Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • August 8, 2017
    Guidelines on cyber security for connected and automated vehicles ‘doesn’t go far enough’
    David Barzilai, chairman and co-founder of automotive cyber-security firm, Karamba Security, has applauded the UK government for taking pre-emptive action and zeroing in on preventing cyber-attacks as critical for the adoption of self-driving cars on a mass scale. However, he says the guidelines don’t go far enough toward effectively preventing car hacking, saying cars are not servers or mobile phones that can sustain the risk of hidden security bugs. The time it takes to remediate such bugs in production,
  • May 12, 2016
    Nissan and Enel launch vehicle-to-grid project in the UK
    Automotive manufacturer Nissan and multinational power company Enel are to launch a major vehicle-to-grid (V2G) trial in the UK, which will see one hundred V2G units installed and connected at locations agreed by private and fleet owners of the Nissan LEAF and e-NV200 electric van. By giving Nissan electric vehicle owners the ability to plug their vehicles into the V2G system, owners will have the flexibility and power to sell stored energy from their vehicle battery back to the National Grid. The annou
  • May 16, 2012
    Nissan Leaf gets top safety rating from Euro NCAP
    Euro NCAP (the European New Car Assessment Programme) has awarded the 100% electric Nissan Leaf the highest five star car safety rating following its performance in the independent organisation's stringent crash tests. It is the first electric vehicle ever to earn this distinction.
  • February 23, 2021
    CVs vulnerable to ‘low skill’ cyberattacks: report
    17% of potential attack scenarios on connected vehicles identified as high-risk, finds Trend Micro