Moneycontrol
HomeTechnologyNew hack threat: Thieves can now break into smart electric cars from anywhere

New hack threat: Thieves can now break into smart electric cars from anywhere

Researcher Eaton Zveare bypassed login security to create an admin account, gaining access to over 1,000 dealers. The flaws were patched after disclosure but raise concerns about dealership system security.

August 11, 2025 / 19:01 IST
Story continues below Advertisement
Hackers

A security researcher has revealed critical vulnerabilities in the web portal of a well-known carmaker that could have allowed hackers to remotely unlock and control customers’ vehicles from anywhere. The flaws exposed private customer data and vehicle information, and offered a backdoor into the company’s entire dealer network.

Eaton Zveare, a security researcher at software delivery firm Harness, discovered the weaknesses earlier this year while exploring the dealer portal as a weekend project. The unnamed carmaker has several popular sub-brands, though Zveare declined to disclose the name.

Story continues below Advertisement

Zveare explained that the main issue was a bug in the portal’s login system. By exploiting code that loaded directly in the browser on the login page, he was able to bypass security checks and create a “national admin” account with unrestricted access to the portal. This gave him control over more than 1,000 dealers across the United States.

With this admin access, Zveare could view sensitive customer and financial data, track vehicles in real time, and enroll users in connected features that allow remote control of vehicle functions, including unlocking the car.