Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • November 28, 2016
    San Francisco transit systems targeted by hackers
    San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
  • September 24, 2015
    Volkswagen emissions – ‘a missing global standard is the issue’ say UK organisations
    The UK’s Transport Research Laboratory (TRL) and research organisation Frost and Sullivan have both commented on the Volkswagen diesel emissions scandal, which has resulted in the resignation of CEO Martin Winterkorn. The world's biggest carmaker by sales has admitted to US regulators that it programmed its cars to detect when they were being tested and altered the running of their diesel engines to conceal their true emissions. Winterkorn said, “I am shocked by the events of the past few days. Above
  • November 14, 2016
    Connected car data – both opportunities and challenges for auto OEMs, says KPMG
    Data collected through connected cars will present automakers with tremendous business opportunities to enhance customer experiences while at the same time also posing inherent risks, according to a new KPMG report, Your Connected Car is Talking: Who's Listening? KPMG's national automotive leader, Gary Silberg, notes that, while OEMs can use data collected through connected vehicles to optimise performance, reliability and safety of vehicles they produce, failure to get cyber-security right could have a
  • September 25, 2019
    BlackBerry’s Jeff Davis: ‘Hands off 5.9GHz!’
    As a US Marine, BlackBerry’s Jeff Davis saw the world’s trouble spots. But much of his attention is now focused on what he sees as the ITS sector’s biggest issue: cybersecurity. Adam Hill finds out more Oh, I often feel I’m the dumbest guy in the room,” laughs Jeff Davis, senior director, connected transportation, at BlackBerry. It’s hard to credit this. Davis has a range of experience that sets him apart from most people in the ITS sector. He was in the US Marine Corps, with seven tours of duty, inclu