Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • March 29, 2017
    Technology solution needed to counter mobile phone menace
    With the UK set to increase the penalties for using mobile phones while driving, the RAC Foundation’s Steve Gooding considers what else can be done to combat this deadly distraction. The first mobile phone call was made in 1973, by an engineer working for Motorola. Today 4.7 billion people across the globe subscribe to a mobile service.
  • September 7, 2017
    Ricardo and Roke Manor to collaborate on next-generation vehicle cyber security
    International technology company Ricardo is to join forces with cyber security specialist Roke Manor Research to develop solutions that will make autonomous and connected transport robust against cyber attack. Many of today’s new vehicles are already connected over the air for telematics and maintenance, for safety systems such as eCall, by consumers using insurance-based monitoring technology, and by the many smartphone apps available to vehicle owners.
  • January 23, 2012
    ANPR - cost-efficient traffic management, enforcement and more
    Geoff Collins of Vysionics Intelligent Traffic Solutions talks about the near-term prospects of ANPR. The continued absence of a champion for its cause is preventing digital enforcement technology from delivering the true levels of cost-effectiveness of which it is capable, according to Geoff Collins, sales and marketing director of ANPR specialist Vysionics Intelligent Traffic Solutions.
  • May 31, 2013
    Navigating a path towards greater safety
    Eric Sampson takes a look at why the European Union’s eCall system is taking rather longer to arrive than it should. There’s an old story about the person who asked an Irishman for directions and after much thought he responded: “If you’re going there from here it would be better to start from somewhere else.” This came to mind when I was recently reflecting on eCall and wondering when it will come - some stakeholders say the answer is never. So despite years of workshops and discussions, eCall is still not