Driving Data as a National Security Problem

Published October 5, 2026 | 10 min read

Key Takeaways

Most privacy arguments are about the individual: what a company knows about you, and what it does with it. The national security argument is different in kind. It is not about any one person's movements being sensitive. It is about what becomes visible when enough people's movements are collected in one place and that place is reachable.

Three documented episodes make the point, and only the third involves cars. They are worth reading in order, because each one answered a question the previous one raised.

2018: a fitness app drew the map

In January 2018, Strava's global heat map — an aggregate visualization of routes recorded by its users — was found to reveal the layout of overseas military installations. The pattern was noticed by Australian researcher Nathan Ruser, who observed activity tracing clearly in otherwise empty terrain. ABC News reported that the map showed base perimeters, supply routes and patrol paths at sites in Syria, Iraq and Afghanistan, along with the daily rhythms of the people working there.

The Department of Defense opened a review of its GPS policies, as NPR reported at the time. In August 2018 it restricted the use of geolocation features on fitness trackers and similar devices for personnel in deployed and operational areas. Strava subsequently narrowed how much street-level detail the map exposed.

Several things about this case set the template:

2023: the data was simply for sale

The Strava case involved data a company gave away by accident. Five years later, researchers at Duke University's Sanford School of Public Policy tested whether the same category of information could just be bought.

Justin Sherman, Hayley Barton, Aden Klein, Brady Kruse and Anushka Srinivasan published Data Brokers and the Sale of Data on U.S. Military Personnel in November 2023. Their method was deliberately unexceptional: scrape hundreds of data broker websites for terms like “military” and “veteran”, then approach US brokers as an ordinary buyer — once from a US .org domain, and once from a .asia domain — and try to purchase.

They succeeded. Duke's summary of the study records a price as low as $0.12 per record, and data obtained that included health information, financial information and details of religious practice about active-duty personnel, their families and veterans. Location data was available for purchase, though the team did not buy it. CNN's coverage reported the findings at the time.

The finding that matters most is not the price. It is that identity verification was weak enough that the destination of the data barely mattered to the seller. The study frames the risk as a foreign actor acquiring such data for targeting, blackmail or influence operations — and that risk does not require a breach, a hack, or anything unlawful by the buyer.

A lawful purchase at twelve cents a head is a harder problem than a breach. There is no incident to disclose, no vulnerability to patch, and no obvious moment at which anyone did anything wrong.

2024: a car maker's cloud, including a police fleet

The third episode brings it back to vehicles. In December 2024, the Chaos Computer Club reported that Cariad, Volkswagen's software subsidiary, had left location and personal data for roughly 800,000 electric vehicles in an unprotected cloud store. In about 466,000 cases the data was precise enough to reconstruct a daily routine.

The exposed set reportedly included German politicians, business figures, suspected intelligence service employees, and the entire electric fleet of the Hamburg police.

That last detail is the clearest illustration of the whole argument. A police fleet's movement history is operational information: where unmarked vehicles go, which addresses they visit, how patrols are distributed by hour. It was exposed not through espionage but because a cloud bucket was misconfigured, and the owners of those vehicles had no way to know, no way to check, and no setting that would have prevented it.

Full detail on that case, and the Subaru portal flaw that exposed a year of location history at roughly five-meter accuracy, is in When Connected Cars Get Hacked.

Why vehicles are the sharper version of this problem

Compared with a phone or a fitness tracker, a connected car is an unusually good surveillance device, for reasons that have nothing to do with intent:

  1. It cannot be left at home. A tracker is optional and removable. The vehicle is the thing making the journey.
  2. It has its own connection. Most modern vehicles transmit over an embedded cellular modem, so there is no phone to put in a drawer and no app to delete.
  3. It records events, not just positions. Braking, acceleration and cornering are logged with times attached, which distinguishes a commute from a pursuit.
  4. Retention is long. The Subaru case showed a full year of history held at high precision.
  5. Fleets cluster. Agencies buy vehicles in batches from one manufacturer, so one company's data often covers an entire department.

Point five is the one that converts a privacy issue into a security one. An individual's commute is not sensitive. Every vehicle belonging to one agency, in one system, is a different kind of object.

What is being done, and what it misses

The Commerce Department's connected vehicle rule, effective March 2025, is the clearest official response. Its stated concern is that suppliers subject to a foreign government's direction could be compelled to hand over data or permit remote access — a framing about compulsion, not consent. We cover its scope and timeline in Who Builds the Box in Your Car.

Its limit is equally clear. The rule addresses foreign-linked suppliers in future model years. It says nothing about a domestic manufacturer selling driving data to a domestic broker, which is what California's $12.75 million settlement with General Motors in May 2026 concerned, and nothing about a broker selling to whoever asks, which is what the Duke study measured.

What an individual can actually do

We should be straight about the ceiling here. If you are a service member, a government employee or a first responder, nothing on this page is solved by a personal opt-out, because the exposure comes from aggregation rather than from your own record. Reducing your own footprint is still worth doing — it is simply not a substitute for institutional policy.

What is in reach:

For the step-by-step requests, see How to Stop Car Companies From Collecting Your Data. For how the commercial pipeline fits together, start at Your Car Is Reporting on You.

Delete Your Data from 1,475 Data Brokers

The Duke researchers bought service member data from brokers for twelve cents a record. We send legal CCPA deletion demands to 1,475 data brokers and file FCRA disclosure requests with the consumer reporting agencies that hold driving data — so you can see what is on file and demand its removal. Automated 45-day re-checks. $9.95/month.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.