Related: Free App Helps Erase Personal Information, Data from Vehicles
Privacy4Cars Discovers Bluetooth-Enabled Vehicle Hack
Vehicle users should consider deleting personal data from any and all vehicle infotainment systems before allowing anyone access to their vehicle.

The hack was discovered by Privacy4Cars founder Andrea Amico during development of the namesake Privacy4Cars app in February.
Photo via Christopher Schirner/Flickr.
Privacy4Cars, the first mobile app designed to help erase personally identifiable information (PII) from modern vehicles, publicly disclosed today the existence of a concerning vehicle hack, titled CarsBlues, that exploits infotainment systems of several makes via the Bluetooth protocol.
The attack can be performed in a few minutes using inexpensive and readily available hardware and software and does not require significant technical knowledge.
As a result of these findings, it is believed that users across the globe who have synced a phone to a modern vehicle may have had their privacy threatened. It is estimated that tens of millions of vehicles in circulation are affected worldwide, with that number continuing to rise into the millions as more vehicles are evaluated.
The hack was discovered by Privacy4Cars founder Andrea Amico during development of the namesake Privacy4Cars app in February. Upon discovery, Amico, a vehicle privacy and cybersecurity advocate, immediately notified the Automotive Information Sharing and Analysis Center (Auto-ISAC), the organization established by the automotive industry to share and analyze intelligence about emerging cybersecurity risks among its members.
Amico worked for months with Auto-ISAC to help its affected members understand how an attacker might access stored contacts, call logs, text logs, and in some cases even full text messages without the vehicle’s owner/user being aware — and without the user’s mobile device being connected to the system. Amico recently noticed that at least two manufacturers have made systematic updates to their new 2019 models, making those new models immune to CarsBlues.
“Now that we have completed our ethical disclosure with the Auto-ISAC, we are turning our focus to educating the industry and the public about the risks associated with leaving personal information in vehicle systems,” Amico said in a statement. “The CarsBlues hack, given its ease to replicate, the breadth of situations in which it can be performed against unsuspecting targets, and the difficulty in detecting the exploitation, is a clear indication that industry and consumers alike need to be proactive when it comes to deleting personally identifiable information from vehicle infotainment systems.”
Those most at risk of having their personal information exposed include people who have synced their phones in vehicles that are no longer under their direct oversight, including but not limited to vehicles that have been rented, shared through a fleet or subscription service, loaned, sold, returned at the end of a lease, repossessed, or deemed a total loss. Additionally, people who have synced their phones and given others temporary access to their personal vehicle, such as at dealerships’ service centers, repair shops, peer-to-peer exchanges, and valets may also be at risk for CarsBlues.
Vehicle users should consider deleting personal data from any and all vehicle infotainment systems before allowing anyone access to their vehicle. Industry players should consider instituting a policy to protect consumer data, either by helping customers delete their personal information or by performing the operation themselves — similarly to how telecom carriers handle returned smartphones.
More Rental Software
Stop Losing Money On Rental Tolls
Regardless of your rental fleet size and structure, fleet managers, executives, and owners can gain valuable insights into an often-overlooked area of fleet operations.
Read More →Grow Your Rental Business Beyond Cars
Rental fleet operations are facing numerous evolving challenges and opportunities from AI technology to rate and revenue management, to customer service and business growth.
Read More →
Using AI to Create Clarity, Not Conflict, in Rental Car Damage
Rental companies still need people, policy, judgment, and thoughtful implementation, with operators remaining in control of the customer experience.
Read More →
Get Ready To Roll: No Stopping Self-Driving Rental Cars
The autonomous mobility technology revolution will move at its own pace, but sooner rather than later.
Read More →
Southwest Airlines Selects CarTrawler For Its Car Rental Booking Platform
The platform is designed to allow customers to compare and book rental vehicles more easily during the travel booking process.
Read More →
RentalMatics, GeoInt Partner On Rental Car Speed Tracking Tech
Rental operators can now detect and act on speeding while vehicles are still on rent, thereby reducing fines, admin workload, vehicle wear, and safety risks.
Read More →
NextPass Expands Toll Payment Service to Highway In Toronto
Fleets and consumer can use a transponder-less option when traveling between Canada and the U.S.
Read More →
Zubie, PurCo Integrate Rental Damage Detection With Telematics
The combination brings actionable vehicle insights into PurCo’s PurInspect platform, improving damage detection and operational efficiency for rental fleets.
Read More →
Why Car Rental Can No Longer Run On Workarounds
The shift from branch-based software to connected operations is turning rental technology into strategic infrastructure.
Read More →
Why Car Rental Can No Longer Run On Workarounds
The shift from branch-based software to connected operations is turning rental technology into strategic infrastructure.
Read More →
