When Connected Cars Get Hacked: Four Documented Cases

Published October 5, 2026 | 11 min read

Key Takeaways

These cases are often retold as action stories about remote control of a moving vehicle. That framing has aged badly, and it obscures what the research record actually establishes. Only the oldest of the four is mainly about vehicle control. The later ones are about data: how much a manufacturer keeps, how precisely, for how long, and how many people can reach it.

All four were disclosed responsibly and all four were fixed. They are useful not as warnings about your next drive but as independent measurements of what the systems hold, taken by people who got inside them.

2015: Jeep Cherokee — the precedent

In July 2015, Charlie Miller and Chris Valasek demonstrated a wireless attack on a Jeep Cherokee. Brookings' write-up by John Villasenor records that they reached the entertainment system first and from there gained control of the windshield wipers, the accelerator and the brakes. Fiat Chrysler recalled approximately 1.4 million vehicles.

Two details are worth keeping. The first is the manufacturer's initial response: Chrysler characterized the exploit as requiring unique and extensive technical knowledge along with physical access, a claim the Brookings piece pushes back on by noting that people with exactly those skills exist. The second is the structural lesson Villasenor draws, which has held up: connectivity development had outpaced security, and unintended connections between in-vehicle systems were becoming common. An entertainment system is not supposed to be a path to the brakes.

This is the oldest case here and we flag it as historical precedent rather than a current risk. Its value is that it established the category.

2016–2018: Tencent's Keen Lab on Tesla and BMW

Keen Security Lab, part of Tencent, published two assessments that remain among the most thorough public work on vehicle architecture.

Tesla, 2016

In September 2016 the lab reported a chain of vulnerabilities allowing remote compromise of a Tesla Model S, described as requiring no physical contact, and demonstrated in both parking and driving modes. The lab's own write-up is deliberately short on exploitation detail, consistent with responsible disclosure. It credits Tesla's security team with a prompt response and urges owners to update to the latest firmware, which is the practically important part: the fix traveled to vehicles as a software update.

BMW, 2018

The BMW assessment is the more instructive document. Keen Lab examined three components — the head unit, the telematics control unit and the central gateway module — and reported 14 vulnerabilities, several with assigned CVE identifiers including CVE-2018-9322, CVE-2018-9320 and CVE-2018-9312.

The remote attack surfaces it lists are the ones that make a car an internet-connected device: GSM communication, BMW Remote Service, ConnectedDrive, the NGTP protocol and remote diagnostic messaging. The paper concludes that it was feasible to gain local and remote access to infotainment and telematics components, and to reach the CAN buses by issuing unauthorised diagnostic requests. The affected models span the i, X, 3, 5 and 7 Series, with telematics-unit issues reaching models produced from 2012 onward. The lab's timeline records the project beginning in January 2017 and the findings being proven in an experimental environment in February 2018.

The detail most worth remembering: the paper states the software vulnerabilities could be fixed by online reconfiguration and offline firmware update — explicitly not an over-the-air upgrade. Where Tesla could push a patch, this fix depended on a different and slower channel. When you assess a connected car, ask how security updates reach it, not just whether they exist.

2024: Volkswagen and Cariad — 800,000 vehicles in the open

In December 2024 the Chaos Computer Club, acting on a tip from an anonymous source, reported that Cariad, Volkswagen's software subsidiary, had left vehicle data in a misconfigured and unprotected Amazon cloud store. As reported by Electrek, roughly 800,000 electric vehicles across Volkswagen, Audi, Seat and Skoda were affected, and in about 466,000 cases the location data was precise enough to reconstruct a daily routine.

The exposed set reportedly included German politicians, business figures, suspected intelligence service employees, and the entire electric fleet of the Hamburg police. The data was accessible for months before being secured following notification on November 26. Cariad's response was that no passwords or payment information were exposed and that reaching individual records required a high level of expertise.

Nobody sold this data and no attacker needed to defeat a vehicle's security. The failure was ordinary cloud misconfiguration, which is why this case belongs in any honest account of the risk: the largest exposures tend to come from the storage layer rather than the car.

The police-fleet detail is the bridge to the national security argument, covered separately in Driving Data as a National Security Problem.

2025: Subaru Starlink — a year of history, reachable by many

In January 2025, researchers Sam Curry and Shubham Shah reported a vulnerability in the administrative back end of Subaru's Starlink telematics service. The Security Ledger's account describes a password reset endpoint that did not require a confirmation token, employee accounts identifiable from publicly listed email addresses, and two-factor authentication that could be bypassed. A detailed walkthrough of their findings is also available.

What the access yielded is the point:

Millions of vehicles across the United States, Canada and Japan were in scope. The researchers reported the issue in November 2024 and it was patched before publication.

The systemic finding is about internal access rather than the bug. The reporting notes that a junior employee in one state could query billing information for a vehicle in another without triggering an alert. A manufacturer can hold a year of your precise movements and still have no meaningful controls over which of its own staff can look at them.

What these four cases establish

  1. Retention is longer than most drivers assume. A year of five-meter location history is not a diagnostic log. It is a movement record.
  2. The back end is the exposure, not the car. Three of the four cases turned on web portals and cloud storage.
  3. Internal access control is part of privacy. Data that only a company can reach is still exposed if anyone at the company can reach all of it.
  4. The update channel matters. A vulnerability fixable over the air and one requiring a dealer visit are different risks for the same flaw.
  5. All four were found by researchers who published. There is no comparable public record of what was found by people who did not.

None of this is reachable by an opt-out form. An opt-out governs disclosure the manufacturer chooses to make; it does not reduce what is retained or who inside the company can see it. That is the honest limit, and it is the argument for asking for deletion rather than only opting out — deletion is the only request that reduces the amount of history sitting in a system like these.

For the mechanics of making that request to each brand, see How to Stop Car Companies From Collecting Your Data. For the commercial side — the data that is sold rather than leaked — start with Your Car Is Reporting on You.

Delete Your Data from 1,475 Data Brokers

A patched vulnerability does not delete the history it exposed. We send legal CCPA deletion demands to 1,475 data brokers and file FCRA disclosure requests with the consumer reporting agencies that hold driving data — so you can see what is on file and demand its removal. Automated 45-day re-checks. $9.95/month.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.