Connected Cars Talk to Google and Ad Trackers While Seven Car Apps Hand Over the Owner's VIN
Ethical Hacking Complete Course Zero to Expert
Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.
→ Take the full courseConnected Cars Talk to Google and Ad Trackers While Seven Car Apps Hand Over the Owner’s VIN
19 of 21 new cars talked to outside companies over WiFi, and 13 reached Google. That was the factory setup. Seven car apps went further and sent the VIN to tracking firms, some with email and location.
Researchers at Northeastern University wanted to know who a new car talks to once it goes online. So they went to the Auto Test Center of Consumer Reports in Connecticut and tested 21 cars from 19 brands, model years 2022 to 2025, between October 2024 and August 2025.
Consumer Reports buys the cars it tests. That gave the researchers a lot full of new cars to work with. Buying those 21 themselves would have cost them more than 1.2 million dollars.
According to the researchers’ project site, more than 75 percent of cars sold today come with an internet connection built in.
The researchers built their own WiFi hotspot on a Raspberry Pi, connected each car to it, and logged the traffic.
Each car went through three rounds. First 30 minutes parked and untouched. Then 30 minutes parked while someone opened the doors and the trunk, pressed the dashboard buttons and clicked through the menus and apps on the screen. Then 15 minutes of driving on the test center’s private roads, with hard braking and swerving thrown in.
The cars encrypt what they send. The researchers tried to put themselves in the middle of the connection with a certificate of their own, the file a device checks before it trusts a connection. That trick is called a man-in-the-middle, and it is the usual way to read encrypted traffic. The cars refused it. The messages themselves stayed unreadable.
What the researchers could read were the names. Before a car opens a connection, it looks up the name of the server it wants to reach, and it says that name again when the connection starts. Those two are called the DNS lookup and the Server Name Indication, or SNI. That is enough to see who a car is talking to.
Out of 21 cars, 19 talked to at least one company that was not the carmaker.
11 of them went further and contacted web addresses, or domains, that are there for advertising, tracking or analytics. On average 8.7 of those per car.
13 cars reached domains owned by Google, including doubleclick.net and googlesyndication.com. Those two serve ads. According to the researchers, a car does not need them to work.
Amazon showed up in the traffic of 12 cars. Spotify showed up in 8 and SiriusXM in 7, and those two stream music to the dashboard. According to the researchers, their domains may also collect tracking data.
The top of the list:
- โ Tesla Model 3: 34 advertising and tracking domains
- โ Tesla Cybertruck: 23
- โ Cadillac Lyriq: 10
- โ Lucid Air: 9
- โ Chevrolet Blazer: 7
- โ Honda Prologue: 5
Look at the software in the dashboard and the list makes sense. The cars with a big touchscreen that runs maps, music and apps, called the infotainment system, contacted the most trackers. So did the cars running Android Automotive, Google’s operating system for cars, with Google’s own services built in.
At the other end, the Mercedes EQS and the Buick Envista only talked to their own maker. The Buick is the strange one here. It comes from the same maker, GM, as the Cadillac and the Chevrolet from the top of the list, but it does not run that software. The researchers think that is why it stayed so quiet.
Some cars behaved differently on the road. The Land Rover, the Mercedes and the Nissan switched their WiFi off as soon as they left Park. The Teslas have a setting that keeps WiFi on while driving, and the researchers switched it on. On the road, the Cybertruck contacted 19 more outside domains and 7 more tracking domains than when it stood still.
Then they drove 11 electric cars into a tent that blocks mobile signals. It is called a Faraday tent, and this one was 5.8 by 2.75 meters. They only used electric cars for this, because running a combustion engine inside a closed tent is dangerous.
With the mobile network gone, 7 of the 11 cars sent more over WiFi, including trackers the researchers had not seen outside the tent. The Tesla Model 3 contacted 27 more tracking domains inside, the Cybertruck 14 more.
The Model 3 was also the only car with a SIM card slot they could reach. They put in a card of their own and ran a small mobile network inside the tent. Now they could see the car’s mobile traffic too, and they found an analytics domain, conviva.com, that only showed up there. When they cut the mobile connection, the same domain moved over to WiFi.
So the researchers call their numbers a lower bound: the true count can only be higher. For 20 of the 21 cars, they could not see the mobile connection at all. Co-author Sarah Elizabeth Gillespie put it plainly: it does not look like you can still buy a new car that does not track you.
Then came the apps. Carmakers give you an app for your phone. With it you open the doors, check the battery, find a charger or open the trunk.
The researchers tested 30 of those apps on their own iPhones. A Consumer Reports employee logged in with the existing account tied to each car. The researchers said yes to the permission requests for tracking, location, calendar and Bluetooth, and then went through the functions one by one.
This time they could read the contents. The traffic ran through phones they controlled, so they could open the encryption and see what was inside.
The apps were far worse than the cars. 70 percent of the apps contacted more than five tracking domains, against 29 percent of the cars. The Buick, the car that only talked to its maker, picked up 23 tracking companies once its app came into play. The Nissan Ariya picked up 25.
Seven apps sent personal data to companies that do advertising, tracking or analytics:
- โ HondaLink sent the VIN and the precise location to Amplitude
- โ MyNISSAN sent the VIN and the email address to Alchemer
- โ The Lincoln app sent the VIN to ContentSquare
- โ myCadillac, myChevrolet, myBuick and myGMC sent the VIN to Adobe, Acxiom, ContentSquare, FullStory, Google, Meta, Microsoft, Pinterest, Snap and Yahoo
- โ All four GM apps sent the email address to Adobe, and three of them also to ContentSquare
- โ myCadillac and myGMC sent the location to ContentSquare, myChevrolet to Adobe, and myGMC added the phone number
Acxiom is a data broker, a company that collects information about people and sells it on. David Choffnes, the cybersecurity professor who worked on the study, told the university that the researchers do not know what those companies do with the data.
The VIN is the vehicle identification number, assigned to your car at the factory and visible through the windshield.
Someone walking past can read it. Once an app sends it along with your email address, a company knows that car belongs to you. Your phone lets you reset its advertising ID, the number apps use to recognize you for ads. A VIN cannot be changed. The researchers point out that a company holding both can link the car to what you do and buy on other websites and apps.
Four of those seven apps belong to General Motors. And GM was already in trouble over driver data.
In January 2025, the FTC, the US agency that protects consumers, accused GM and OnStar of collecting and selling drivers’ exact locations and driving behavior without properly asking them first. On January 14, 2026, the settlement became final.
For the next 20 years, GM has to ask for clear permission before it collects, uses or shares data from its connected cars. For five years, it may not hand location or driving data to consumer reporting agencies, the companies that keep files on people.
The study ran from October 2024 to August 2025, so the case was already open while the researchers were testing. GM told the university it only shares data with service providers under strict contracts.
California went after GM too. From 2020 to 2024, the company sold the names, contact details, locations and driving behavior of hundreds of thousands of Californians to two data brokers, Verisk and LexisNexis. On May 8, 2026, it settled for 12.75 million dollars, the biggest fine ever under California’s privacy law. It has 180 days to delete that driving data, and it has to ask both brokers to delete theirs.
In May 2025, the researchers read the privacy policies of those seven apps. The carmakers wrote that they may share your personal data with other companies. Which companies, and why, they did not say.
Nissan even argued that sharing your VIN is better for your privacy than sharing other fixed IDs.
After the tests, the researchers wrote to 17 carmakers. They skipped Fisker, which had already gone out of business. 14 wrote back.
Each of the 14 said the data went where their contracts allowed it to go.
Five pointed at the browser inside the app. Tap a link in the app, a web page opens, and that page brings its own trackers. Three of them added that you get a cookie prompt there. The researchers went back through their screen recordings. The prompt did not always appear.
Seven said the software in the car comes with its own terms, and that reading and accepting those is the owner’s job.
Tesla takes it one step further in its privacy notice. Opt out of vehicle data collection, and the company says it can no longer warn you about problems with your car as they happen. The car may then end up with fewer working functions, serious damage, or not working at all. That is the choice Tesla gives you.
One carmaker changed course. Honda’s own policy calls the VIN commercial information that may be used for marketing. After the researchers showed their findings, the carmaker asked its analytics company to delete the location data from the app. It also updated the app, so the location no longer goes there.
The study will be presented at the Internet Measurement Conference in Karlsruhe, October 12 to 16.
What you can do with your own car and app:
- โ Set location access for the car’s app to “while using”, never “always”
- โ Skip links inside the app that open web pages
- โ Factory reset the car’s screen before you sell it or trade it in
- โ GM drivers in the US can request a copy of their data under the FTC settlement and ask GM to delete it
Want to see who your devices talk to? Capture at your router or your own access point with Wireshark and read the server names. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.
โ Join my complete ethical hacking course
Hacking is not a hobby but a way of life.
Sources:
Automatic Transmission study, Northeastern University | FTC final order on GM and OnStar | California Attorney General on the GM settlement
Stay updated
Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.