Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • eVolt chargepoints support new fleet of EVs at Taxi Central
    February 7, 2017
    Electric vehicle chargepoint supplier eVolt has completed the installation of three rapid chargers for a Scottish taxi business to support its five new private hire Nissan Leaf EVs, which are now fully operational. Kirkcaldy-based Taxi Central has installed one of eVolt’s, which can charge the 30kWh Nissan Leafs to 80% battery life in 30 minutes, to provide on-shift EVs with essential charging capability; and two eVolt AC 7kW Wall-mount Chargers that fully charge the EVs in around 5 hours. The funding
  • Access and Irdeto partner to protect in-car data and services
    January 22, 2019
    Security specialist Irdeto has teamed up with Access Co to develop protection for the increasing amount of personal data that is generated by Wi-Fi, Bluetooth and Vehicle to Everything (V2X) communication. As cars are increasingly turned into open environments due to advances in connectivity, the threat of data theft has risen. Niels Haverkorn, general manager of connected transport at Irdeto, says: “We are partnering with Access to create a complete and secure ecosystem, which means that V2X communicatio
  • US and UK Respondents call for stricter data security regulations for Connected Cars
    November 28, 2017
    Over 40% of both 1,000 US and UK adult consumers who took part in a new study feel that the government should apply stricter data security regulations for connected cars (CCs), according to Thales’ E-Security IoT Survey. A combined 60% of both respondents believe that CCs pose security concerns with integrity and malfunctions at the top of the list of apprehensions when asked to identify internet-connected devices which they felt were most vulnerable to hacking.
  • Europe's electronic toll service closer to operational reality
    November 7, 2012
    After much debate and delay, a unifying European Electronic Toll Service is now finally on the horizon, says ASFiNAG’s Klaus Schierhackl. Here, he talks with Jason Barnes about what that might mean. Aworkable European Electronic Toll Service (EETS) which will allow truck drivers to travel across the continent and pay tolls using a single account and OnBoard Unit (OBU) was originally timetabled to be in place and operating by October of this year. A lack of urgency from some of the stakeholders involved in t