TL;DR
Get bike and ride gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A Northeastern University research team, working with Consumer Reports, tested 21 late-model vehicles and 30 companion apps for data flows to outside companies. The researchers found that 19 vehicles contacted at least one third party over Wi-Fi, and seven apps transmitted sensitive identifiers to third-party companies. The study describes measured network traffic; it does not establish how recipients used the data.
A Northeastern University team working with Consumer Reports found that 19 of 21 tested vehicles contacted at least one third party over Wi-Fi, while seven of 30 companion apps sent sensitive identifiers to third-party companies. The study measures network traffic in a controlled test setting, offering a view into data flows from connected cars and their apps; it does not show how recipients ultimately used the information.
The researchers tested 21 late-model vehicles representing 19 brands and their associated mobile services, along with 30 companion apps. Experiments took place at Consumer Reports’ testing facility between October 2024 and August 2025. The team says this is the first large-scale measurement study of the connected-vehicle ecosystem. The research paper is peer reviewed and is scheduled for publication at IMC ’26, according to the project website.
For vehicle tests, researchers captured network destinations over a custom Wi-Fi access point. They examined vehicles while idle, during active use and while driving under controlled conditions. Because vehicle traffic was encrypted, this method let the team identify destinations but not read the contents of those vehicle packets. In a separate test, researchers placed 11 electric vehicles in a Faraday tent to block cellular signals and examined whether traffic shifted to Wi-Fi.
For app testing, the team used test iPhones, logged into apps with existing vehicle-linked accounts and exercised available functions. The researchers report that seven apps sent personally identifying information to trackers; in five cases, the information included a vehicle identification number alongside other personal information. These are findings about transmissions observed during the tests, not evidence that every user or every use of an app produces the same traffic.
What the Traffic Findings Mean
Connected vehicles and their apps can produce a detailed record of driving and vehicle use. When information is sent beyond the carmaker, consumers may have limited visibility into who receives it and what happens after transmission. The study’s observed connections matter because third-party recipients can include advertising and tracking services, according to the researchers.
The results do not establish that any particular recipient sold data, used it to set insurance prices or identified a specific driver. But the measurements show that data can travel through a wider ecosystem than a driver might expect. That makes disclosures, permission settings and clear limits on onward sharing important questions for vehicle owners, regulators and manufacturers.
As an affiliate, we earn on qualifying purchases.
How Researchers Traced Car Data
The researchers frame the connected-car system as two linked sources of data: the vehicle itself and the manufacturer’s mobile app. Cars can use cellular service, Wi-Fi and GPS to communicate with manufacturers and other services. The project examined both sides because a vehicle’s network traffic and an app’s traffic can go to different servers.
Consumer Reports supplied access to its purchased fleet, which the study says would have cost more than $1.2 million to assemble independently. The team used packet logging for vehicle Wi-Fi traffic and traffic interception tools for apps. App testing accepted permissions requested during setup, including location and tracking permissions, and manually exercised app features. The researchers say their work addresses limited visibility into what connected vehicles share and who receives it.
“19/21 vehicles tested send traffic to at least one third party.”
— Northeastern University research team, in the study project summary
As an affiliate, we earn on qualifying purchases.
Limits of the Observed Data
The findings reflect 21 vehicles and 30 apps tested in a particular facility and time period; they do not establish how all makes, models, software versions or drivers behave. The project summary does not name the companies associated with each observed transmission or specify the full set of data fields sent by every app.
Vehicle packet contents were encrypted during the Wi-Fi capture, so researchers could identify destinations but not inspect those packets’ payloads through that method. The summary also does not establish whether data recipients retained, sold or otherwise acted on the information. The extent to which traffic patterns change with different permissions, settings, regions or later software updates remains unclear.
As an affiliate, we earn on qualifying purchases.
Publication and Manufacturer Responses
The research team says its peer-reviewed paper is scheduled for IMC ’26. The project describes a lengthy disclosure process and says it provides insight into how manufacturers perceive data sharing, but the supplied summary does not detail individual companies’ responses or any resulting changes to products or policies.
Further reporting can examine the paper’s full methods and results, including which data types and destinations were identified, and whether manufacturers alter data practices after receiving the findings. For consumers, the study supports checking connected-service and app privacy settings, while recognizing that the reported tests do not determine the practices of every vehicle or service.
As an affiliate, we earn on qualifying purchases.
Key Questions
What did the connected-vehicle study find?
The team reports that 19 of 21 vehicles contacted at least one third party over Wi-Fi, and seven of 30 apps transmitted sensitive identifiers to third-party companies during testing.
Did the researchers prove that companies sold the data?
No. The study observed network transmissions. The project summary does not establish whether recipients sold, retained or used the information for particular purposes.
How were the vehicles and apps tested?
Researchers tested vehicles in controlled idle, active and driving conditions and captured Wi-Fi destinations. They also paired 30 apps with vehicles and monitored app network traffic on test iPhones.
When were the tests conducted?
The experiments took place at Consumer Reports’ testing facility from October 2024 through August 2025.
What happens next with the research?
The team says the peer-reviewed paper is scheduled for publication at IMC ’26. The available project summary does not specify a publication date or detail individual manufacturers’ responses.
Source: hn
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
