Bay Street Wire
Tech & BusinessOpinion

The Blind Spot in the C-Suite: Connected Vehicles Are the Newest Data Leak

Portrait of Rachel Moreau
Rachel Moreauenterprise & SaaSOct 4AI
The Blind Spot in the C-Suite: Connected Vehicles Are the Newest Data Leak

AI-generated image · Bay Street Wire

Opinion: Enterprise security leaders are ignoring a massive, unregulated data-harvesting goldmine emerging from the automotive industry's pivot to software-defined vehicles.

For years, enterprise security leaders have obsessed over the 'smartphone in the pocket'—securing mobile endpoints and scrubbing third-party trackers from corporate apps. But there is a massive, unregulated data-harvesting goldmine sitting in the company parking lot that is being completely ignored: the connected vehicle.

As the automotive industry pivots toward software-defined vehicles, cars have effectively become smartphones on wheels. As researchers at Northeastern University first reported in a study conducted in partnership with Consumer Reports, over 75% of vehicles sold globally now feature built-in connectivity via cellular, Wi-Fi, and GPS. While the ROI for manufacturers is clear, the risk for the enterprise is a gaping hole in the data perimeter.

In my view, the current corporate approach to vehicle connectivity is dangerously naive. We treat the company car as a piece of hardware, but the Northeastern University research proves it is a data conduit. In their measurement study of 21 late-model vehicles and 30 companion mobile apps, researchers found that 19 of the 21 vehicles tested sent traffic to at least one third party over Wi-Fi.

The study reveals a systemic leak of sensitive information: seven of the 30 companion apps transmitted sensitive identifiers to third-party companies, and five of those apps sent Vehicle Identification Numbers (VINs) along with other personally identifiable information (PII) to trackers.

From an operational standpoint, the danger is the lack of visibility. The Northeastern University report notes that once data leaves the device, it is up to the receiving companies to decide what happens to it—often including selling or sharing data with undisclosed third parties, including advertisers and insurance companies.

Security leaders often argue that encryption protects this data. However, the Northeastern University team identified the destinations of this traffic using a custom access point on a Raspberry Pi and tcpdump. Even when the content of the packets is encrypted, the metadata provides a roadmap of data exfiltration.

If your security strategy doesn't account for the data flows of the vehicles your employees use, you aren't managing your perimeter—you're just hoping the manufacturers are benevolent. It is time to stop treating the connected car as a utility and start treating it as a high-risk endpoint.

Sources

More from Rachel Moreau