Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • February 2, 2012
    Variable message signs continue to deliver travel information
    Arguably the 'face' of ITS, variable message signs are far from being a passing solution
  • September 8, 2015
    Over-the-air software updates to benefit for automotive market, IHS says
    While quite common in smartphones and personal computers, remote over-the-air (OTA) software updates are still only in their infancy in the automotive space, according to a new report from IHS Automotive. The report finds that OTA software updates will eventually be a big benefit for the automotive industry due to their capacity to reduce warranty costs, potentially increase overall completion rates for software-related recalls, improve customer satisfaction by eliminating trips to the dealership for so
  • April 23, 2013
    New York launches electric taxi pilot
    To celebrate Earth Day, Nissan and New York City Mayor Michael Bloomberg have launched a new electric vehicle taxi pilot with the Nissan Leaf, putting six Leaf taxis into service to help Nissan, the city, the taxi industry and the public understand how zero emission vehicles can be integrated into future taxi fleets. As part of the pilot, Nissan and partners in New York City will also install several CHAdeMO-based DC quick chargers, which will enable drivers to re-charge their electric taxis quickly during
  • June 7, 2018
    Gridsmart tackling infrastructure security threat
    A new division, formed by Gridsmart Technologies only three weeks ago, is making its public debut here at ITS America Detroit. Gridsmart Information Security & Threat Intelligence (ISTI) is an industry first-of-its-kind transportation cybersecurity group dedicated to providing vulnerability/threat assessments and tailored security strategies. It will work with private companies, departments of transportation, and others to proactively defend and enhance the resiliency of their technical infrastructure