• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechInternet of Things

How Hackers Could Heat Up a Nissan Leaf

By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
By
Hilary Brueck
Hilary Brueck
Down Arrow Button Icon
February 24, 2016, 2:29 PM ET
Business Wire

There are more than 200,000 Nissan Leaf electric cars on the road. But the most popular plug-in in the world may also come with one problematic feature: a hackable heat and air conditioning system.

Security expert Troy Hunt revealed the find on his blog on Wednesday after he said he spent a month going back and forth with the car maker about creating a fix for the security hole.

Nissan did not immediately respond to a request for comment from Fortune, but Hunt said he contacted the company in late January to alert Nissan about the flaw.

This isn’t the first time or the most serious way connected cars have gone buggy. Last year, hackers tapped into the controls on a Jeep Cherokee, running the windshield wipers and blasting music while also, more disturbingly, cutting the vehicle’s transmission.

On the Leaf, air conditioning and heat can be controlled via an app meant to let owners remotely pre-heat or cool their cars. But as Hunt shows, anyone with a working Internet connection and a little coding know-how can enter a few commands and control the climate in the car. Hackers also need the car’s vehicle identification number (VIN), the unique ID label that’s displayed on all cars.

Get Data Sheet, Fortune’stechnology newsletter.

“I would make the assumption that people don’t want other people being able to turn features on and off,” Hunt said in an interview with Fortune.

Hunt said he tried the trick out on a friend’s car in the U.K. using commands from his own computer in Australia.

Besides running heat and cooling, Hunt could also see a log of trip distances, learning more about the car’s daily driving patterns.

A car app relies on a fundamental security principle that Hunt says Nissan has only built up halfway: A consumer logs in to a car system on a computer or smartphone, but the app never subsequently verifies from where commands to the car are coming.

In other words, Hunt explained, “It never makes sure you are you.”

Hunt says the easiest thing for Nissan to do would be to shut the feature down until the company can develop a fix, such as some kind of an authorization token that would verify command origins. For now, Leaf owner and U.K. security consultant Scott Helme said it may be possible for consumers to temporarily opt-out of the remote system by deactivating the app from the owner portal on a computer browser.

Healthcare And Auto Companies Are In Danger Of Hacks:

Nissan continued its push toward more connected cars this week at Mobile World Congress in Barcelona. The company rolled out its 2016 edition of the Leaf, which boasts even more connectivity features. Users will be able to manage car batteries remotely, including setting timers for charging up vehicles.

“Nissan is proud to be at the forefront of developing efficient and reliable in-vehicle connected technologies that are available and accessible to all,” said Gareth Dunsmore, director of electric vehicles for Nissan Europe, during the event.

Meanwhile, Hunt underscored he’s been in conversation with people from around the world, including in Canada, the U.K., South Africa and Norway, all worried about the security hole.

Update (Feb. 24): In a statement to Fortune, Nissan said the company is aware of the NissanConnect EV App issue and is working on a fix.

About the Author
By Hilary Brueck
See full bioRight Arrow Button Icon

Latest in Tech

Big TechStreaming
Trump warns Netflix-Warner deal may pose antitrust ‘problem’
By Hadriana Lowenkron, Se Young Lee and BloombergDecember 7, 2025
6 hours ago
Big TechOpenAI
OpenAI goes from stock market savior to burden as AI risks mount
By Ryan Vlastelica and BloombergDecember 7, 2025
6 hours ago
AIData centers
HP’s chief commercial officer predicts the future will include AI-powered PCs that don’t share data in the cloud
By Nicholas GordonDecember 7, 2025
8 hours ago
Future of WorkJamie Dimon
Jamie Dimon says even though AI will eliminate some jobs ‘maybe one day we’ll be working less hard but having wonderful lives’
By Jason MaDecember 7, 2025
13 hours ago
CryptoCryptocurrency
So much of crypto is not even real—but that’s starting to change
By Pete Najarian and Joe BruzzesiDecember 7, 2025
17 hours ago
Elon Musk
Big TechSpaceX
SpaceX to offer insider shares at record-setting $800 billion valuation
By Edward Ludlow, Loren Grush, Lizette Chapman, Eric Johnson and BloombergDecember 6, 2025
1 day ago

Most Popular

placeholder alt text
Real Estate
The 'Great Housing Reset' is coming: Income growth will outpace home-price growth in 2026, Redfin forecasts
By Nino PaoliDecember 6, 2025
2 days ago
placeholder alt text
AI
Nvidia CEO says data centers take about 3 years to construct in the U.S., while in China 'they can build a hospital in a weekend'
By Nino PaoliDecember 6, 2025
2 days ago
placeholder alt text
Economy
The most likely solution to the U.S. debt crisis is severe austerity triggered by a fiscal calamity, former White House economic adviser says
By Jason MaDecember 6, 2025
1 day ago
placeholder alt text
Economy
JPMorgan CEO Jamie Dimon says Europe has a 'real problem’
By Katherine Chiglinsky and BloombergDecember 6, 2025
1 day ago
placeholder alt text
Big Tech
Mark Zuckerberg rebranded Facebook for the metaverse. Four years and $70 billion in losses later, he’s moving on
By Eva RoytburgDecember 5, 2025
3 days ago
placeholder alt text
Uncategorized
Transforming customer support through intelligent AI operations
By Lauren ChomiukNovember 26, 2025
11 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.