Your Car Is Talking: How Connected Vehicles Feed Driver Data to Ad Tech Giants

Modern cars have become data machines on wheels. They constantly beam information to manufacturers and outside firms through built-in cellular links, Wi-Fi and GPS. A new study exposes just how much personal detail escapes these vehicles and their companion smartphone apps.

Researchers at Northeastern University’s Khoury College partnered with Consumer Reports to run the first large-scale measurement of this connected-car ecosystem. They tested 21 late-model vehicles from 19 brands and 30 associated mobile apps. The results surprised few experts yet still shock in their breadth. Consumer Reports detailed the partnership on Sept. 29, 2026.

Nineteen of the 21 vehicles contacted at least one third-party domain over Wi-Fi. Many of those domains belong to advertising, tracking or analytics companies. Seven of the 30 apps went further. They transmitted sensitive identifiers such as vehicle identification numbers, emails, phone numbers or precise locations to similar third parties.

Five apps paired VINs with other personal data before sending it along. That combination lets advertisers link a specific driver to detailed consumer profiles sold by data brokers. The study appears in the proceedings of the 2026 ACM Internet Measurement Conference and carries the title Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem. Lead authors include Nicole Zagson and Sarah Elizabeth Gillespie of Northeastern.

The team set up a controlled testing environment at Consumer Reports’ facility in Connecticut. Vehicles connected to a custom Wi-Fi access point built on a Raspberry Pi. This setup captured all outbound traffic while the cars sat idle, ran systems without driving, or moved at speeds from 5 to 45 miles per hour. Tests included acceleration, hard braking and normal operation. Apps ran on iPhones paired to the actual vehicles.

Such methodical collection produced hard numbers instead of speculation. Tesla and General Motors models stood out for volume. The Tesla Model 3 reached 34 advertising, tracking and analytics domains. The Cybertruck hit 23. Cadillac Lyriq followed with 10. In contrast, the Mercedes-Benz EQS and Buick Envista registered zero such contacts in the vehicle tests.

Yet no brand escaped entirely. Even models with low counts still phoned home to their manufacturers and a handful of support services. And the apps often doubled the exposure. Twenty-eight of 30 apps contacted at least one outside advertising or analytics firm.

The apps emerged as the greater risk.

Four GM apps—myCadillac, myChevrolet, myBuick and myGMC—plus HondaLink, MyNissan and the Lincoln app sent VINs alongside email addresses or location data. The researchers noted that a VIN reveals trim level, options and manufacturing plant. Those details serve as strong signals of household wealth. Combine them with a name or email and a tech platform can build a precise profile for targeted ads or even influence insurance pricing.

David Choffnes, a Northeastern professor and co-author, told interviewers the findings leave plenty to worry about. “It does not appear that a customer can buy a new car that does not track you,” co-author Sarah Elizabeth Gillespie said in comments relayed by outlets covering the release.

Recipients of the data read like a who’s who of American tech. Alphabet’s Google services, Amazon, Meta, Microsoft, Pinterest and Reddit ranked among the most frequent destinations. Other firms included Adobe, LexisNexis and Amplitude. Some traffic crossed international borders, though the study focused primarily on U.S. market vehicles.

The paper avoids sweeping claims. It simply documents what the packets reveal. Vehicles and apps contact first-party manufacturer domains as expected. They also reach car-specific support services. The surprise lies in the steady stream to advertising and tracking specialists. The Verge summarized the work on Sept. 29, noting the systematic approach filled a gap left by earlier suspicions.

Automakers have long argued that connected features improve safety, convenience and maintenance. Real-time diagnostics can alert drivers to problems. Over-the-air updates fix software bugs without a dealer visit. Location services help recover stolen cars. Yet the same architecture that delivers these benefits also creates persistent data flows that owners rarely see or control.

Consumer Reports has tracked this issue for years. Earlier investigations revealed that some brands sell driving data to brokers who then supply it to insurers. The new study shifts focus from paper privacy policies to actual network behavior. Policies promise protection. Packets show what really happens.

Variation across brands suggests the problem stems from choices, not technical necessity. Some manufacturers appear to have minimized third-party contacts. Others allow dozens. The same pattern holds for apps. A few transmit almost no sensitive data. Several send VINs paired with owner identifiers.

But the broader trend points one direction. Cars have joined smartphones as always-on sensors feeding the advertising economy. Drivers sit inside rolling data centers that broadcast their speed, location, braking habits and identity markers. And unlike a phone, you cannot easily turn the car’s connectivity off without disabling core functions.

Regulators have started to pay attention. European rules already limit some data practices. U.S. lawmakers have proposed bills targeting automotive data brokers. Yet enforcement lags behind the technology. The Northeastern team plans to release more detailed datasets and urges further independent testing.

Owners can take limited steps today. Review app permissions. Disable unnecessary connected services through vehicle menus. Use privacy modes where available. Still, many features require data sharing to operate. The study’s authors stop short of recommending specific brands. Their goal remains measurement, not endorsement.

Additional coverage reinforced the core numbers. Road & Track reported on Sept. 29 that nearly every automaker in the test sent data outward. Auto Connected Car News highlighted on Sept. 30 that the apps created the bigger leak. These reports drew directly from the project site and Consumer Reports’ article, adding context on real-world implications for insurance and marketing.

The research team at Northeastern includes experts in privacy, security and networked systems. Their work builds on prior studies of mobile app tracking and web measurement. This time they turned the same rigorous lens on automobiles. The result is a landmark dataset that others will reference for years.

Drivers have grown used to trading privacy for convenience on their phones. Cars may force a similar bargain, only now the device weighs thousands of pounds and travels at highway speeds. The packets keep flowing. The question is whether owners, manufacturers and regulators will demand better controls before the data becomes even more valuable, and more invasive.


Discover more from Web and IT News

Subscribe to get the latest posts sent to your email.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top

Discover more from Web and IT News

Subscribe now to keep reading and get access to the full archive.

Continue reading