A Northeastern University and Consumer Reports study of 21 connected vehicles spanning 19 brands and 30 companion apps found widespread communications with third-party advertising, tracking, analytics, and technology domains. Researchers observed traffic during driving and idle tests, using DNS requests, TLS Server Name Indication, timing, and transfer volumes to identify destinations despite encryption. Nineteen of 21 vehicles contacted at least one third party over Wi-Fi; Tesla’s Model 3 contacted 34 advertising, tracking, and analytics domains and 37 infotainment-app domains, while Alphabet domains were the most frequently observed, including doubleclick.net and googlesyndication.com.
The observed sharing could expose or link VINs, precise location, names, email addresses, vehicle identity, and travel patterns to advertising or data-broker profiles. Seven companion apps transmitted sensitive identifiers to tracking-associated third parties, and consumers may face substantial feature loss if they decline connected-services terms; Tesla warned refusal could reduce functionality or make a vehicle inoperable. Following disclosure of the findings, Honda said it directed Amplitude to delete received location data and stopped sending location data to that vendor.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
After researchers presented their findings, Honda said it directed Amplitude to delete location data it had received and stopped sending location data to the vendor.
The researchers found that 19 of 21 tested vehicles contacted at least one third party over Wi-Fi, including advertising and tracking-related domains; seven companion apps also transmitted sensitive identifiers to such third parties. Tesla's Model 3 contacted 34 advertising, tracking, and analytics domains, while Alphabet domains were the most frequently observed across the tested vehicles.
Northeastern University and Consumer Reports researchers evaluated 21 connected vehicles across 19 brands and 30 companion applications while vehicles were stationary, driving, and used through their apps. The vehicles tested were model years 2022 through 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcearstechnica.com
Open sourceconsumerreports.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.