• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Commentary

The Latest Security Threat Could Be Hiding in Your Car

By
David Barzilai
David Barzilai
and
Bethany Cianciolo
Bethany Cianciolo
Down Arrow Button Icon
By
David Barzilai
David Barzilai
and
Bethany Cianciolo
Bethany Cianciolo
Down Arrow Button Icon
June 4, 2016, 1:00 PM ET
on board a driving car - hood in foreground
Long exposure photograph captured with a front-mounted camera from outside the car. Streaking reflections in the car's surface and streaking background.Photograph by Emanuel M Schwermer via Getty Images

Have you ever watched a thrilling movie scene, where fear grips a driver who realizes he’s no longer in control of his car, but rather in the clutches of some far-off villain who has taken over? Ever wonder if it could actually happen? It turns out that with today’s connected cars, it’s not just a far-fetched plot dreamed up by an imaginative screenwriter, but a real possibility.

In mid-April, the U.S. assistant attorney general for national security warned that connected cars can be attacked, making them a potential target for hackers and terrorists. That warning came after a recent joint statement made by the FBI, the Department of Transportation, and the National Highway Traffic Safety Administration that warned “motor vehicles [are] increasingly vulnerable to remote exploits.”

Automotive companies and car systems providers have been taking notice, particularly after white-hat hackers demonstrated they can get into the connected cars on the road today and do almost anything, from turning on the radio and windshield wipers to killing the engine as the car flies down the freeway.

Many of today’s cars are made up of more than 100 small computers called controllers, which are responsible for running many of the car’s operations. They control the windshield wipers, move the driver’s seat, activate the airbags, run the engine, apply the brakes, etc. All of the controllers are connected to a network within the car, called a CAN (controller area network) bus.

A few controllers are available to the external world, enabling the car to connect to the Internet and external networks, such as GPS systems, cellular, Bluetooth and Wi-Fi networks. This connectivity, which is common in many of today’s automobiles, has given rise to the term “connected cars.” And it appears the connected car is here to stay: Gartner estimates there will be 250 million connected vehicles on the road by 2020.

Because the car is now connected to the Internet, Wi-Fi, etc., hackers can take advantage of those external connections to penetrate the car’s network and target its safety systems, just as they’ve done in enterprise and government data centers. In the enterprise, we continuously see attackers hack into externally connected devices, drop malware onto those devices, and then use that malware to move around the network to access and manipulate the data center’s critical resources. Using that same approach, hackers can penetrate connected cars—via the externally connected controllers—to gain access and control over all of the controllers in that car’s network. This means they can manipulate the car’s safety systems and drive or stop the car, leaving the driver helpless.

What concerns the FBI and the assistant to the attorney general the most is the potential grand scale of hacks on automobiles. For example, hackers could theoretically penetrate a single car make/model and then stop the engine of all of the cars of that make/model during rush hour. This type of coordinated hack could be used by criminal organizations or terrorists to create havoc or hold states ransom.

 

The good news is there are relatively effective solutions that can be used to protect automobiles. Unlike enterprise networks and data centers, which have many different devices connected to the Internet, cars are generally closed systems, with only a limited number of externally connected controllers. By protecting those externally connected controllers, car manufacturers can significantly minimize the risk of attackers being able to penetrate the car and disrupt its safe operations.

The industry is starting to take action, with car manufacturers and system providers strengthening their software security practices and hiring security teams. In addition, legislators proposed the Spy Car Act 2015, which is designed to ensure vehicle manufacturers in the U.S. take “reasonable measures to protect against hacking attacks” on all of a car’s “entry points,” i.e. the externally connected controllers.

The best way to protect those externally connected controllers is to ensure that nothing except factory settings is allowed to run on them. There are now open-source and commercial technologies that can be used by car manufacturers and system providers to allow only the code and applications that were approved in the factory to run on the controller. It is fairly easy to add this security software to the controller as a software update. By hardening the externally connected controller, the car cannot be infiltrated. There is no ambiguity; no false alarms; no threats.

Using this approach, connected cars on the road today can also be easily retrofitted. When cars are brought into the dealership for their annual service checks, the dealer occasionally upgrades some of the controllers’ software according to the system provider’s guidance. Vendors can take advantage of this annual cycle to add the hardening capabilities as part of a regular upgrade to the software of the car’s controllers, effectively protecting the cars from hackers.

David Barzilai is the executive chairman of Karamba Security.

About the Authors
By David Barzilai
See full bioRight Arrow Button Icon
By Bethany Cianciolo
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

old
Commentaryaffordability
The American household just took an 81% margin cut. Wall Street hasn’t priced it in
By Katica RoyMay 2, 2026
4 hours ago
dario
CommentaryAnthropic
Anthropic’s most powerful AI model just exposed a crisis in corporate governance. Here’s the framework every CEO needs.
By Jeffrey Sonnenfeld, Stephen Henriques, Dan Kent and Holden LeeMay 2, 2026
4 hours ago
mackenzie
Commentaryphilanthropy
Stop donating to Harvard and the Ivy League. There’s a better option that MacKenzie Scott already figured out
By Ed Smith-LewisMay 2, 2026
7 hours ago
drinks
CommentaryFood and drink
We need a new way of thinking about drinking: Time to replace the ‘standard drink’ with advice people can actually use
By Justin KissingerMay 2, 2026
7 hours ago
pakistan
CommentaryIran
Asia is being hammered by the Iran conflict’s economic fallout. The U.S. has the playbook to help—and every reason to
By Wendy Cutler and Jane MellsopMay 2, 2026
7 hours ago
francis
CommentaryFlorida
Former Miami Mayor Francis Suarez: Why I’m joining Stephen Ross and Ken Griffin in betting big on ambitious business leaders
By Francis SuarezMay 1, 2026
1 day ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
1 day ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
2 days ago
Current price of oil as of May 1, 2026
Personal Finance
Current price of oil as of May 1, 2026
By Joseph HostetlerMay 1, 2026
1 day ago
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
Law
A Chick-fil-A worker got fired and then showed up behind the register to allegedly refund himself over $80,000 in mac and cheese
By Catherina GioinoMay 1, 2026
22 hours ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
1 day ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
5 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.