• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechInternet of Things

How Hackers Could Heat Up a Nissan Leaf

By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
February 24, 2016, 2:29 PM ET
Business Wire

There are more than 200,000 Nissan Leaf electric cars on the road. But the most popular plug-in in the world may also come with one problematic feature: a hackable heat and air conditioning system.

Security expert Troy Hunt revealed the find on his blog on Wednesday after he said he spent a month going back and forth with the car maker about creating a fix for the security hole.

Nissan did not immediately respond to a request for comment from Fortune, but Hunt said he contacted the company in late January to alert Nissan about the flaw.

This isn’t the first time or the most serious way connected cars have gone buggy. Last year, hackers tapped into the controls on a Jeep Cherokee, running the windshield wipers and blasting music while also, more disturbingly, cutting the vehicle’s transmission.

On the Leaf, air conditioning and heat can be controlled via an app meant to let owners remotely pre-heat or cool their cars. But as Hunt shows, anyone with a working Internet connection and a little coding know-how can enter a few commands and control the climate in the car. Hackers also need the car’s vehicle identification number (VIN), the unique ID label that’s displayed on all cars.

Get Data Sheet, Fortune’s technology newsletter.

“I would make the assumption that people don’t want other people being able to turn features on and off,” Hunt said in an interview with Fortune.

Hunt said he tried the trick out on a friend’s car in the U.K. using commands from his own computer in Australia.

Besides running heat and cooling, Hunt could also see a log of trip distances, learning more about the car’s daily driving patterns.

A car app relies on a fundamental security principle that Hunt says Nissan has only built up halfway: A consumer logs in to a car system on a computer or smartphone, but the app never subsequently verifies from where commands to the car are coming.

In other words, Hunt explained, “It never makes sure you are you.”

Hunt says the easiest thing for Nissan to do would be to shut the feature down until the company can develop a fix, such as some kind of an authorization token that would verify command origins. For now, Leaf owner and U.K. security consultant Scott Helme said it may be possible for consumers to temporarily opt-out of the remote system by deactivating the app from the owner portal on a computer browser.

Healthcare And Auto Companies Are In Danger Of Hacks:

Nissan continued its push toward more connected cars this week at Mobile World Congress in Barcelona. The company rolled out its 2016 edition of the Leaf, which boasts even more connectivity features. Users will be able to manage car batteries remotely, including setting timers for charging up vehicles.

“Nissan is proud to be at the forefront of developing efficient and reliable in-vehicle connected technologies that are available and accessible to all,” said Gareth Dunsmore, director of electric vehicles for Nissan Europe, during the event.

Meanwhile, Hunt underscored he’s been in conversation with people from around the world, including in Canada, the U.K., South Africa and Norway, all worried about the security hole.

Update (Feb. 24): In a statement to Fortune, Nissan said the company is aware of the NissanConnect EV App issue and is working on a fix.

About the Author
By Hilary Brueck
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Aerial view of a data center under construction in Ohio.
EconomyEconomics
Before AI gains materialize, governments will have to deal with a ‘policy trade-off,’ Moody’s says: How to handle the massive spending and debt risk
By Tristan BoveFebruary 27, 2026
7 minutes ago
Graphic depicting a coin reads, Fortune Crypto: Facebook Crypto 2.0
CryptoCrypto Playbook
Facebook’s first crypto push set off a firestorm. This time around, its plans are met with a shrug
By Jeff John RobertsFebruary 27, 2026
1 hour ago
jack dorsey
AILayoffs
Block CEO Jack Dorsey lays off nearly half of his staff because of AI and predicts most companies will make similar cuts in the next year
By Jake AngeloFebruary 27, 2026
2 hours ago
Anthropic CEO Dario Amodei.
AIAnthropic
The Pentagon brands Anthropic’s CEO a ‘liar’ with a ‘God-complex’ as deadline looms over AI use in weapons and surveillance
By Beatrice NolanFebruary 27, 2026
4 hours ago
lacks
LawLawsuit
The immortal life of Henrietta Lacks lawsuits gets a bit shorter with Novartis settlement
By Brian Witte and The Associated PressFebruary 27, 2026
4 hours ago
burger king
AIOpenAI
Burger King tests OpenAI-powered headsets that will track the friendliness of drive-through workers
By Dee-Ann Durbin and The Associated PressFebruary 27, 2026
6 hours ago

Most Popular

placeholder alt text
Innovation
An MIT roboticist who cofounded bankrupt robot vacuum maker iRobot says Elon Musk’s vision of humanoid robot assistants is ‘pure fantasy thinking’
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago
placeholder alt text
Success
Jeff Bezos says being lazy, not working hard, is the root of anxiety: ‘The stress goes away the second I take that first step’
By Sydney LakeFebruary 25, 2026
2 days ago
placeholder alt text
Economy
Trump claims America is ‘winning so much.’ The IMF agrees, adding that Trump’s trade policies are the only thing holding it back from even more
By Tristan BoveFebruary 26, 2026
1 day ago
placeholder alt text
Success
Gen Z Olympic champion Eileen Gu says she rewires her brain daily to be more successful—and multimillionaire founder Arianna Huffington says it really does work
By Orianna Rosa RoyleFebruary 25, 2026
2 days ago
placeholder alt text
Economy
It’s more than George Clooney moving to France: America is becoming the ‘uncool’ country that people want to move away from
By Nick LichtenbergFebruary 27, 2026
12 hours ago
placeholder alt text
AI
Jamie Dimon says society should start preparing for AI job displacement: ‘Now’s the time to start thinking about’ it
By Marco Quiroz-GutierrezFebruary 25, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.