• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechInternet of Things

How Hackers Could Heat Up a Nissan Leaf

By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
February 24, 2016, 2:29 PM ET
Business Wire

There are more than 200,000 Nissan Leaf electric cars on the road. But the most popular plug-in in the world may also come with one problematic feature: a hackable heat and air conditioning system.

Security expert Troy Hunt revealed the find on his blog on Wednesday after he said he spent a month going back and forth with the car maker about creating a fix for the security hole.

Nissan did not immediately respond to a request for comment from Fortune, but Hunt said he contacted the company in late January to alert Nissan about the flaw.

This isn’t the first time or the most serious way connected cars have gone buggy. Last year, hackers tapped into the controls on a Jeep Cherokee, running the windshield wipers and blasting music while also, more disturbingly, cutting the vehicle’s transmission.

On the Leaf, air conditioning and heat can be controlled via an app meant to let owners remotely pre-heat or cool their cars. But as Hunt shows, anyone with a working Internet connection and a little coding know-how can enter a few commands and control the climate in the car. Hackers also need the car’s vehicle identification number (VIN), the unique ID label that’s displayed on all cars.

Get Data Sheet, Fortune’s technology newsletter.

“I would make the assumption that people don’t want other people being able to turn features on and off,” Hunt said in an interview with Fortune.

Hunt said he tried the trick out on a friend’s car in the U.K. using commands from his own computer in Australia.

Besides running heat and cooling, Hunt could also see a log of trip distances, learning more about the car’s daily driving patterns.

A car app relies on a fundamental security principle that Hunt says Nissan has only built up halfway: A consumer logs in to a car system on a computer or smartphone, but the app never subsequently verifies from where commands to the car are coming.

In other words, Hunt explained, “It never makes sure you are you.”

Hunt says the easiest thing for Nissan to do would be to shut the feature down until the company can develop a fix, such as some kind of an authorization token that would verify command origins. For now, Leaf owner and U.K. security consultant Scott Helme said it may be possible for consumers to temporarily opt-out of the remote system by deactivating the app from the owner portal on a computer browser.

Healthcare And Auto Companies Are In Danger Of Hacks:

Nissan continued its push toward more connected cars this week at Mobile World Congress in Barcelona. The company rolled out its 2016 edition of the Leaf, which boasts even more connectivity features. Users will be able to manage car batteries remotely, including setting timers for charging up vehicles.

“Nissan is proud to be at the forefront of developing efficient and reliable in-vehicle connected technologies that are available and accessible to all,” said Gareth Dunsmore, director of electric vehicles for Nissan Europe, during the event.

Meanwhile, Hunt underscored he’s been in conversation with people from around the world, including in Canada, the U.K., South Africa and Norway, all worried about the security hole.

Update (Feb. 24): In a statement to Fortune, Nissan said the company is aware of the NissanConnect EV App issue and is working on a fix.

About the Author
By Hilary Brueck
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

Latest in Tech

AIthe future of work
‘Godfather of AI’ Geoffrey Hinton predicts 2026 will see the technology get even better and gain the ability to ‘replace many other jobs’
By Jason MaDecember 28, 2025
3 hours ago
Startups & VentureTaxes
California tech founders unload on a proposed state wealth tax that already has some billionaires preparing an escape. ‘I am screwed for life’
By Jason MaDecember 28, 2025
5 hours ago
Innovationspace
NASA’s upcoming moonshot may let astronauts be the first to lay eyes on parts of the lunar far side that were missed by the Apollo program
By Marcia Dunn and The Associated PressDecember 28, 2025
7 hours ago
Arts & EntertainmentGen Z
Gen Zers and millennials flock to so-called analog islands ‘because so little of their life feels tangible’
By Michael Liedtke and The Associated PressDecember 28, 2025
8 hours ago
Sridhar Ramaswamy is CEO of Snowflake, the AI Data Cloud company.
CommentarySoftware
Snowflake CEO: Big Tech’s grip on AI will loosen in 2026 — plus 6 more predictions that will define the year
By Sridhar RamaswamyDecember 28, 2025
9 hours ago
Sam Altman, chief executive officer of OpenAI Inc., during a media tour of the Stargate AI data center in Abilene, Texas, US, on Tuesday, Sept. 23, 2025.
AISam Altman
OpenAI CEO Sam Altman says he is ‘envious’ of Gen Z college dropouts who have the ‘mental space’ and time to build new startups
By Nino PaoliDecember 28, 2025
9 hours ago

Most Popular

placeholder alt text
Future of Work
Malcolm Gladwell tells young people if they want a STEM degree, 'don’t go to Harvard.' You may end up at the bottom of your class and drop out
By Sasha RogelbergDecember 27, 2025
1 day ago
placeholder alt text
Banking
Russian official warns a banking crisis is possible amid nonpayments. 'I don’t want to think about a continuation of the war or an escalation'
By Jason MaDecember 27, 2025
24 hours ago
placeholder alt text
Europe
Christmas 500 years ago was a drunken 6-week feast that may have been considerably better than the modern holiday, medieval historian says
By Bobbi Sutherland and The ConversationDecember 25, 2025
3 days ago
placeholder alt text
Success
As millions of Gen Zers face unemployment, CEOs of Amazon, Walmart, and McDonald's say opportunity is still there—if you have the right mindset
By Preston ForeDecember 26, 2025
3 days ago
placeholder alt text
Politics
Peter Thiel and Larry Page are preparing to flee California in case the state passes a billionaire wealth tax, report says
By Jason MaDecember 27, 2025
1 day ago
placeholder alt text
Retail
Trump just declared December 26th a national holiday. What's open and closed?
By Dave SmithDecember 26, 2025
3 days ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.