German teen claims he found a way to hack over 25 Tesla cars in 13 countries

By Alma Fabiani

Published Jan 15, 2022 at 08:57 AM

Reading time: 2 minutes

On Tuesday 11 January, 19-year-old David Colombo, a self-described “information technology security specialist and hacker,” wrote on Twitter that he had found flaws in a piece of third-party software used by a relatively small number of owners of Tesla cars, meaning that hackers could remotely control some of the vehicles’ functions.

According to Colombo, the flaws gave him the ability to unlock doors and windows, start the cars without keys and even disable their security systems. He also claimed that he could see if a driver is present in the car, turn on the vehicles’ stereo sound systems and flash their headlights.

In other words, hacking into the third-party software in question offered him the chance to control pretty much what he wants in most Tesla cars. Considering the fact that a Massachusetts Institute of Technology (MIT) study confirmed that Tesla’s autopilot is unsafe back in September 2021, this potential addition to the infamous cars’ list of dangers came as yet another blow to Elon Musk’s company.

In an interview with Bloomberg, Colombo provided screenshots and other documentation of his research that identified the maker of the software and gave more details on the vulnerabilities it presents. He asked that the publication not publish specifics however, because the affected company had not published a fix at the time of writing. On Twitter, Colombo added that he could access more than 25 Teslas in at least 13 countries, which is why he decided to share this information on the social media platform when he wasn’t able to contact most of the owners directly.

‘So what’s wrong exactly?’ some of you might be wondering. According to what Colombo told Bloomberg, “the problem involves an insecure way the software stores sensitive information that’s needed to link the cars to the program.” While it truly depends on who can access such information, in the wrong hands, it could be stolen and repurposed by hackers to send malicious commands to the cars, he continued to explain. He even showed Bloomberg screenshots of a private conversation he had on Twitter with one of the affected owners, who allowed him to remotely honk his car’s horn.

Since then, Colombo has been in touch with members of Tesla’s security team as well as with the maker of the third-party software. Tesla has a “bug bounty” programme where cybersecurity researchers can report vulnerabilities in the company’s products and, if validated, receive payment.

This latest discovery goes to show some of the remaining risks of moving to the so-called ‘Internet of Things’, where everything is connected online—thus becoming potentially vulnerable to hacking threats. “Just don’t connect critical stuff to the internet,” Colombo advised. “It’s very simple. And if you have to, then make sure it is set up securely.”

Keep On Reading

By Fatou Ferraro Mboup

UK medics told not to report illegal abortions to police due to women being wrongly prosecuted

By Abby Amoakuh

Shoplifting addiction is at an all-time high. And white middle-class women are to blame

By Abby Amoakuh

Men are warming up to lip fillers and finding more than just one use for the injections

By Fatou Ferraro Mboup

Florence Pugh reveals her mum got high with Snoop Dogg at the Oscars

By Fatou Ferraro Mboup

From Love & Hip Hop to the latest Offset drama, let’s unpack the queen that is Cardi B

By Abby Amoakuh

Far-right influencers try to bail out Elon Musk as Disney and Apple leave X due to antisemitism claims

By Charlie Sawyer

Dwayne Johnson revokes Joe Biden endorsement. Wait, is The Rock running for president?

By Jack Ramage

The age of loud quitting and why everyone’s filming themselves getting fired or resigning on TikTok

By Charlie Sawyer

Conspiracy theorists fear for King Charles’ safety after white bloody horse spotted in central London

By Alma Fabiani

What is a nepo baby, and why do they make everyone so mad?

By Malavika Pradeep

What is vaporwave? Here’s everything you need to know about the viral music genre

By Fatou Ferraro Mboup

Problematic P Diddy Nickelodeon cameo surfaces following house raids and Quiet On Set documentary

By Abby Amoakuh

Alabama Barker denies claims she has had a lot of plastic surgery in major clapback

By Charlie Sawyer

What’s in the 2024 Oscars gift bag that’s worth more than most people’s annual salary?

By Fatou Ferraro Mboup

Grindr sued for allegedly sharing UK users’ HIV status with ad firms

By Charlie Sawyer

Real Legion from viral Who TF Did I Marry TikTok drama comes out with new response

By Charlie Sawyer

Poison seller who promoted death kits on suicide forums tracked down by BBC

By Charlie Sawyer

Meta faces backlash from Instagram users over new political content limitation feature

By Charlie Sawyer

Man partied for four days unaware he had been shot in the head

By Fatou Ferraro Mboup

Move aside Tube Girl, Mumbai’s Train Girl Seema Kanojiya is here to slay