networks that can potentially be accessed through wireless interfaces.
Recent incidents and tests have underscored these vulnerabilities. In late 2025, Norwegian bus operator Ruter conducted security assessments on electric buses and discovered concerning access points linked to OTA systems. One vehicle reportedly had potential exposure to its battery and power control systems via a mobile network connection. While no malicious exploitation occurred, the findings prompted investigations in the United Kingdom and Denmark, particularly regarding buses manufactured by Chinese firm Yutong.
These concerns extend beyond public transit. Passenger vehicles face similar threats. A compromised OTA connection could theoretically allow attackers to manipulate vehicle controls, disable safety systems, or harvest sensitive data. National security analysts worry about state-sponsored actors gaining footholds in vehicle fleets, potentially disrupting transportation infrastructure or conducting espionage through connected devices.
Gabriel Lim, a senior analyst at Singapore’s S. Rajaratnam School of International Studies, has described OTA technology in vehicles as representing “a unique national security concern.” Countries have expressed worries about foreign manufacturers embedding capabilities that could allow remote interference with moving vehicles. In May 2026, the American Enterprise Institute released a report emphasizing the need for stronger safeguards against foreign espionage through automotive components and software.
Professor Siraj Ahmed Shaikh of Swansea University notes that while much attention focuses on Chinese manufacturers, the issue is industry-wide. OTA adoption spans maritime, rail, aerospace, and industrial sectors. The pervasive nature of the technology means vulnerabilities in one area can have cascading effects across critical infrastructure.
Real-world demonstrations of vehicle hacking are not new. Security researchers have previously shown how they could remotely control brakes, steering, and other systems in experimental settings. OTA expands these possibilities by providing persistent, manufacturer-approved communication channels that, if compromised, grant broad system access.
Data privacy represents another major dimension of risk. Connected vehicles generate vast amounts of information about driving habits, locations, and even passenger behavior. Securely transmitting and storing this data while enabling convenient updates presents a complex challenge that not all manufacturers address with equal rigor.
Industry responses vary. Some companies invest heavily in cybersecurity, implementing multi-layered encryption, regular vulnerability assessments, and over-the-air security patches. Others lag, prioritizing speed-to-market and cost efficiency. Regulatory frameworks remain fragmented. While regions like the European Union are advancing cybersecurity requirements for connected vehicles, comprehensive global standards are still developing.
Experts call for greater intervention. Recommendations include mandatory security reviews for foreign-made components, increased transparency requirements around data collection, and restrictions on certain high-risk hardware and software in critical applications. Jason Van der Schyff of the Australian Strategic Policy Institute stresses that as OTA becomes normalized, proactive governance is essential rather than reactive measures after incidents occur.
For consumers, the implications are practical and immediate. Vehicle buyers should research manufacturers’ cybersecurity track records, understand what data their cars collect and transmit, and stay vigilant about applying updates promptly. Fleet operators and governments face even higher stakes when managing large numbers of connected vehicles.
The tension between innovation and security is not unique to automobiles, but the stakes feel particularly high when lives are literally in the driver’s seat. As vehicles evolve into sophisticated software platforms on wheels, balancing convenience with robust protection will define the next chapter of automotive technology. Without concerted effort from industry, regulators, and consumers, the convenience of over-the-air updates risks becoming a vulnerability that adversaries are all too eager to exploit.
The automotive sector stands at a crossroads. Embracing connectivity has driven remarkable progress in safety, efficiency, and user experience. Ensuring that progress doesn’t come at the expense of security will require vigilance, investment, and collaboration across borders and industries. The wireless future of driving is here — now comes the hard work of making it safe.