The government's recent advisories have shifted the focus to digital vulnerabilities, underscoring the growing need to secure India's rapidly evolving EV ecosystem
Cyber security is emerging as the next frontier of vehicle safety as India’s electric mobility transition gathers pace. While the conversation, until recently, on EV batteries centered around thermal runaway, fire incidents and charging infrastructure, some recent developments have shifted attention to a less visible yet potentially more disruptive risk - the vulnerability of Battery Management Systems and connected vehicle softwares to cyber attacks.
In a recent advisory, the Indian government asked Original Equipment Manufacturers (OEMs) to immediately audit battery communication systems, eliminate cyber security vulnerabilities and accelerate preparations for upcoming cyber security regulations. The move came after reports claimed that publicly available mobile applications could remotely access and even shut down the batteries of certain electric vehicles by exploiting their insecure bluetooth enabled BMS modules.
According to reports, the ministry of heavy industries (MHI) directed OEMs to “strengthen authentication mechanisms, eliminate insecure default settings, secure over-the-air (OTA) communication pathways, and review battery communication interfaces” in an advisory issued to the Society of Indian Automobile Manufacturers (SIAM) and vehicle testing agencies.
The timing is significant in India. The country is witnessing rapid growth in connected electric two and three-wheelers, domestically manufactured battery packs and software-defined vehicles, while simultaneously building a domestic battery manufacturing ecosystem. As connectivity becomes central to vehicle performance, over-the-air updates and intelligent battery management, cyber resilience will increasingly determine consumer trust, public safety and the competitiveness of Indian EV manufacturers.
Fig 1: An e-rickshaw in India. Image: Shutterstock
Realising the gravity of the situation, the advisory also asks manufacturers to start initiating the “rollout of AIS-189 and AIS-190, the proposed vehicle cybersecurity regulations that introduce mandatory Cyber Security Management Systems (CSMS) and Software Update Management Systems (SUMS).” According to the draft notification, beginning October 1, 2026, a phased rollout that mandates manufacturers to validate software integrity, reinforce user authentication, and safeguard OTA software updates, will be undertaken, the report pointed out.
The Ministry of Electronics and Information Technology (MeitY), has also initiated action against apps BAT-BMS, Epoch Li-ion, and Lossigy which were purportedly used in disabling electric vehicles and plans to block any other app that may also be misused in a similar way. Reports suggest that these apps allow a user to keep track of bluetooth-enabled lithium-ion batteries, which are mostly used in electric vehicles. These apps allow anyone standing approximately 15 metres to connect to the bluetooth enabled electric vehicle, which are mostly vulnerable and mostly do not have password protection, and turn off the batteries’ discharge function.
Heavy dependence on digital technologies and the presence of more components in comparison to an Internal Combustion Engine (ICE) vehicle make EVs and smart vehicles even more vulnerable to cyber threats. Clean Mobility Shifted highlighted some of the key vulnerabilities of EVs in an article published sometime back. Let's look at some of them.
- Intercepting Signals: Hackers can intercept fob key signals and gain access to vehicles. Most of the EVs get unlocked either through manufacturer apps which can be hacked into or RFID chips that can be easily cloned.
- Introduction of malicious software: Apart from compromising the vehicle safety and its functionality, malicious software can help hackers gain a wealth of data like user profiles, location data, and payment details stored in the EVs and their charging infrastructure network.
- Malware Exposure: Introduction of malwares into EVs runs the risk of compromising the safety features, functionality and data integrity of the vehicle, leading to grave inconvenience of the consumer and also threatening the critical charging infrastructure.
- Power grid vulnerability: Since most of the charging stations are connected to national assets like power grids, by hacking into this infrastructure, cyber criminals have the capability to disrupt the entire power ecosystem and even disable EV charging stations and operations.
As vehicles become increasingly connected and software-driven, cybersecurity is emerging as a core pillar of vehicle safety and consumer trust. The government's recent interventions underscore a broader shift in regulatory thinking—from preventing battery failures to safeguarding digital vulnerabilities that could compromise entire vehicle systems.

