Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Supply chain issues: AGD looks ahead
    June 2, 2022
    There are multiple causes for current global supply chain issues – and this isn’t likely to improve in the near future. Ian Hind of ITS manufacturer AGD Systems spells out how to mitigate the impact
  • Helsinki’s residents trial MaaS as alternative to private cars
    August 21, 2018
    Would you give up your own car? Helsinki implemented MaaS late last year and Colin Sowman discovers that the initial reaction has been positive What would it take for you to give up your own car? That is the question posed by Sampo Hietanen, the so-called ‘father’ of Mobility as a Service (MaaS) and CEO of MaaS Global. And he is about to discover if MaaS really will convince the people of Helsinki to do the unthinkable. MaaS Global introduced a fledgling version of its Whim app in the city in late 2016
  • What Citizen Kane can teach transportation engineers
    July 14, 2023
    Andy Boenau suggests that one of the most famous movies of all time might have lessons for our industry. And they’re all about not knowing things...
  • A global standard for enforcement systems – is it necessary?
    May 30, 2013
    Jason Barnes speaks to leading figures from the automated enforcement sector about whether a truly international standard for automated enforcement systems is necessary or can ever be achieved. Recent reports of further press controversy in the US over automated enforcement (see ‘Focusing on accuracy?’, ITS International raise again the issue of standards and what constitutes ‘good enough’ in terms of system accuracy and overall solution effectiveness. Comparatively, automated enforcement has always expe