Can Cars Actually Be Hacked?
Yes, though the practical risk looks different than the dramatic scenarios sometimes portrayed in media coverage. Modern vehicles contain dozens of electronic control units (ECUs) communicating over internal networks, most commonly the Controller Area Network (CAN bus), which was originally designed decades ago without strong security considerations, since it wasn't built anticipating internet connectivity or remote access. Security researchers have demonstrated various vulnerabilities in vehicle systems over the years, including some notable, publicly documented cases where researchers successfully accessed vehicle systems remotely under controlled research conditions.
That said, most documented vehicle hacking demonstrations have occurred under specific research conditions, often requiring either physical access to the vehicle or exploiting a specific, since-patched vulnerability in a particular vehicle's connected systems, rather than reflecting an easy, widespread, ongoing threat to typical drivers. Automakers have also invested significantly in vehicle cybersecurity following high-profile research disclosures, including establishing dedicated security response processes similar to those used in traditional software industries.
What Actually Makes Modern Cars More Vulnerable Than Older Ones
The increase in vehicle connectivity β infotainment systems with internet access, smartphone app integration, over-the-air software updates, and built-in cellular connectivity for features like remote start or emergency services β expands the potential attack surface compared to older vehicles without this level of connectivity. Each connected feature represents a potential entry point that security researchers and, in principle, malicious actors could theoretically target, which is a genuine tradeoff of the convenience these features provide.
Automakers have generally responded to this expanded risk by implementing network segmentation, keeping critical safety systems (steering, braking) on separate, more isolated networks from less critical, more connected systems (infotainment, entertainment), specifically to limit how much access a vulnerability in a less critical system could provide to safety-critical vehicle functions.
What Data Your Car Is Actually Collecting
Beyond hacking risk, it's worth understanding that modern vehicles collect substantial data as part of their normal, intended operation, not through any kind of breach or unauthorized access. This typically includes location and trip history through built-in GPS and connectivity features, driving behavior data like acceleration, braking patterns, and speed, often used for features like automatic emergency response or, in some cases, usage-based insurance programs, and vehicle diagnostic data monitoring the health and performance of various vehicle systems.
Many automakers have specific data-sharing partnerships with third parties, including insurance companies and data brokers, and this has drawn increasing regulatory and media scrutiny in recent years, with several automakers facing public criticism and, in some cases, legal action over how driving behavior data was collected and shared, sometimes without sufficiently clear consumer disclosure or consent processes.
Why This Data Collection Matters
This data collection isn't inherently nefarious β much of it genuinely supports features drivers actively want, including automatic crash detection and emergency response, remote vehicle diagnostics, and personalized services through connected apps. The concern isn't that this data collection exists at all, but rather how transparently it's disclosed to consumers, how it's used beyond its original stated purpose, and whether meaningful consumer consent and control exists over secondary uses like data sharing with insurance companies or other third parties.
Several state regulators and consumer protection agencies have specifically investigated automaker data practices in recent years, reflecting genuine, ongoing regulatory attention to this issue rather than a settled, fully resolved area of consumer protection law.
Practical Steps to Understand and Manage Your Vehicle's Data Practices
Check your vehicle's specific privacy policy and data-sharing disclosures, typically available through the automaker's website or your vehicle's owner documentation, to understand exactly what data your specific make and model collects and whether it's shared with third parties like insurance companies. This information isn't always prominently advertised, making it worth a deliberate search rather than assuming standard practices apply universally across all vehicles.
Review connected app permissions and settings within your vehicle's companion app, since many automakers provide at least some user controls over data sharing, location tracking, and driving behavior monitoring features, even if these controls aren't always the default, most visible setting within the app.
Keep your vehicle's software updated through official manufacturer channels, since over-the-air updates often include security patches addressing newly discovered vulnerabilities, similar to how software updates function on phones and computers.
What to Avoid
Avoid connecting unofficial or unverified third-party devices to your vehicle's onboard diagnostics (OBD-II) port, since this port provides fairly direct access to vehicle systems, and unofficial devices from unverified sources could introduce genuine security risk beyond whatever functionality they're marketed to provide. It's also worth being cautious about aftermarket connected accessories that request extensive vehicle data access without a clear, specific reason tied to their actual advertised function.
FAQ
Can someone hack my car while I'm driving it? This remains a genuinely rare, largely research-demonstrated scenario rather than a common real-world threat for typical drivers, though it underscores why keeping vehicle software updated and being cautious about unofficial connected devices remains reasonable practice.
Is my car sharing my driving data with my insurance company without my knowledge? This varies by automaker and specific vehicle, and some documented cases have involved data sharing that wasn't clearly disclosed to consumers, making it worth specifically checking your vehicle's privacy policy and any connected app settings to understand your specific situation.
Can I opt out of my car's data collection entirely? This depends on your specific vehicle and automaker, with some data collection tied to core safety features that can't be fully disabled, while other data-sharing features, particularly those involving third-party sharing, may have opt-out options worth actively seeking out in your vehicle's settings.
Are older, less connected cars safer from these concerns? Generally yes, from a pure cybersecurity attack surface perspective, since older vehicles with fewer connected features have fewer potential entry points, though they also lack the safety and convenience benefits that connectivity provides, representing a genuine tradeoff rather than a clearly superior alternative.
π Sources
National Highway Traffic Safety Administration β Vehicle Cybersecurity Research
Federal Trade Commission β Connected Cars and Consumer Privacy
Mozilla Foundation β Privacy Not Included: Car Data Practices





























