Study finds every modern car leaks driver data to third-party trackers
Researchers from Northeastern University and Consumer Reports found that all 21 examined vehicles transmitted data to external domains, many of which belong to advertising firms.
A research team from Northeastern University, in partnership with Consumer Reports, systematically examined the data flows of 21 late-model vehicles representing 19 U.S. brands and 30 associated mobile apps. By installing a Raspberry Pi on each car’s Wi-Fi and employing a car-sized Faraday tent to force cellular fallback to a controlled hotspot, they captured outbound traffic and identified connections to numerous third-party domains, including advertising and analytics providers like Adobe, LexisNexis and Amplitude.
Every vehicle transmitted data to at least one external server, and more than half communicated with advertising-tracking services, especially those equipped with Google’s Android Automotive OS. Seven companion apps—including HondaLink and MyNissan—relayed sensitive details such as VINs, phone numbers and exact locations to ad networks, enabling detailed driver profiling. While some manufacturers defended the practice as lawful, Honda pledged to delete collected location data and halted geolocation transmission in its app. The researchers warn that most drivers are unaware of these extensive data collections and call for clearer opt-in mechanisms and greater transparency.
Why it matters
Drivers’ personal and location data are being shared widely without clear consent, raising privacy and security concerns.
In this story
