Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Ministers to urge use of ‘drive safe’ modes for mobile phones
    December 20, 2016
    An informal meeting in Whitehall is due to take place early in 2017, according to the Guardian, in which ministers and officials will tell mobile companies that ‘drive safe’ modes, similar to the airplane mode that has become standard, must be included in basic software ahead of a broader crackdown on illegal mobile phone use on the roads. In spring 2017, the fixed penalty for using a mobile phone while driving without a hands-free device will double to US$248 (£200). The fixed penalty notice will increa
  • Cloud-based app paves way for near field ticketing
    December 17, 2013
    Cubic latest introduction provides a short cut for transit authorities looking to offer travellers mobile, smart phone payment options. Transit operators wanting to provide travellers with a mobile fare payment option now have an ‘off-the-shelf’ solution in Cubic’s NextWave. Through the use of near field communications (NFC) technology, NextWave turns travellers’ mobile phones and tablets into the equivalent of a ticket vending machine able to instantly re-load contactless transit cards. It also enables the
  • South Africa launches electric vehicle pilot programme
    February 28, 2013
    South Africa’s Department of Environmental Affairs (DEA) has launched a zero emission electric vehicle pilot programme, which would see it trial a fleet of electric vehicles. Speaking at the launch, water and environmental affairs minister Edna Molewa said the multi-stakeholder partnership project would pilot, test and demonstrate the viability of electric vehicles under South African conditions. The pilot programme would also serve to determine end-user, infrastructure and running costs associated with loc
  • Transit in a time of protest
    July 13, 2020
    Street demonstrations at times create tricky balancing acts for public transportation providers - and the recent Black Lives Matter protests have also put a spotlight on the deeper problem of ‘infrastructural racism’…