Dutch intelligence warns modern cars can create espionage risks
The AIVD says microphones, cameras, GPS and connected devices in modern vehicles can expose sensitive information and advises against confidential conversations in or near them.
By The Guardian
Drivers who handle sensitive information are being warned to think carefully about what they say and connect inside modern vehicles because smart-car technology can create opportunities for espionage.
The Netherlands’ General Intelligence and Security Service, known as the AIVD, has issued guidance on the risks posed by increasingly connected vehicles equipped with systems such as microphones, cameras, GPS and internet-enabled services.
The agency says modern cars can collect large amounts of information about passengers, the vehicle itself and people or objects nearby.
That data can be useful for everyday functions, including navigation, driver assistance and connected entertainment systems, but the AIVD says it may also be of interest to hostile state actors, cybercriminals and hackers.
Its advice is aimed particularly at government officials, senior business figures and others who may have access to confidential or sensitive information.
The AIVD says microphones fitted inside vehicles can, in technical terms, be activated remotely if a malicious actor gains access to relevant systems.
Its guidance therefore recommends that confidential conversations should not be held in or immediately around a modern connected vehicle.
The same concern applies to cameras.
Many newer vehicles contain internal and external cameras for driver assistance, parking and security features. The AIVD says remote access could potentially allow an attacker to make recordings inside or around the vehicle.
It advises people with sensitive roles to consider what a vehicle’s cameras may be able to see and to avoid using vehicles with external cameras when travelling to particularly sensitive locations.
Phone connections present another potential route for data exposure.
Modern cars frequently allow devices to connect through Bluetooth, Wi-Fi, USB ports or wireless charging systems.
The AIVD warns that compromised vehicle systems could potentially be used to access information from connected devices.
Its advice includes avoiding automatic Bluetooth and Wi-Fi connections where sensitive information is involved, not using wireless charging unnecessarily and considering a USB data blocker when charging a phone through a vehicle.
The intelligence service also points to the wider network of companies involved in connected-car services.
Vehicle manufacturers and technology providers can process data generated by cars, while malicious actors may try to obtain that information either directly from companies or through cyber attacks.
The AIVD does not single out an individual manufacturer or model in its guidance.
The warning has, however, emerged amid wider scrutiny of connected vehicles and the growing share of Chinese-made cars entering European and UK markets.
The Guardian reports that security concerns have already led some organisations to place restrictions on connected vehicles at sensitive sites and to advise staff against linking personal devices to certain cars.
The Dutch guidance stops short of suggesting that ordinary motorists should stop using connected-car features altogether.
Instead, it urges people to understand what information their vehicle may collect and to take additional precautions when their work or travel could expose commercially or nationally sensitive information.