**H1** Worried about your car being hacked? You should be – no matter where it was made

**Introduction**

A recent demonstration by a cybersecurity expert has highlighted a growing concern in the automotive industry: the vulnerability of modern cars to hacking. The expert was able to gain control of a Chinese-made vehicle's locks, headlights, and audio and video systems with ease, raising concerns that cars made by Chinese companies may share data with the Chinese government. But the issue goes beyond foreign-made vehicles – most modern cars, regardless of their country of origin, collect a vast amount of personal information and transmit it to offshore servers, making them vulnerable to hackers.

**The Car as a Distributed Network of Computers**

Modern cars have evolved from simple machines to complex networks of computers on wheels. With dozens of computers managing different functions, including entertainment, communications, braking, steering, and engine performance, they are no different from other computer systems. These systems communicate with one another, and with the outside world, through various connections, including Bluetooth, WiFi, and built-in SIMs or eSIMs. This interconnectedness creates a vulnerability to hacking and malware, which can compromise not only the vehicle's safety but also the safety of its occupants.

**The Risk of Data Breach**

Many modern cars collect a vast amount of personal information, including audio, video, and location data. This information is transmitted to offshore servers for storage and processing, where it may be accessible to foreign governments, including China. But it's not just foreign governments that have access to this data – hackers may also be able to access it, posing a significant risk to car owners. A network of computers, on wheels or in the cloud, is only as secure as its weakest link.

**The SIM and Cellular Connection**

Similar technology to SIM cards and eSIMs, which connect our phones to mobile networks, is built into many modern vehicles. This allows them to communicate with manufacturers, receive software updates, and transmit vehicle data, known as telematics. While the SIM itself is not usually the vulnerability, it provides a pathway into a much larger communications system that includes the vehicle's cellular modem, telematics systems, and mobile network, as well as the manufacturer's online infrastructure. Researchers have found weaknesses in this communications chain, including in Tesla Model 3s and Cybertrucks.

**The Growing Threat of Car Hacking**

Hackers are paying more attention to cars, and the consequences can be severe. In August, cybersecurity company Kaspersky documented a malware campaign targeting "head units" (which handle multimedia and sometimes car control functions) running on the Android operating system. The malware worked via an automatic firmware-update service. Security researchers have also demonstrated several ways to attack vehicles that use the common QNX operating system. The risk of car hacking is no longer limited to high-end vehicles or those with advanced features – all connected vehicles are at risk.

**The Risks to Car Owners**

Gaining access to a vehicle could present direct physical safety risks if hackers compromise things such as steering or lights. It could also be used for identity theft or to steal the vehicle itself. Australia's eSafety Commissioner has also identified connected vehicles as technologies that can facilitate coercive control. Trip histories, geolocation data, and vehicle apps can be used to monitor a person's movements. Remote functions can operate doors, climate controls, horns, headlights, and other vehicle systems.

**The Need for Cybersecurity Standards**

Australia currently has no mandatory minimum cybersecurity standard specifically for vehicles. Implementation of new rules is likely years away at best. Other markets, including China and the European Union, already require manufacturers to demonstrate how they manage cybersecurity risks and protect software updates throughout a vehicle's life. The more connected our cars become, the more important it is to ask not only what data leaves them, but what can get back in.

**What to Know if You're Buying a Car**

If you're thinking about buying a new, connected vehicle, there are steps you can take to reduce the risks. The Australian Cyber Security Centre offers a detailed guide on what issues to keep in mind when purchasing and using a connected vehicle. Most of the advice comes down to four tips: keep the vehicle and any related apps up to date, research the maker's approach to cybersecurity, consider the risks of using connected services, and restore it to factory settings if you're buying or selling a used vehicle.

**Conclusion**

The risk of car hacking is real, and it's not just a concern for foreign-made vehicles. Most modern cars, regardless of their country of origin, are vulnerable to hacking and malware. As we become increasingly reliant on connected vehicles, it's essential to take steps to protect ourselves and our vehicles. By understanding the risks and taking the necessary precautions, we can reduce the likelihood of a data breach or a physical safety risk.