Tesla data breach of old car parts is for sale on eBay
Security researchers have identified old Tesla car parts for sale on eBay with personal data of previous owners and has created some controversy among the Tesla’s customer privacy. GreenTheOnly, a white hat hacker had mentioned that the media control units (MCUs) and an autopilot hardware that were switched in the old models of Tesla vehicles are now being sold online.
These parts contained previous owners personal data like address, WiFI usernames and passwords, calendar data, call logs, and mobile contact book data that had been paired with the car, along with Netflix and other session cookies that have been accessed earlier through those components.
Tesla data breach through old components
Tesla upgrades car components when requested and the old components are taken back by Tesla and is not allowed to remain with the car owners.
On the contradictory, this discovery by the white hat shows that the techs are selling the withdrawn old components online, or according to InsideEVs, black hats are leveraging a random Tesla warehouse or service centers for the details.
Tesla has not responded yet to the discovery, and has not denied the same until this article was published. However, the techs have been advised by the firm to crush the old components before disposing of them as a junk. Meanwhile, Tesla is yet to notify its customers about this data breach, however it is better for the previous owners to update passwords of any accounts that have been paired or linked to the car.
Aftermath of Tesla data breach
However, considering the California Consumer Privacy Act (CCPA) is in force, and after Tesla data breach, the company may be asked to prove their innocence or penalized for their negligence of personal data protection and security. Furthermore, with the development in the automotive sector, more components and devices do have access to computerized data.
Any information that is stored in a computerized format, can be equally stored in devices that are involved with the operation. Advanced car manufacturing companies like Tesla and others need to ensure they have proper data protection lifecycle in place to ensure no stone is left unturned. Also, this Tesla data breach case is a wonderful example of non-intentional insider threat vector.
Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.