
The Netherlands’ intelligence service has warned that connected cars can expose sensitive information to state actors.
The alert is largely based on university research from last month, which revealed extensive contact with third-party services and personal data sharing by car companion apps.
The General Intelligence and Security Service (AIVD) issued its warning primarily addressing government officials, business leaders, and others whose work involves confidential information. Modern vehicles collect data about occupants, their surroundings, and the vehicles themselves, creating information sources that foreign intelligence services could seek to access.
The agency says state actors may obtain vehicle data by requesting it from companies or hacking the systems that hold it. Potential recipients extend beyond manufacturers to dealerships, leasing companies, app developers, component suppliers, and cloud providers.
The AIVD identifies microphones, cameras, infotainment systems, GPS tracking, and telematics modules as potential sources of exposure. It warns that remotely activated microphones or cameras could enable eavesdropping or recording, while navigation records and location services can reveal sensitive travel patterns.
Car apps expand tracking exposure
Northeastern University researchers working with Consumer Reports examined 21 US-market vehicles across 19 brands and 30 companion mobile apps between October 2024 and August 2025.
Researchers captured vehicle Wi-Fi traffic during stationary and driving tests, used a vehicle-sized Faraday tent to block cellular connections in selected experiments, and decrypted companion-app traffic using instrumented iPhones.
They found that 19 of the 21 vehicles contacted at least one third party over Wi-Fi. Destinations included advertising, tracking, and analytics services, although the encrypted vehicle traffic generally prevented researchers from inspecting the transmitted contents.
Seven apps transmitted vehicle identification numbers (VINs), precise location, email addresses, or phone numbers to companies associated with advertising, tracking, or analytics.
Those apps were myCadillac, myChevrolet, myBuick, myGMC, HondaLink, Lincoln, and MyNISSAN. The four General Motors apps transmitted VINs to multiple companies, including Google, Meta, Microsoft, Adobe, and Acxiom.

northeastern.edu
Unlike resettable advertising identifiers, VINs are permanent vehicle identifiers. Combining them with personal information can help companies connect vehicle ownership with activity across websites and apps, the researchers warn.
For most vehicles studied, including the companion app at least doubled the number of advertising, tracking, and analytics companies contacted. Cadillac’s app added 26 companies beyond those observed in the vehicle’s own traffic.
Limited choices for owners
The researchers contacted 17 manufacturers and received 14 responses. All responding manufacturers cited service-provider contracts governing data use; some attributed tracking to embedded webpages or said consumers were responsible for reviewing third-party agreements.
Honda said it asked analytics provider Amplitude to delete location data received through HondaLink and updated the app to stop sending geolocation to that provider.
The study documents commercial data flows rather than state-sponsored espionage, and its findings represent a snapshot of the tested vehicles and apps.
For people handling sensitive information, the AIVD advises avoiding confidential conversations in or around vehicles, limiting automatic phone connections, using USB data blockers, and avoiding sensitive addresses in built-in navigation.







Leave a Reply