Modern connected vehicles are transmitting driver data directly to third party advertising and analytics firms. A study from Northeastern University revealed that every single tested vehicle communicated with external tracking domains. As reported by The Verge, companion mobile apps routinely broadcast vehicle identification numbers and live GPS coordinates to commercial data brokers.
Researchers examined 21 vehicles representing 19 automotive brands alongside 30 companion mobile applications. All 21 cars sent telemetry to at least 1 external third party domain. More than 50% of the vehicles connected to platforms dedicated to advertising, consumer tracking, and risk analytics, including Adobe, LexisNexis, and Amplitude. Cars equipped with modern operating software, particularly those running Android Automotive with Google services, transmitted data at the highest frequencies.
Mobile companion software exhibited even greater privacy vulnerabilities. Apps including HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC sent vehicle identification numbers, owner phone numbers, and precise geographic coordinates directly to advertising networks. Over 70% of the analyzed apps contacted 5 or more distinct analytics domains. Researchers pointed out that linking a vehicle identification number with personal identifiers allows data brokers to assemble detailed behavioral profiles of individual drivers.
To measure wireless traffic, the research team captured Wi Fi transmissions using a Raspberry Pi paired with a mobile hotspot. For cellular data, engineers built a specialized radio frequency shielded enclosure to block outside network interference and isolate outbound signals. While encryption prevented researchers from inspecting the raw payload contents, tracking domain destinations confirmed the flow of user telemetry. Following the publication of the study, Honda instructed Amplitude to delete all collected location data and released a software update for its HondaLink application.
