Auto Rental News
MenuMENU
SearchSEARCH

Rental Cars' Infotainment Systems Vulnerable to Hacking

When drivers connect their phones to a rental car's infotainment system via Bluetooth, their personal data and safety can be compromised with malware through text messages.

August 10, 2018
Rental Cars' Infotainment Systems Vulnerable to Hacking

A maliciously crafted USB device plugged into a vehicle can infect the infotainment system, something that could be done by a driver via social engineering tricks, such as a USB loaded with free music that entices a driver to plug in the infected USB drive.

Photo via New Range Rover Evoque Autobiography/Flickr.

2 min to read


Zingbox, the leading Internet of Things (IoT) device management and security provider, has new research that shows how a car’s driver can be subject to cybersecurity attacks through the car’s “infotainment” system, the embedded operating system powering the iPad-looking display on today’s modern cars.

Previous car hacking efforts focused on the car’s functionality — brakes, steering, and door locking mechanisms. The idea that a car could be infected with ransomware or other viruses was hypothetical until now.

Ad Loading...

Zingbox researcher Daniel Regalado, co-author of Gray Hat Hacking, and independent researchers Gerardo Iglesias and Ken Hsu broke into a car’s infotainment system and reverse-engineered its main components with one goal in mind: to determine if a car’s operating system could be infected with malware and prove that this Trojan could be controlled remotely through SMS messages. In this way, a driver’s personal data and safety could be compromised using the driver’s own cell phone.

An auto infotainment system depends on the IoT to operate. The fact that an infotainment system can be infected is important learning for the industry, suggesting the need for stepped-up IoT cybersecurity solutions similar to what is already available for IoT devices in healthcare, financial services, and manufacturing. This would protect drivers, especially the millions of car renters around the world.

A car’s infotainment system powers GPS navigation and music selection, makes and receives phone calls, reads SMS messages, and can manage firmware updates. A maliciously crafted USB device plugged into a vehicle can infect the infotainment system, something that could be done by a driver via social engineering tricks, such as a USB loaded with free music that entices a driver to plug in the infected USB drive.

Once paired with the driver’s phone, malware in the infotainment system leverages the phone’s SMS message service to access personal information such as contact lists. It can also intercept banking authentication pins, or even block incoming or outgoing calls. The same SMS service could then be used to take control of the infotainment system remotely and create distractions for the driver or put the system into an unusable state that requires repair from the manufacturer.

More Rental Software

Photos of Martin Romjue and Denis Gjoni on opposite sides of large headline for the video.
Rental Operationsby Martin RomjueJune 17, 2026

Stop Losing Money On Rental Tolls

Regardless of your rental fleet size and structure, fleet managers, executives, and owners can gain valuable insights into an often-overlooked area of fleet operations.

Read More →
Interviewer Martin Romjue and guest Ryan Kerzner on both sides of a title page with large lettering.
Rental Operationsby Martin RomjueJune 3, 2026

Grow Your Rental Business Beyond Cars

Rental fleet operations are facing numerous evolving challenges and opportunities from AI technology to rate and revenue management, to customer service and business growth.

Read More →
An AI-imaging tunnel instantly scans a car for damages at Wenn's location in Lithuania.
Rental OperationsJune 2, 2026

Using AI to Create Clarity, Not Conflict, in Rental Car Damage

Rental companies still need people, policy, judgment, and thoughtful implementation, with operators remaining in control of the customer experience.

Read More →
Ad Loading...
Close up of a high-tech vehicle console with a remote key.
Rental OperationsJune 1, 2026

Get Ready To Roll: No Stopping Self-Driving Rental Cars

The autonomous mobility technology revolution will move at its own pace, but sooner rather than later.

Read More →
Two execs hold up a sign with Southwest and CarTrawler logos

Southwest Airlines Selects CarTrawler For Its Car Rental Booking Platform

The platform is designed to allow customers to compare and book rental vehicles more easily during the travel booking process.

Read More →
Photos of CEOs Colm Brady and Francois Kruger on a blue background and above a headline.
Telematicsby News/Media ReleaseMay 22, 2026

RentalMatics, GeoInt Partner On Rental Car Speed Tracking Tech

Rental operators can now detect and act on speeding while vehicles are still on rent, thereby reducing fines, admin workload, vehicle wear, and safety risks.

Read More →
Ad Loading...
NextPass 407 ETR

NextPass Expands Toll Payment Service to Highway In Toronto

Fleets and consumer can use a transponder-less option when traveling between Canada and the U.S.

Read More →
A black Jeep is displayed at the Zubie-Bosch-TSD exhibit during the International Car Rental Show.

Zubie, PurCo Integrate Rental Damage Detection With Telematics

The combination brings actionable vehicle insights into PurCo’s PurInspect platform, improving damage detection and operational efficiency for rental fleets.

Read More →
A tech collage of electronic devices against a computer chip blueprint map.
Rental OperationsMay 1, 2026

Why Car Rental Can No Longer Run On Workarounds

The shift from branch-based software to connected operations is turning rental technology into strategic infrastructure.

Read More →
Ad Loading...
A tech collage of electronic devices against a computer chip blueprint map.
Rental OperationsMay 1, 2026

Why Car Rental Can No Longer Run On Workarounds

The shift from branch-based software to connected operations is turning rental technology into strategic infrastructure.

Read More →
Ad Loading...