Particle.news

Study Finds Connected Cars and Apps Routinely Share Drivers' Data

Researchers say VINs, contact details and precise locations reached advertising, tracking and major tech firms, raising new grounds for regulatory scrutiny.

Overview

  • The peer‑reviewed paper, published Sept. 29–30, 2026, tested 21 late‑model vehicles and 30 companion mobile apps to measure what the cars and apps transmit.
  • Nineteen of the 21 vehicles contacted at least one third‑party domain and more than half reached advertising, tracking or analytics (ATA) firms, with cars running Android Automotive and Google services contacting many more outside domains.
  • Seven companion apps—including GM’s myCadillac/myChevrolet/myBuick/myGMC, HondaLink, Lincoln and MyNissan—sent personally identifiable information such as VINs, emails, phone numbers or precise location to third‑party trackers.
  • Researchers used Wi‑Fi captures with a Raspberry Pi and a car‑sized Faraday tent to force traffic over controlled links and relied on DNS, SNI, timing and volume to identify recipient domains but could not decrypt encrypted payloads.
  • Automakers mostly defended the flows as driven by vendor contracts or embedded components and made few fixes; Honda ordered deletion of some location data, and regulators and consumer advocates are positioned to press for oversight because a VIN paired with other identifiers creates a durable, linkable dossier that can harm privacy and safety.