Every Car Tested Shared Data With Outsiders, Researchers Found

All 21 late-model vehicles tested by Northeastern University researchers sent data to at least one outside company over Wi-Fi. The work was done with Consumer Reports and reported on Sept. 29, 2026. It covered 21 vehicles from 19 brands sold in the United States, plus 30 companion phone apps linked to active vehicles. The Verge
To watch the traffic, researchers placed a small Raspberry Pi computer inside each car, joined it to the car's Wi-Fi and sent the traffic out through a mobile hotspot for recording. Each car was parked inside a car-sized Faraday tent, an enclosure that blocks cellular signals, to force data onto that monitored Wi-Fi path. The project was led by David Choffnes, former director of Northeastern's Cybersecurity and Privacy Institute.
More than half of the vehicles contacted servers that specialize in advertising, tracking or analytics. A third-party domain, in this context, is a server run by a company other than the automaker. The study named Adobe, LexisNexis and Amplitude as firms collecting vehicle or driving details for sale to insurance companies or for ad targeting. Cars running Google's Android Automotive OS with Google Automotive Services, Google's built-in car software and apps package, contacted the highest number of third-party domains.
Regulators have already acted on related practices. The Federal Trade Commission penalized General Motors for collecting and selling precise location and driving behavior data without informed consent. Ford and Honda faced fines for making it overly difficult for customers to opt out of data collection.
Honda, Toyota, Volkswagen and General Motors were among the automakers named in a vehicle-data privacy lawsuit covered in November 2023, with Ford also subject to a vehicle-data privacy case. Northeastern News Mozilla's 'Privacy Nightmare on Wheels' review found that every car brand it reviewed failed its privacy test, including Ford, Volkswagen and Toyota, and that BMW, Ford, Toyota, Tesla, Kia and Subaru can collect deeply personal data. Mozilla A California state agency said in July 2023 it was reviewing the privacy practices of automakers and vehicle technology companies. Reuters The FTC has stated that data collected from cars could be sensitive, such as biometric information or location, and its collection, use and disclosure can threaten consumers' privacy. FTC
The broader context here is worth keeping in mind when reading the results. A Wi-Fi-only test sees only part of the picture. Cars also send data over cellular networks, and a destination address alone does not show how sensitive the contents were. Still, destination records are a practical check. They can reveal extra software kits and analytics calls, background connections that were not clearly disclosed, and permission settings that do not carry over to background services.
In my view, the fix is less about removing connectivity than about tightening defaults. That would mean collecting less data at the car's main computer, allowing only approved outside connections, building clear yes-or-no permission switches into the car software and company servers, and checking third-party traffic on a regular basis. I have watched my own children accept every in-car and in-app prompt without reading, then later ask why an insurance quote knew how they drive. That gap between the permission screen and the actual network behavior is where trust is lost.
Looking at what this enables, steady testing gives automakers, regulators and independent researchers a shared set of facts. If checking data traffic becomes routine, in the same way crash testing did, buyers and fleet operators can compare privacy behavior directly and suppliers can compete on cleaner network designs.


