
The Central government has mandated immediate audits of connected vehicle software systems to fix cybersecurity flaws and prepare for new vehicle cybersecurity regulations after reports of a security flaw that could allow unauthorised users to remotely disable moving electric vehicles. The Ministry of Heavy Industries issued an advisory to the Society of Indian Automobile Manufacturers (Siam) and vehicle testing agencies this week, directing original equipment manufacturers (OEMs) to review battery communication interfaces, eliminate insecure default settings, strengthen authentication mechanisms and secure over-the-air (OTA) communication pathways. The ministry has also called for closer coordination among the Ministry of Road Transport and Highways (MoRTH), the Ministry of Electronics and Information Technology (MeitY), automobile manufacturers and other stakeholders to incorporate cybersecurity safeguards into vehicle design. Following the recent hacking incident, the Union government has asked automobile and parts makers to audit the software and devices in connected cars and EVs, with connected vehicles defined as those connected to the internet directly or via Bluetooth to smartphones.
The new government regulations mandate annual cybersecurity audits for 100% of connected vehicles and EVs sold in India, creating a structural demand surge for KPIT Technologies' automotive security suite. According to recent reports, this transition from voluntary security guidelines to mandatory, audited compliance standards will drive 25% projected increase in automotive cybersecurity spending by 2027. The regulation creates a recurring revenue stream as OEMs seek KPIT's specialized middleware and security protocols for both pre-launch certification and annual compliance. While OEMs face increased compliance costs for annual audits, the estimated impact is less than 0.5% of the vehicle cost, which is largely offset by the long-term benefits of reduced insurance premiums for secure, audited vehicles.
The directive follows reports that surfaced on July 1-2 claiming that a smartphone application called BAT-BMS, developed by Shenzhen Grenergy Technology, was used to unexpectedly shut down moving e-rickshaws by disconnecting the battery's discharge function. According to the ministry, the application is a legitimate tool for managing Bluetooth-enabled battery systems, but a critical security vulnerability arises when low-cost lithium battery packs are deployed with factory-default settings, weak passwords or without Bluetooth authentication. Under such conditions, anyone standing within a range of around 10-15 metres can connect to the battery using the application and switch off the discharge function, instantly cutting power to the motor and bringing the vehicle to a halt. Following the incident, the Union government has banned three Chinese-origin EV apps - BAT-BMS, Lossigy, and Epoch-i-ion - which were designed for electric-vehicle battery management but could be misused to remotely disable vehicles. While MeitY has initiated action to remove these applications from app stores, the ministry said removing the apps addresses only the immediate symptom, while the underlying vulnerability in battery communication interfaces remains.
The automobile industry faces significant cybersecurity risks that extend beyond India's borders. According to Business Standard, there is a global annual cybersecurity event, Pwn2Own Automotive, which focuses on demonstrating vulnerabilities in vehicles. In January, security researchers earned $516,500 after demonstrating 37 "zero-day" vulnerabilities in different vehicles on the first day of Pwn2Own Automotive 2026. A zero-day is a previously undiscovered bug, highlighting that automobiles without cyber firewalls present critical security vulnerabilities and hackers have demonstrated such bugs for at least a decade. This global context underscores the urgency of India's regulatory response and the need for robust cybersecurity standards across the automotive industry.
Significantly, the advisory asks manufacturers to begin preparing for the rollout of AIS-189 and AIS-190, the proposed vehicle cybersecurity regulations that introduce mandatory Cyber Security Management Systems (CSMS) and Software Update Management Systems (SUMS). The draft notification proposes a phased implementation beginning October 1, 2026, requiring manufacturers to secure OTA software updates, strengthen user authentication and validate software integrity. The ministry noted that although the latest battery safety standards under AIS-156 and AIS-038 Rev.2 have integrated telematics and connected features into modern battery systems, they neither mandate specific wireless communication technologies nor guarantee complete protection against cyber threats. The ministry said no single standard could eliminate every digital risk, but implementation of AIS-189 and AIS-190 would be a decisive step towards building a trustworthy connected vehicle ecosystem in India.