TECH/Tech/TSLA

Connected Cars Remain a Privacy Nightmare, New Northeastern and Consumer Reports Study Reveals

A comprehensive new study conducted by researchers at Northeastern University and Consumer Reports reveals that connected vehicles actively transmit user telemetry and tracking data to advertisers, tech giants, and analytics firms. The findings demonstrate that utilizing companion smartphone applications dramatically multiplies privacy exposure for drivers across the United States.

By Nexvoro Tech Wire
PUBLISHED TUE, SEP 29, 2026 6:30 PM UTC • 7 MIN READ
CNBC Market Tracker • NASDAQ:TSLA
REAL-TIME QUOTE
Tesla Inc
$228.40-14.20 (-5.85%)
Volume: 68.4M
52-Wk Range: $138.80 - 271.00

KEY POINTS

  • •A joint study by Northeastern University and Consumer Reports evaluated 21 connected cars across 19 brands, uncovering extensive data-sharing with advertisers, trackers, and tech firms like Microsoft and Adobe.
  • •Tesla's Model 3 contacted 34 advertising and tracking domains and 37 infotainment app domains, while Alphabet domains were the most frequently contacted overall across the industry.
  • •Using connected car companion apps significantly multiplies privacy exposure, with General Motors, Toyota, and Nissan identified as the worst offenders for third-party tracking integration.
  • •Automakers defended their data practices by claiming third parties are bound by contracts restricting PII usage, though these are governed by the same privacy agreements criticized previously by the Mozilla Foundation.
Connected Cars Remain a Privacy Nightmare, New Northeastern and Consumer Reports Study Reveals
PHOTO VIA ARS TECHNICANEXVORO EDITORIAL WIRE

The Anatomy of Connected Vehicle Surveillance

In findings that will surprise very few privacy advocates, modern connected cars continue to operate as a complete privacy nightmare for consumers navigating America's roadways. A groundbreaking new study conducted by a dedicated team of researchers at Northeastern University, working in tandem with Consumer Reports, has provided unprecedented clarity regarding the vast quantities of data modern automobiles siphon away from drivers and passengers. By rigorously testing 21 connected vehicles representing 19 distinct automotive brands, the research initiative uncovered deeply troubling patterns of network traffic flowing directly to advertisers, data trackers, and prominent Big Tech corporations, including tech titans Microsoft and Adobe.

This empirical investigation builds upon a heavily covered 2023 report published by the Mozilla Foundation, which analyzed the privacy policies of more than two dozen major automakers and concluded that cars represent "the worst product category we have ever reviewed for privacy." However, while the Mozilla analysis relied exclusively on reviewing dense corporate privacy documentation, the Northeastern and Consumer Reports study took a hands-on approach. Researchers measured live network traffic emanating from actual physical cars across a variety of operational scenarios, including stationary idling and active driving on public roadways, to map out precisely where sensitive driver data travels.

Technical Methodology and Encryption Hurdles

To peer inside the digital transmissions leaving these modern vehicles, the research team deployed sophisticated network monitoring equipment. However, initial attempts to inspect the precise payloads contained within the intercepted data packets using modified certificates failed in every single test instance due to robust encryption protocols. Despite these cryptographic roadblocks, the researchers emphasize that network traces still yielded an immense treasure trove of valuable diagnostic and behavioral information, confirming corporate surveillance practices across the modern automotive sector.

Among the data points successfully captured by the research team were the specific domains contacted via Domain Name System (DNS) traffic, Server Name Indication (SNI) data captured during Transport Layer Security (TLS) handshakes, the exact volume and timing of data transmissions, and distinct behavioral variations across experimental driving and idling scenarios. Every single vehicle evaluated successfully contacted at least one first-party domain belonging directly to the original equipment manufacturer (OEM), which is an inherent operational requirement for connected vehicle ecosystems. While a select few models - specifically the Buick Envista and the Mercedes-Benz EQS - largely confined their digital chatter to these necessary first-party corporate servers, many other popular models proved to be alarmingly promiscuous in their external communications.

The Corporate Footprint and Big Tech Penetration

At the top of the telemetry charts sat Tesla, whose Model 3 contacted a staggering 34 distinct advertising, tracking, and analytic domains, alongside an additional 37 domains originating from third-party applications deeply integrated directly into the vehicle's onboard infotainment system. Across the broader market landscape, domains controlled by Alphabet emerged as the most frequently contacted third-party destinations. While this heavy interaction with Alphabet infrastructure is hardly surprising given the deep market penetration of its Android Automotive operating system throughout the contemporary automotive sector, researchers noted a more insidious reality underlying the network flows.

Specifically, the study authors highlighted that many of the second-level domains observed during testing were entirely unnecessary for delivering core vehicle services. Prominent examples included tracking destinations such as doubleclick.net and googlesyndication.com, which are deployed primarily for digital advertising and behavioral monetization purposes rather than vehicle diagnostics or navigation. Furthermore, the testing revealed that media streaming applications - including popular platforms like Spotify and Sirius XM - alongside dedicated mapping and location companies such as HERE, TomTom, and Mapbox, maintained heavy representation across the network traces.

Infotainment Usage and Faraday Cage Discoveries

When evaluating how driver interactions influence data exfiltration, the research team discovered that utilizing a vehicle's onboard infotainment system consistently resulted in the highest volume of contacted domains compared to simply letting the car sit idle or driving without active infotainment engagement. The notable exception to this rule was the Tesla Cybertruck, which uniquely demonstrated an aggressive spike in network activity while in motion, contacting 26 more third-party domains while actively being driven than it did while sitting completely stationary.

To isolate cellular data transmissions from external network interference, researchers parked 11 electric vehicles inside a specialized Faraday tent - a measure necessitated by the carbon monoxide hazards of running internal combustion engines within an enclosed fabric structure. Cut off entirely from a standard cellular network signal, some electric models - including the Cadillac Lyriq, Chevrolet Blazer, Honda Prologue, and Rivian R1S - effectively halted transmissions from their connected subsystems. Conversely, several other tested vehicles actively redirected their outbound telemetry traffic to available Wi-Fi connections, granting researchers unprecedented visibility into data flows that previously remained obscured during standard road testing.

Companion Apps, OEM Responses, and Industry Accountability

The privacy exposure did not stop at the vehicle dashboard; the researchers also evaluated 30 distinct connected car companion apps designed for smartphones. Testing revealed that utilizing these companion applications frequently exposed users to more than 20 newly activated advertising, tracking, and analytics companies, with major global manufacturers General Motors, Toyota, and Nissan emerging as the worst offenders in this digital category. In response to these alarming findings, the study authors formally reached out to 17 major automakers - noting that Fisker had already filed for bankruptcy and gone under - and ultimately received substantive replies from 14 companies.

The official corporate responses offered little comfort to privacy advocates. Every single responding OEM asserted that their data-sharing arrangements with third-party partners were strictly governed by legal contracts explicitly prohibiting the secondary use of Personally Identifiable Information (PII) outside the restrictive scopes of their existing privacy agreements - the exact corporate privacy policies that initially horrified the Mozilla Foundation in 2023. Additionally, several automakers attempted to deflect corporate accountability by shifting blame onto the embedded third-party internet browsers operating natively within their modern infotainment dashboards.

Sponsored / Google AdSense SlotResponsive Leaderboard 728x90 / 970x250 (article-mid-story)
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via Ars Technica
Verified Dispatch
Related Tickers:#CYBERSECURITY#CONSUMER REPORTS#TESLA#GENERAL MOTORS#DATA PRIVACY#TECH

Share this story

Send to colleagues, X/Twitter and social networks

More Coverage in Tech

View Topic Desk →
Anthropic Targets Eye-Popping $2 Trillion Valuation in IPO Filing While Warning of Catastrophic AI Risks and Massive Losses
Tech
Tech•7h ago

Anthropic Targets Eye-Popping $2 Trillion Valuation in IPO Filing While Warning of Catastrophic AI Risks and Massive Losses

As artificial intelligence pioneer Anthropic prepares for a blockbuster public debut in November targeting an unprecedented $2 trillion valuation, its newly unveiled IPO prospectus details soaring revenues alongside mounting losses, heavy infrastructure spending, and alarming internal warnings regarding existential AI risks. The comprehensive financial disclosure reveals a complex corporate strategy designed to secure executive control while confronting the profound safety challenges of advanced frontier models.

N
Nexvoro Tech Wire
7 min read