Cybersecurity Threats Are Evolving—but So Are the Tools to Combat Them

With the growth of new technologies like AI comes new ways for hackers to exploit vulnerabilities, causing disruptions to entire business operations. We break down some of the latest trends in cybersecurity for auto shops, and what you can do to protect your business.

Key Highlights

  • Auto repair shops are vulnerable to cyberattacks targeting POS systems, websites, IoT diagnostic tools, and customer portals, with 68% experiencing successful breaches in 2025.
  • AI-driven vulnerabilities are emerging as a significant threat, with cybercriminals exploiting AI models and external AI platforms to access sensitive data.
  • Small businesses often lack resources for robust cybersecurity, but implementing multi-factor authentication, role-based permissions, and regular audits can significantly reduce risks.
  • Choosing secure shop management systems and vendors that prioritize security features like patching, backups, and transparency is crucial for protection.
  • Developing and practicing contingency plans, including manual processes for operations during outages, ensures business continuity in case of cyber incidents.

Many shops are already aware of cybersecurity threats—but how do they culminate? What does it look like when a shop is targeted, and what sets a cyberattack in motion?

This month we’re breaking down some of the top threats and recent trends in cybersecurity, while Taylor Fuqua, Tekmetric’s chief technology officer, provides insight into how you can safeguard your own shop against those threats.

How Cybersecurity Attackers Target Shops

Like many small businesses, auto repair shops have become more reliant on digital tools to help streamline processes like scheduling, communicating with customers, building repair orders, and collecting vehicle information. While these tools have become essential in operations, the new digital landscape also brings with it certain risks that shops must be aware of.

The most noticeable impact for a shop hit by a cyberattack can be connection issues, affecting things like a shop’s Wi-Fi or shop management system. In that event, it can bring operations to a grinding halt.

“If your Wi-Fi goes down or your shop management system is no longer available, how are you going to check in customers? How are you going to fix cars, and how are you going to accept payment and get your customers out the door?” says Fuqua.

The data makes it clear where shops are being targeted: as shared in VikingCloud’s most recent Auto Service, Repair, and Parts Businesses Survey, point-of-sale systems were cited as the most targeted function of a shop, accounting for 66% of attacks. It’s followed by websites and mobile apps at 36%, IoT-connected diagnostic tools in service bays at 38%, and customer-facing portals at 32%.

The survey also showed that 68% of auto service shops were successfully attacked throughout 2025, with 40% of cybersecurity leaders believing those attacks were driven by AI. This is further emphasized by Upstream in its 2026 Global Automotive and Smart Mobility Cybersecurity Report, which found that the rapid adoption of AI has created even more vulnerabilities for cybercriminals to target.

“Even if interfaces are properly secured, the AI systems operating behind them can be exploited,” the report states. “These AI-specific vulnerabilities represent a new frontier that extends beyond the protocol surface. … AI models, particularly LLMs, can be tricked through carefully crafted queries into revealing sensitive information they were trained on or have access to.” 

Upstream cited an incident occurring in late 2025, in which a massive cyberattack targeted an AI-driven component within a popular customer relationship management platform, Salesforce. The attack impacted major corporations that used the platform, including Stellantis.

“The growing reliance on external services and third-party AI platforms is dissolving the traditional vehicle perimeter, extending the attack surface across a distributed ecosystem of cloud servers, mobile apps, and interconnected APIs,” the report added.

In addition, small businesses in general are more likely to be targeted by cybersecurity attacks. Hackers realize that small businesses often lack the resources available to larger companies, making them seem like a better opportunity to target for a cyberattack.

Safeguarding Your Business

Just because small businesses face hurdles doesn’t mean there’s nothing they can do to protect themselves. Shop management systems are integral to business operations, but when choosing one, consider how much control you’re given over your data and how it’s used. 

Tekmetric offers features like multi-factor authentication, separate accounts for each employee, and the ability to adjust permissions for what each employee can access. However, a software provider is not meant to handle every aspect of your security. What these features do is help counteract one of the biggest slipups shops make, which is a lack of hygiene around logins and permissions.

Shops need to pay close attention to what permissions each employee has. When bringing on a new hire and assigning them roles, make it part of the onboarding process to determine what permissions they have. Conversely, it should also be part of the offboarding process to ensure no one retains permissions and has lingering access to shop data. It can also be worthwhile to conduct a monthly audit of your shop management systems and tools, reviewing who has permissions to what.

When choosing a shop management provider, it’s crucial to consider whether they offer adequate patching, infrastructure, and backups. But it’s not just shop management systems to examine; businesses should take inventory of all their vendors, including DVI or payment processing software, and see how much they offer in the way of cybersecurity.

“It’s really important to understand … all (the) systems that you’re using. How secure are they, and how transparent are they with their security posture?” Fuqua says. “Do they offer MFA? Do they have role-based security, and do they have everything in place for you to roll out a good security policy within your shop?”

Finally, shops should have a plan for what to do if an internet or software outage takes place to ensure their business operations are still able to run smoothly. Fuqua recommends having manual processes in place for customer check in, repair workflow, communication, and payments.

As with each step of your cybersecurity plan, it will require not just conceptualizing, but putting it into place to ensure it works. Keep all your tools up to date and ready to adapt, because the technology our industry works with is only growing more complex.

“If you’ve said, ‘Hey, if an incident happens, this is what we’ll do,’ but you’ve never gone through the process, at that point your backup plan is a bit of a hope, not really a recovery plan,” Fuqua says.

About the Author

Kacey Frederick

Kacey Frederick

Associate Editor

Kacey Frederick joined as the assistant editor of Ratchet+Wrench in 2023 after graduating from the University of Arkansas at Fort Smith with a bachelor’s in English and a minor in philosophy.

The grandchild of a former motorcycle repair shop owner, he’s undergone many trials and tribulations with vehicles. Now the proud owner of a reliable 2011 Toyota Camry, he works to represent those in the repair industry that keep him and so many others safely rolling on.

Sign up for our eNewsletters
Get the latest news and updates