Automatic Transmission – A Data-privacy Study Of Connected Vehicles
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get garage and car supplies delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Researchers at Northeastern University, working with Consumer Reports, tested 21 late-model vehicles and 30 companion apps in a controlled U.S. setting. They found that 19 vehicles contacted at least one third party over Wi-Fi, while seven apps sent sensitive identifiers to third-party companies; the study says encrypted vehicle traffic limited what researchers could inspect.

A Northeastern University-led study of 21 late-model vehicles and 30 companion apps found that 19 vehicles contacted at least one third-party domain over Wi-Fi, while seven apps sent sensitive identifiers to third-party companies. The research, conducted with Consumer Reports, offers a measured look at data flows in connected cars, though it does not establish what recipients did with the information.

The research team tested vehicles from 19 brands and paired them with manufacturer companion apps at a Consumer Reports testing facility. Experiments ran between October 2024 and August 2025. Researchers examined network destinations contacted by vehicles and analyzed app traffic while manually using available features.

According to the report, 19 of 21 vehicles sent traffic to at least one third party over Wi-Fi. The team also found that seven of 30 apps transmitted personal information or sensitive identifiers to third-party companies. Five apps sent a vehicle identification number, or VIN, along with other personal information to trackers, the report says.

For vehicle testing, researchers routed Wi-Fi traffic through a custom access point and recorded network packets. They could identify destinations, but said the contents of vehicle packets were encrypted and not visible through that method. App testing used instrumented iPhones and a traffic-interception setup. Researchers accepted permissions requested during installation and login, then exercised app functions such as locating the vehicle and searching for charging stations.

At a glance
reportWhen: Testing conducted October 2024 to Augus…
The developmentA Northeastern University-led study reports that many tested connected vehicles and some companion apps communicated with third-party domains, including trackers and advertisers.

What the Data Flows Reveal

The findings matter because connected vehicles and their apps can handle information that may identify a driver, a vehicle or patterns of use. Network contact with a third-party domain does not, by itself, show that a company sold data, used it for advertising or linked it to a named person. But the study documents that data can move beyond the automaker’s own systems, making the identity and practices of recipients relevant to consumers.

The report says consumers have limited control over information after it reaches outside servers, and argues that more visibility is needed. Its measurements provide evidence about where some traffic was sent, while leaving open what happened after receipt. That distinction is important for interpreting the results: the research maps observed communications, not every downstream use of data.

For drivers, the work raises practical questions about app permissions, vehicle connectivity and privacy disclosures. It also gives regulators and researchers a reproducible area for further scrutiny. The figures describe a specific sample of 21 vehicles and 30 apps, not every connected vehicle or manufacturer on the market.

Amazon

vehicle Wi-Fi privacy protection device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Researchers Tested Cars

A connected vehicle can use cellular service, Wi-Fi and GPS to communicate with its manufacturer and outside services. The study examined two points in that ecosystem: the vehicle’s network traffic and the manufacturer-provided mobile apps paired with it. The report describes the work as an early large-scale measurement of connected-vehicle privacy practices.

Researchers ran idle, active and driving tests, and tested 11 electric vehicles inside a Faraday tent designed to block cellular signals. This let them examine whether traffic shifted to Wi-Fi when cellular communication was unavailable. For app tests, the team used three iPhone models and tested apps individually to reduce unrelated background traffic. Consumer Reports supplied its purchased test fleet, which the researchers said would have cost more than $1.2 million to assemble independently.

The team says the study went through a lengthy disclosure process with manufacturers and provides insight into how manufacturers view data sharing. The report identifies the work as peer reviewed and says it is scheduled for publication at IMC ’26.

What the Measurements Cannot Show

The study’s vehicle method identified network destinations but could not read encrypted packet contents. The results therefore do not establish precisely what data each vehicle transmitted in those encrypted connections. App testing provided a different view, but the report’s summary figures alone do not identify every company, identifier, or circumstance involved in each finding.

It is also unclear from the supplied report summary what third parties did with received information, whether they retained or shared it, or whether any data was tied to an identifiable driver. Contact with an advertising or tracking domain is not proof of a sale or a particular use. The tests covered a limited group of vehicles and apps under controlled conditions, so the findings should not be treated as a market-wide rate.

The report does not provide a full account in the supplied material of manufacturer responses, the specific disclosures made during the research process, or the outcome of those exchanges. Those details, along with the complete paper’s methods and results, would help readers evaluate the findings more fully.

Publication and Further Scrutiny

The researchers say the paper is scheduled for publication at IMC ’26. The full paper and any accompanying manufacturer responses may provide more detail on the observed destinations, app transmissions, testing limits and disclosure process. The report calls for continued measurement and scrutiny of connected-vehicle data practices.

Until those details are available, the study’s confirmed contribution is a set of measurements from a defined sample, rather than a complete account of how the industry handles driver data. Follow-up research could test more models and software versions, examine traffic over cellular connections, and clarify what receiving companies do with data after collection.

Key Questions

What did the connected-car study find?

The researchers report that 19 of 21 tested vehicles contacted at least one third party over Wi-Fi. They also found that seven of 30 companion apps sent sensitive identifiers to third-party companies.

Does the study prove automakers sold driver data?

No. The study reports network traffic to third-party domains and some app transmissions of personal information. The supplied findings do not establish that recipients sold the data or how they used it after receiving it.

Could researchers read what the vehicles sent?

Not through the vehicle Wi-Fi packet-capture method described in the report. Researchers could identify destinations, but said the packet contents were encrypted. The app tests used a separate traffic-interception method.

How broad was the testing?

The team tested 21 vehicles from 19 brands and 30 companion apps in a controlled U.S. setting from October 2024 to August 2025. That is a defined research sample, not every model or connected-car service.

When will the full study be published?

The research team says the peer-reviewed paper is scheduled for publication at IMC ’26. The supplied report does not provide a specific publication date.

Source: hn

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

The Iconic 911 Slantnose Returns As The Insane Porsche Flachbau RS

Porsche officially unveils the 911 Slantnose RS, a modern interpretation of the classic Flachbau, combining iconic design with high-performance engineering.

Unpacking Ford’s Spat With The Trump Administration Over China

Analysis of Ford’s recent conflict with the Trump administration over China policies, highlighting confirmed facts, implications, and ongoing uncertainties.

New Nissan Z T-Top Revealed! And It Sure Looks Like More Than A Concept

Nissan has unveiled a T-Top version of the Z sports car, sparking speculation it may move beyond a concept to production. Details are still emerging.

New Diesel Engine Oil Blends Are Designed To Keep DPFs From Clogging So Darn Much

Search and coverage interest in low-SAPS diesel oils designed to protect DPFs is rising. What is confirmed, what is claimed, and what remains unclear.