Skip to main content

Cars are computers on wheels now, and the CAN bus trusts what it hears

An editorial on why cars are becoming computers on wheels, why the CAN bus trusts internal messages, what attacks are documented, and where the evidence on car ransomware stops.

By John Maya · Last updated 10 October 2026

Close-up of an OBD-II diagnostic connector, the port in a car's cabin that diagnostic tools plug into.

This is a platform comparison. General information gathered from public sources — pricing, features and policies change, so check each platform’s own site before deciding. Full note

ABC News reported on 21 September 2026 (opens in a new tab) that Australia has no minimum cybersecurity standards for cars and that new rules are likely years away. In the same report, a security researcher switched off a BYD Shark 6's headlights while the reporter was driving it (opens in a new tab), using access he said had no password. BYD says the first step needed physical access (opens in a new tab), and we give both sides below.

Our view is that a car has become a computer you sit in. The basic network linking its parts has no built-in way to check who is talking (opens in a new tab), and it is not hard to believe that one day an owner will be asked to pay to get a car working again. That last part is a prediction: we could not find a case of it, and we say below where the evidence stops.

This is an editorial: it argues a view that is ours, and every fact under it is linked so you can check it and disagree.

Minimum car cyber standard in Australia
None, per ABC (Sept 2026)
ECUs in a premium car
Up to 100, per Aptiv
Sender check on CAN packets
None, per 2010 research
Brisbane Toyota thefts alleged
60 cars, 7 men charged
Vic Police estimate, key-cloning device thefts
More than 10,000 a year
Ransomware incidents, car industry
160 in Q2 2026 (VicOne)

Why a car now counts as a computer

These figures are estimates and supplier claims, not audited counts. In 2009, IEEE Spectrum quoted informatics professor Manfred Broy (opens in a new tab) saying a premium-class car probably contains close to 100 million lines of software code; the same article said, in its own words, that this software runs on 70 to 100 ECUs. An ECU, or electronic control unit, is a small computer that looks after one part of the car. Supplier Aptiv said in 2020 (opens in a new tab) that premium cars can carry up to 150 million lines across as many as 100 ECUs.

Toyota called its new RAV4 the first step toward fully software-defined Toyota vehicles (opens in a new tab), and the software fails the way computer software does. CarExpert reported (opens in a new tab) that Toyota Australia will recall 16,238 Camrys over a software error that may stop the combination meter displaying at startup, with a dealer software update that takes around 60 minutes, though some cars may need to stay longer. One consultancy's tally counts 1,573 vehicle software recalls since 1994 (opens in a new tab), though we could not find a definition of a software recall in it.

We think "computer on wheels" has stopped being a figure of speech. It has bugs and patches, and Toyota says its Arene software platform is built to support over-the-air updates and continuous software improvement (opens in a new tab).

The CAN bus: a shared wire that doesn't ask who is talking

ECUs talk to each other over a network, and a widely used one is CAN, short for controller area network. Bosch began developing it in 1983 and introduced it in 1986, and Mercedes-Benz has used it in its upper-class cars since 1991 (opens in a new tab). We could not find any mention of security in the original design in the history we read; it mentions security only in passing, for the newer CAN XL protocol.

In 2010, researchers from the University of Washington and UC San Diego found that CAN packets carry no authenticator and no source identifier (opens in a new tab), so any component can send to any other. On a real car they disengaged the brakes while it was driving and killed the engine (opens in a new tab). Ken Tindell of Canis Automotive Labs wrote in 2023 (opens in a new tab) that in most cars the receivers simply trust internal messages, and that the weakness is industry-wide. He is chief technology officer of Canis Automotive Labs (opens in a new tab), whose own CAN security products (CAN-HG, CryptoCAN) the post discusses, which is worth knowing.

A fix is known. Tindell recommends cryptographic authentication of messages (opens in a new tab), and the authors of a 2025 paper call AUTOSAR's SecOC the foundational mechanism for securing in-vehicle communication (opens in a new tab). They say it has been used for over a decade in hundreds of millions of automotive systems. The abstract gives no source for that figure, we could not find an independent count, and two of the authors work for Bosch and NXP, which supply automotive hardware and software, while the paper proposes a competing approach for CAN XL.

Our reading: CAN grew up assuming that whatever was on the wire belonged there. That is a poor assumption once the wire has infotainment, radios and a diagnostic socket attached.

What has already happened: demonstrated, and exploited

Researchers showing something is possible is not the same as criminals doing it, so we keep the two apart.

Demonstrated by researchers

Exploited by criminals

  • Tindell describes how (opens in a new tab), in the theft of a security researcher's Toyota RAV4, the bumper had been pulled away and the headlight unplugged. He says it looks like the thieves reached the CAN bus through the headlight connector and sent a spoofed "key validated" message that unlocks the immobiliser, using a device that looks like a JBL Bluetooth speaker. The formal record, CVE-2023-29389 (opens in a new tab), limits it to attackers physically near the car.
  • Information Age reported on 8 January 2026 (opens in a new tab) that seven men were charged over the alleged theft of 60 Toyotas around Brisbane. In the same report it describes a CAN bus injector exploit, previously reported in Victoria, that it says can be bought on the black market for between $5,000 and $10,000; it links the two by sequence and does not say outright that the Brisbane men used one. A Queensland Police update (opens in a new tab) on what appears to be the same case alleges the syndicate stole 60 vehicles, targeting specific Toyota models including LandCruisers and Prados, and we could not find any mention of the CAN bus in it. These are allegations, and we could not find court outcomes.
  • The Nightly reported in August (opens in a new tab) that Victoria Police intelligence estimates more than 10,000 cars a year are being stolen by offenders using devices that clone or mimic car keys, a group the article says includes tools that exploit the on-board diagnostic system, with LandCruiser thefts up from 89 in 2022 to 846 last year. We could not find any mention of CAN injection or malware in the report.
  • Malware has reached a car's head unit, its infotainment system. Kaspersky reported on 21 August 2026 (opens in a new tab) what it calls the first documented case of malware found on a car head unit with an infection chain specific to that kind of device: a downloader on DoFun head units, built for ad fraud and a proxy botnet. We could not find an infection count in the report, or any statement that the malware touched driving functions.

Ransomware and pay-to-unbrick: what is documented, and what we could not find

Ransomware locks a system until the victim pays. Against the car industry it is documented: VicOne, a security vendor, counted 160 ransomware incidents (opens in a new tab) in the second quarter of 2026, led by logistics and transport firms (64), then suppliers, dealers and manufacturers. We could not find any statement in its report that any hit individual vehicles or owners. Upstream Security says ransom-related incidents more than doubled in 2025 (opens in a new tab) to 44% of the 494 public incidents it counted; we could not find a definition of the term, or a count of incidents hitting individual vehicles, in the report.

Nearest to our scenario are owners being asked to pay. A Russian dealer said in mid-2025 (opens in a new tab) that fraudsters were taking over Li Auto owners' app accounts and demanding about 250,000 rubles on average, and that it had re-registered 47 accounts in the past month, some of them compromised; we could not find a police or manufacturer statement behind it. Upstream's own write-up (opens in a new tab) of what appears to be the same episode, which names a Chinese maker rather than Li Auto, says it involved no malware and no coordinated cyberattack: whoever held the phone number the app was registered to controlled the car's account, and the cause was grey-market imports whose app could only be registered with a Chinese phone number.

The nearer precedent for paying to get a car's functions back comes from manufacturers, not criminals. In late 2019 Tesla remotely removed Enhanced Autopilot and Full Self-Driving from a used Model S that a third-party dealer had bought at a Tesla auction and sold on. The Next Web reported (opens in a new tab) that the new owner says Tesla offered to sell the features back to him and that they were reinstated after media attention; the invoice said the customer had not purchased the software, and the article says Tesla had issued no official statement. Electrek reported (opens in a new tab) that an over-the-air update in October 2025 left some Jeep Wrangler 4xe plug-in hybrids bricked and towed to dealers, with Stellantis recalling 24,238 vehicles. Tesla's removal was a company decision and the Jeep failure a software error, not attacks. In our view they show what an extortionist would need: a server that can change what a car does, and an owner who cannot fix it in the driveway.

What we could not find is the scenario itself: a documented case of ransomware on a car's own computers that locked the car until the owner paid. A talk titled "AutoSec 2020 - Ransomware Targeting Automobiles" (opens in a new tab) (page last updated September 2023) describes testing a QNX-based car infotainment system. The authors found an unauthenticated debug service that allowed arbitrary code to run, and used a fork bomb to exhaust the system's resources, arguing that ransomware attacks are viable on automotive platforms. The page does not show working ransomware, and says no ransomware had been seen in the wild on the automotive surface. In the 2025 and 2026 reports we read we found none either: the vendor counts above do not say they involve individual vehicles, the Kaspersky malware chased ad fraud, and the Russian case was an account takeover. Our view is that it is not hard to believe. In our view the ingredients, remote reach, a maker's server and an app account that controls the car, already exist.

What the rest of the world is doing

The main international answer we found is a pair of United Nations rules. UN Regulation 155 (opens in a new tab) makes type approval depend on the manufacturer running a cyber security management system, and requires it to detect and prevent attacks and monitor vehicles in the field; its threat tables name malicious CAN messages and diagnostic-port dongles (opens in a new tab). UN Regulation 156 (opens in a new tab) covers software updates. Australia is listed on the UN treaty register as a participant (opens in a new tab) in R155, alongside the EU, Japan, South Korea and the UK. Heavy Vehicle Industry Australia reported (opens in a new tab) that the infrastructure department began consulting in April 2026 on adopting both as Australian Design Rules, so on that reporting neither is yet one here, and the department's drafts, ADR 115 and 116, drew a call from the association to pause for an impact analysis (opens in a new tab). The federal smart-device security standard, as made in 2025, excludes road vehicles and their components (opens in a new tab).

The country worth a closer look is the United States, because it has done two different things. NHTSA's 2022 guidance is, in the agency's words, voluntary and non-binding (opens in a new tab), and the notice says it does not have the force and effect of law and is not a regulation, though it recommends that critical safety messages on non-segmented communication buses should employ a message authentication method to limit the possibility of message spoofing. The Commerce Department's connected-vehicles rule (opens in a new tab), published in January 2025, restricts transactions involving connected-vehicle technology from persons tied to certain foreign adversaries, on a finding that such technology poses an undue or unacceptable national-security risk because it could enable them to exfiltrate sensitive data and remotely access and manipulate vehicles. The software prohibitions apply to vehicles from model year 2027 and the hardware prohibitions to vehicles from model year 2030, or to hardware not tied to a model year that is imported from 1 January 2029, according to the rule's text (opens in a new tab) (we have not checked for later amendments). In our reading, that is a supply-chain measure aimed at particular countries' technology, not a standard for how well a car's network defends itself. Our reading of the whole picture: the US has a binding rule on who supplies connected-vehicle software and communications hardware and a voluntary one on how the wiring is defended, and Australia, on the ABC's account (opens in a new tab), has no minimum standard yet.

The honest case against us

Here is the strongest counter-evidence.

We would sharpen our own view in one place. It is tempting to say simple cars are safe and complex ones are not. CAN is not an EV feature: Mercedes-Benz has used it in upper-class cars since 1991 (opens in a new tab), and the CAN in Automation group says almost every new passenger car made in Europe has at least one CAN network. A car with no radio link can still be stolen by someone standing at it. What connectivity adds is reach. NHTSA's follow-up said Uconnect radios not included in the recalls were not equipped with built-in cellular access or short-range wireless communication (opens in a new tab) and did not contain the vulnerabilities the recalls addressed. In our view, one flaw in a server, an app or an update can touch a whole fleet; the scale we have in mind is Spireon's estimated 15.5 million devices (opens in a new tab) and the Jeep recall's 1.4 million vehicles (opens in a new tab). A simple, unconnected car is exposed to local thieves, not to fleet-wide remote failure. That is our sharper argument: connectivity and over-the-air control are what turn one fault into a fleet-wide event, and it is why we keep arguing for simple, repairable, owner-controlled machinery.

Watch this space

Our prediction, and it is only that: the first widely reported case of a car held to ransom is more likely to arrive through a maker's server, an app account or a head unit than through a worm racing along a CAN bus. The Li Auto case above is the pattern: no malware on the car, but someone else controlled the account. We would watch three things: whether Australia's draft ADR 115 and 116 get a start date or stall; whether vendors such as VicOne and Upstream start reporting ransomware against individual vehicles separately from companies; and whether CAN message authentication appears in the specifications of cars sold here, now that BYD says it is assessing whether additional CAN message authenticity measures are necessary and feasible (opens in a new tab). A few years of enforced rules and close to no vehicle-level incidents would change our mind, and we would say we were too gloomy.

What it means if you're buying or selling in Australia

Electronic theft is a live risk in Victoria, where police intelligence says key-cloning and similar devices feature in up to 40 per cent of vehicle thefts (opens in a new tab). Toyota Australia's secondary immobiliser, a Toyota Genuine Accessory for the LandCruiser 300 Series and Prado 250 Series, costs $1,735 fitted (opens in a new tab), with installation taking about five hours, and Toyota describes it as an additional layer of vehicle-start authentication. Our guide to car theft in Australia (opens in a new tab) covers the electronic methods and what to do if your car is stolen.

If you are buying a connected used car, ask whether its recalls and software updates have been done; the Camry fix we mentioned is quoted at around 60 minutes at a dealer (opens in a new tab), and Toyota says some cars may need to stay longer. If you are selling, sign out of the car's app and remove your account and phone before handover. The Russian lockouts Upstream describes, which appear to be the Li Auto case, turned on who controlled the phone number behind the account (opens in a new tab), so treat that as a principle, not a local risk.

Watch out

The expensive mistake is trusting a late-model car's factory security alone, when Victoria Police recommend adding an OBD port lock, a steering-wheel lock or an immobiliser (opens in a new tab).

Cover photo: OBD-II connector (opens in a new tab) by Alain Van den Hende, licensed CC BY-SA 4.0 (opens in a new tab), via Wikimedia Commons.

FAQs

Can a car get ransomware?

We could not find a documented case of ransomware on a car's own computers locking the car until the owner paid. Ransomware is documented against the car industry, with VicOne counting 160 incidents in the second quarter of 2026 (opens in a new tab), but we could not find any statement in its report that any hit individual vehicles. The closest owner-level case we found, app-account lockouts of Chinese-brand cars in Russia that appear to be the Li Auto episode, involved no malware, according to Upstream's own write-up (opens in a new tab), which does not name the maker. Our view is that car ransomware is not hard to believe, but it remains a prediction.

What is the CAN bus?

CAN, short for controller area network, is the shared network that lets a car's ECUs talk to each other. Bosch introduced it in 1986 and Mercedes-Benz has used it in upper-class cars since 1991 (opens in a new tab). Researchers found in 2010 that its packets carry no authenticator and no source identifier (opens in a new tab). Message authentication exists, and the authors of a 2025 paper call AUTOSAR's SecOC the foundational mechanism (opens in a new tab) for it, but we could not find an independent count of how many cars use it.

Can my car be hacked?

Researchers have shown remote attacks on specific models, such as a 2014 Jeep Cherokee (opens in a new tab), and several cases we read were reported fixed. A security researcher describes CAN injection being used to steal Toyota RAV4s (opens in a new tab), and Information Age (opens in a new tab) describes a CAN bus injector exploit in its Brisbane report; the RAV4 method needs physical access to the car. In Victoria, police intelligence estimates more than 10,000 cars a year (opens in a new tab) are stolen using devices that clone or mimic keys. NHTSA's reviewers found no confirmed hacking incidents (opens in a new tab) in the records they reviewed in the Jeep case. We cannot tell you about your car in particular.

Are older cars safer?

It depends on the risk. NHTSA's follow-up said Uconnect radios not included in the Jeep recalls were not equipped with built-in cellular access or short-range wireless communication (opens in a new tab), so a car without a radio link lacks that remote route. But Mercedes-Benz has used CAN in upper-class cars since 1991 (opens in a new tab), and a car with no radio link can still be stolen by someone at the car. Our view is that connectivity and over-the-air control, rather than age or engine type, decide whether one fault can reach a whole fleet.

Does Australia have rules for car cybersecurity?

ABC reported in September 2026 (opens in a new tab) that Australia has no minimum cybersecurity standards for cars. Heavy Vehicle Industry Australia reported that the infrastructure department began consulting in April 2026 on adopting UN Regulations 155 and 156 as Australian Design Rules (opens in a new tab), with drafts ADR 115 and 116 and the association asking for a pause for an impact analysis (opens in a new tab). The federal smart-device standard excludes road vehicles (opens in a new tab).

Found this useful? Share it with someone buying or selling a car.

About this guide

The MotorLoop team — These guides are researched and maintained by the MotorLoop team, and every claim names the source that publishes it so you can check it yourself.

General information only — not advice, and not confirmed fact. Everything on this page was gathered from public sources (each platform’s own pages, reviews and press coverage) at the date shown, and pricing, features and policies change often and can vary by vehicle and location. Always check each platform’s own website for its current, correct information before making decisions.

All platform names, trademarks, logos and content referenced here belong to their respective owners; MotorLoop is not affiliated with, endorsed by, or responsible for any of the third-party sites mentioned. MotorLoop operates its own marketplace, which appears in this comparison clearly marked as ours.

Last updated 10 October 2026.

← All guides