Truemag

  • Newsletters
  • Thought Leadership
  • Mobility
  • Safety
  • Work Trucks
  • Videos
  • Home
  • Subscribe
  • Contact Us
  • Media Kit
  • Who We Are

Tesla-Stealing Hack is about Much More than Tesla

Fortune

Hackers can steal your car—and a lot more—through your phone.

An often-asserted downside of internet-connected vehicles is that they’re subject to various forms of hacking, including theft.

On Wednesday, a Norwegian security company called Promon claimed to have found something like the Holy Grail of vehicle hacking—by compromising a Tesla owner’s Android phone, they could take control of Tesla’s mobile app and steal the car.

The hack relies on tricking a Tesla owner into downloading a malicious app, for instance through a spoofed public Wi-Fi hotspot that would direct them to a deceptive Google Play download.

That app could then escalate permissions on the owner’s phone and corrupt the Tesla app. Attackers could then, according to Promon, communicate with the Tesla server to issue remote commands including locating the victim’s car, opening its doors, and enabling keyless driving.

There are a few caveats. The specific exploit used by Promon only works on Android versions 5.1 or older—that is, phones that haven’t been updated in nearly two years. More to the point, Promon acknowledged in a followup note that “this attack is not Tesla specific, and in generalized form can be used against any app”.

Promon does point out that an authorization token used by the Tesla app was unencrypted, making the hack easier, and that a few extra measures could have protected the app even after the phone was compromised. But at bottom, the flaw highlighted by Promon was in an outdated version of Android, not in the Tesla app itself. Choosing Tesla as a target was just savvy marketing by a company selling app security tools.

What’s not clear is whether that should make anyone feel better. Moralizing experts can scold users to keep their OS updated and not click on bad links. But in the real world, around 20% of Android devices still run 2012’s Jelly Bean, largely because hardware manufacturers don’t maintain device support. And hacking through deception (“social engineering”) will probably never die—by definition, half of all people are below average at spotting scams.

The consequences of phone hacking will get more severe as remote-control apps become more common in the Internet of Things, making it possible for both owners and hackers to control everything from cars to home locks to desktop computers. Tesla itself, alongside its recent introduction of autonomy features, has said owners will someday be able to summon their cars from across the country using their phones. Some of those phones will, simply according to the law of averages, be compromised.

Of course, connection has its benefits, too. Tesla vehicles send real-time location data to owners’ apps, which last year helped a Vancouver couple relocate their stolen S 85D. Promon’s app hack doesn’t involve shutting down the car’s GPS feed, so even if a thief were to pull it off, they might not keep their prize for long.

 

Nov 27, 2016connieshedron
NAFA Announces Holman Parts Distribution Fleet As Newest Sustainability-Accredited FleetDriverless Vehicle Makers Push Back on Data Sharing, Fleet Size
Recent Posts
  • IMPROVLearning: How Comedy, Behavioral Science and AI Improve Fleet Safety
  • Improving Productivity with AI: Turning Fleet Data into Faster Decisions
  • National Safety Council Projects Increased Traffic Crash Risk during Fourth of July Weekend
  • Keep Every Heavy-Duty Maintenance Inspection on Track — Free Fullbay Checklist
  • Gain Data-Driven Insights into Commercial Vehicle Market Trends at Executive Leadership Summit
  • Last Chance to Save: Register for NAFA’s Maintenance Workshop
  • License Plate Cameras Are About to Start Tracking a Lot More Than Just Your Car
  • America’s Heavy EV Problem May End with Drivers Paying More
  • Trends in U.S. Drivers’ Perceptions and Attitudes Toward Vehicle Automation, 2019–2025
  • 2026 NETS Strength IN Numbers Conference: Early Bird Rates!
ASSOCIATION NEWS
Last Chance to Save: Register for NAFA’s Maintenance Workshop
How AFLA Is Positioning Itself for the Future of Fleet Mobility
‘Raise Your Hand and Get Involved’
NAFA Names 2026 Class of Fellows, Honoring Leaders in Fleet Management
Award Winners Honored at NAFA I&E
2026 NAFA I&E Seeks to Change Perceptions, Invigorate Fleets
NAFA Announces Lineup for Media Day at I&E 2026: Industry Leaders to Showcase the Latest Innovations
TECHNOLOGY
Improving Productivity with AI: Turning Fleet Data into Faster Decisions
Fleet Operations Are Changing – The Industry Needs to Evolve With Them
AI-Powered Vehicle Inspections Move Beyond the Checklist
Motive’s New Workforce Capabilities Aim to Improve Performance, Automate Rewards
AI + Human Insight: Why Fleet Leaders Need Both to Win in 2026
NTSB Finds Automation Overreliance Contributed to Two Fatal Ford BlueCruise Crashes
New AI Assistants Automate Fleet Data Analysis, Decision Making and More
CONFERENCES & WEBINARS
2026 NETS Strength IN Numbers Conference: Early Bird Rates!
AFLA 2026 – Keynotes Announced!
Private Fleets Flex at National Private Truck Council Conference
Free NAFA Webinar: Manage Your Fuel Cost Volatility
Registration Now Open for NETS Annual Conference
Early Bird Pricing for AFLA 2026 – Ending June 1
NAFA Online Seminar: Essentials of Fleet Management
INDUSTRY ANNOUNCEMENTS
Union Leasing Becomes Moventum Fleet Management as 70-Year Company Accelerates into Next Phase
Fleetio Wins Innovations Award at NAFA’s 2026 Institute & Expo
WIFM is heading to NAFA!
Cox Automotive Unveils Cox Fleet, Setting a New Standard for Fleet Uptime Nationwide
AFLA Canadian Fleet Professional of the Year Award: Nominations Open!
NAFA Webinar: Kickoff the 2026 100 Best Fleets Contest on December 4!
Join NAFA’s Free Fleet 101 Live Course

Fleet Management Weekly Newsletter Archive
Access to back issues of the FMW newsletter.

FMW Mobility
How mobility is rapidly changing the fleet management landscape.

Newsletter

Subscribe

FMW Fleet Videos
Video clips of industry leaders speaking on a variety of engaging hot topics in fleet.

2014-2020 © Fleet Management Weekly