For years, the debate over connected-car privacy has mostly been fought on paper. Someone reads an automaker’s privacy policy, finds the clause that says data “may be shared with third parties,” and everyone shrugs, because that sentence appears in every privacy policy ever written. A team at Northeastern University tried something more useful. They put actual cars on an actual network and watched where the packets went.
The resulting paper, Automatic Transmission, is credited to Nicole Zagson, Sarah Elizabeth Gillespie, Jason Veara, Devin Patel, David Choffnes, Alan Mislove, Aanjhan Ranganathan, Piotr Sapiezynski, and Christo Wilson, and appears in the proceedings of the 2026 ACM Internet Measurement Conference, held October 12–16 in Karlsruhe, Germany. The headline number is blunt: 19 of the 21 vehicles tested contacted at least one third party over Wi-Fi, including known advertising and tracking domains. northeasternnortheastern
How you eavesdrop on a car
The testing happened at Consumer Reports’ track in Connecticut, which supplied the cars. The vehicles were model years 2022 through 2025, a mix of mass-market and luxury, and many were EVs so the team wouldn’t be running combustion engines inside an enclosed space. consumerreports
The setup came in three parts. Wi-Fi traffic was captured while the cars sat still, while they were driven at moderate speeds, and during bursts of hard acceleration, hard braking, and swerving meant to mimic reckless driving. Cars were also parked in a Faraday tent that blocks cellular signals, isolating their Wi-Fi traffic. Then testers logged into the companion apps and ran every function, including locating the car, checking service history, and opening the trunk where possible. consumerreports
Related Articles
- Portland’s $207K Takeover Grant: Federal Cash, Tight Clock, Forfeiture Risk
- A Sheriff’s Helicopter on Another Call Spotted a Truck Under a Scottsdale Lake. Its Owner Went Missing in 2015.
The Faraday tent is the clever part. A modern car has two ways to reach the internet. One is the telematics control unit, a cellular modem buried behind the dash that handles crash notification, remote start, and over-the-air updates. The other is the infotainment head unit, which will happily use your home Wi-Fi or your phone’s hotspot. Cut off the cellular link and you can see whether the car simply pushes the same traffic through the Wi-Fi it can still reach. It also explains the main caveat. The researchers watched the Wi-Fi channel, so anything that only rides the car’s built-in cellular modem stays out of view. Treat these counts as a floor, not a ceiling.
The scoreboard
The researchers classified each destination as first party (the automaker), integrated third party (navigation, music, cloud hosting), or advertising, tracking, and analytics. The data published alongside the study is revealing. The Tesla Model 3 contacted 34 advertising, tracking, and analytics domains and the Cybertruck 23. They were followed by the Cadillac Lyriq at 10, the Lucid Air at 9, the Chevrolet Blazer at 7, and the Honda Prologue at 5. The Mercedes-Benz EQS and Buick Envista each registered zero such domains. consumerreports
Look at the middle of that list and you’ll see a pattern. The Lyriq, the Blazer, and the Prologue all ride GM’s EV architecture, with the Honda built by GM, and they share a Google-based infotainment stack. These cars aren’t fitted with ad tech by accident. Their dashboards are essentially tablets running a big platform’s operating system, carrying that platform’s usual telemetry habits. The study’s partners describe the dual role directly: many of these companies supply software like Android Automotive while also running the ad auction platforms marketers use to target customers. consumerreports
The Tesla numbers will raise eyebrows, though they come with a nuance. A domain count measures how many different places a car talks to, not how much personal data it sends to each one. A car that loads a web browser and a dozen streaming apps will hit many domains without necessarily leaking your name. That’s why the second half of the study matters more.
The app is the real leak
The car is only half the system. The companion app on your phone, the one the dealer insisted you download before handing over the key card, turned out to be the bigger problem. 28 of 30 apps sent data to at least one outside advertising or analytics company, and seven sent at least one piece of personally identifiable information, meaning the owner’s name, the VIN, or the car’s precise location. consumerreports
The specific offenders: four GM apps (myCadillac, myChevrolet, myBuick, and myGMC), along with HondaLink, MyNissan, and the Lincoln app, were found sharing VINs paired with either email addresses or location data. consumerreports
That pairing is the key point. A VIN on its own is a 17-character string anyone can read through your windshield. Combined with an email address, it becomes a join key. With that one link, an ad platform can connect “owner of a 2024 Lyriq, garaged at this address” to the purchase history, browsing profile, and inferred income already attached to that email. The VIN also decodes into trim, options, and build plant, which is about as clear a household-wealth signal as a marketer can get. The researchers called this their most serious finding: with those two identifiers, a major ad or tech company can link the owner to commercially available consumer profiles sold by data brokers. consumerreports
There’s a nice irony in the results. The Buick Envista was one of the two cleanest cars on the network, but myBuick was one of the apps pairing VINs with other identifiers. Owners of the “quiet” car still get tracked, just through their phones instead.
The researchers’ summary of the whole system is the line automakers should remember: “large gap between what vehicle manufacturers publicly disclosed and how the connected vehicle ecosystem actually shares data over the Internet”. northeastern
What the automakers said
Automakers contacted about the results gave fairly consistent answers. Several said some links inside their apps open outside webpages, where third parties can place pixels and cookies that may collect customer data. The researchers noted this happened without warning or the driver’s knowledge. Others pointed to contracts. GM, Honda, Nissan, and Stellantis said some data recipients were barred from independently using or selling what they received. consumerreportsconsumerreports
Honda’s response did the most to undercut that argument. After seeing the findings, Honda told its analytics vendor, Amplitude, to delete all the location data it had received, and stopped sending it. To Honda’s credit, it acted. But the episode shows a contractual restriction doesn’t stop the data from leaving in the first place. Someone has to notice first. consumerreports
The “you opted in” defense has the same problem. Saying no can make the car worse, or not work at all. Tesla owners who decline its data-sharing agreement are told: “This may result in your vehicle suffering from reduced functionality, serious damage, or inoperability.” As one co-author, Gillespie, put it: “It does not appear that a customer can buy a new car that does not track you.” consumerreportsconsumerreports
Why insurers, regulators, and lawyers care
We already know where driving data can end up. In January, the Federal Trade Commission finalized an order against GM and OnStar settling allegations that they collected, used, and sold precise geolocation and driving behavior data from millions of vehicles without proper notice or consent. The order bans GM from disclosing that data to consumer reporting agencies for five years and, for its 20-year term, requires an opt-out for geolocation and driver behavior collection, with limited exceptions. Consumer reporting agencies matter here because they’re where insurers buy risk scores. Texas went further: in August 2024 its attorney general sued GM and OnStar, alleging the companies illegally collected driving data from more than 1.8 million Texas drivers and sold it to data brokers without consent. ftccaptaincompliance
The Northeastern study isn’t about insurance scoring, and the researchers didn’t show any of this traffic reaching an insurer. What it does show is that the plumbing is everywhere. The GM case involved one company’s program and a clear sale. This study maps many quieter pipes, run by ad-tech firms whose business is resolving identities. Those are separate legal questions, and the FTC order covers only GM. Each other automaker is governed by its own privacy policy and a patchwork of state laws.
What owners and buyers can actually do
First, treat the companion app like any other ad-supported app. Check its permissions on your phone, deny “always” location access unless you need remote features, and don’t tap links inside the app that open web pages. That last route is how the automakers themselves said pixels and cookies get in.
Second, don’t assume a car with fewer infotainment features is automatically private. The cleanest cars on the Wi-Fi test still had apps that leaked identifiers.
Related Articles
- Watch: Allegedly Stolen Mercedes Flies Into an Ashtonfield Front Yard, Then a 14-Year-Old Gets Bail Days After NSW Extended Its Youth Bail Law
- Volkswagen Cut a Shift on the Line That Builds Its Best-Selling U.S. Model. Puebla’s Strike Deadline Is Friday.
Third, think hard before cutting the cellular modem. Pulling the telematics fuse or unplugging the antenna is a popular forum fix. It can also disable automatic crash notification, remote unlock, over-the-air updates (including recall fixes delivered that way), and on some EVs, charger routing. You’d be trading a privacy problem for a safety and maintenance one.
Fourth, when selling or trading in, factory-reset the head unit and remove the VIN from your app account. Otherwise the VIN-to-email link outlives your ownership.
Fifth, if your premiums jump for no clear reason, ask your insurer what data it used, and request your file from the consumer reporting agencies that sell driving-behavior scores. Federal credit-reporting law gives you the right to see it.
Automakers love calling their cars “smartphones on wheels.” The researchers took that literally, and it held up: the dashboard behaves like a phone, and phones get tracked.

