
Modern cars are no longer isolated machines. They contain internet-connected infotainment systems, mobile apps, Bluetooth connections, navigation services, wireless keys, telematics units and dozens of computers communicating with one another.
That connectivity creates new ways for attackers to target a vehicle, but the reality is more complicated than the idea of a hacker sitting miles away and suddenly taking over the steering wheel. Experts say the biggest distinction is between hacking a connected feature and gaining control of safety-critical driving functions.
According to experts, remote attacks against driving systems have been demonstrated in laboratory conditions, while he is not aware of a successful real-world attack that has remotely hijacked a vehicle's steering or braking.
Research and incidents involving Jeep, BMW and Kia vehicles nevertheless show that connected cars can have exploitable weaknesses, particularly around infotainment, telematics and online services. The risk is real, but so is the gap between compromising a car's digital features and controlling the car itself.
What Can Actually Be Hacked in a Connected Car?
The phrase 'car hacking' can make it sound as though every electronic component of a modern vehicle is sitting on the open internet. That is not how most vehicles are designed. Cars contain multiple electronic systems and networks, with different functions separated to reduce the consequences of an intrusion.
Ash Allen, speaking to TechTimes exclusively as a researcher at the University of Hertfordshire, explained that the first question is what is meant by 'hacked'.
'The first point is to determine what you mean by "hacked"?' he said. 'I am assuming that you are interested in anything that can take control of the car remotely and, say, apply the brakes, or steer off the road?'
He pointed out that higher-level compromises, such as breaking into a vehicle or accessing non-driving systems, are much more realistic. Infotainment systems are particularly attractive targets because they are designed to communicate with phones, wireless networks, online services and other external systems.
The distinction matters because the infotainment system is not necessarily the same thing as the network responsible for controlling the vehicle's driving functions. Allen explained that driving-related functions operate on a separate network known as the controller area network, or CAN.
That does not make the CAN completely unreachable. The security question is whether an attacker can find a path from an externally accessible system into a network that can issue commands to safety-critical components.
One of the best-known demonstrations came in 2015, when security researchers Charlie Miller and Chris Valasek remotely compromised a Jeep Cherokee through a vulnerability in its Uconnect system.
Their demonstration showed that an internet-connected infotainment system could ultimately be used to send commands to vehicle systems, including the brakes and steering. Chrysler subsequently issued a software update to address the vulnerability.
That case remains important because it showed why connectivity changes the security equation. A weakness in a system that appears to be primarily about entertainment or communications can become much more serious if an attacker can move from that system into networks controlling physical components.
Researchers have found similar problems in other manufacturers' vehicles. In 2018, Tencent's Keen Security Lab reported 14 vulnerabilities affecting multiple BMW connected vehicles.
The researchers examined components including infotainment, telematics and the central gateway, and reported both local and remote attack paths. BMW confirmed the vulnerabilities and worked with the researchers on remediation.
The lesson is not that every connected BMW, Jeep or other modern vehicle is waiting to be hijacked. It is that the number of potential entry points has increased as cars have become computers on wheels. Recently a hack into Jaguar Land Rover ended up costing the UK billions.
Modern vehicles can also be attacked through physical access. Allen said it is possible to reach a vehicle's CAN network locally, although doing so can require considerable effort. He also noted that third-party devices such as OBD readers can provide another route into vehicle systems.
That is why vehicle security is not solely about the car manufacturer's own software. Accessories, diagnostic equipment, connected services and third-party suppliers can all become part of the security picture.
Government agencies recognise the same problem. The US National Highway Traffic Safety Administration says automotive cybersecurity involves protecting electronic systems, communications networks, control algorithms, and software.
User data must also be protected from unauthorised access or manipulation. It recommends a layered approach that protects safety-critical systems while also monitoring potential attack paths.
The Bigger Risk May Be the Digital Ecosystem Around Your Car
The most realistic threat to many drivers may not be someone remotely grabbing the steering wheel. Connected vehicles can expose owners to attacks involving their accounts, personal information, location data, vehicle access and connected services.
A 2024 investigation into Kia's online services demonstrated how serious that category of vulnerability can become. Security researchers found a flaw in Kia's web infrastructure that could allow attackers to take control of certain internet-connected features associated with vehicles.
The researchers reported that they could access functions such as unlocking and starting vehicles and obtain location information, although the vulnerability did not provide the ability to remotely drive the vehicle or control its brakes. Kia subsequently fixed the issue.
That distinction is crucial. A hacker being able to unlock your car is a security problem. A hacker being able to track its location is a privacy problem. A hacker being able to start the vehicle remotely creates another set of risks. None of those automatically means the attacker can steer the vehicle down the road.
The wider connected-vehicle ecosystem is also growing. Cars now communicate with manufacturer servers, smartphone applications, charging infrastructure, cloud services and third-party platforms.
Security researchers and industry reports increasingly focus on these connections because compromising an external service could potentially affect large numbers of vehicles at once.
Upstream Security's 2025 automotive cybersecurity report found that telematics and application servers accounted for 66% of the attack targets it analysed, while APIs accounted for 17%.
The report also said 59% of incidents resulted in data or privacy breaches and 55% caused operational disruption. Those figures illustrate how automotive cybersecurity extends beyond the vehicle's physical controls.
For drivers, there are also more familiar threats. Keyless entry systems have been targeted by criminals using relay and other techniques to imitate or extend legitimate key signals. These attacks can allow thieves to unlock and start compatible vehicles without physically possessing the owner's key.
They are a form of automotive technology abuse, but they are very different from remotely taking control of steering or brakes. Allen's assessment puts the situation into perspective.
'So, to summarise, things like alarms, immobilizers, etc. can absolutely be attacked,' he said. 'There are a few "over the air" hacks that target the infotainment systems of modern cars as they generally seem to be the weak point.'
He said remote attacks affecting driving functions have been demonstrated in laboratory environments, but added: 'In terms of remote, James Bond-style hijacking of the car's driving functions, outside very specific lab conditions I don't know of any successful attacks.'
That is perhaps the most useful answer for ordinary motorists. The possibility of automotive hacking should not be dismissed, but neither should drivers assume that every connected vehicle can be remotely commandeered at any moment.
Manufacturers are also under increasing pressure to treat cybersecurity as part of vehicle safety. UN Regulation No. 155 established an international framework requiring manufacturers to identify and manage cyber risks, test security measures, monitor attacks and maintain cybersecurity throughout a vehicle's life.
The UK's Department for Transport has similarly published principles for connected and automated vehicles covering secure design, supply-chain risks, software security, incident response and protection of data. For owners, the practical steps are fairly straightforward.
Keep vehicle software updated when manufacturers issue security fixes, protect accounts associated with connected-car services, use strong and unique passwords, be cautious about third-party devices and avoid plugging unknown equipment into diagnostic ports.
The US Cybersecurity and Infrastructure Security Agency also advises vehicle operators to install recommended software updates, avoid unsecured or unknown devices and look for signs of physical tampering, including unfamiliar equipment attached to OBD-II ports.
The modern car can certainly be hacked. The real question is what an attacker can reach after getting in. For now, the evidence suggests that compromising connected services, infotainment, telematics and vehicle access is a much more established concern than the Hollywood-style scenario of a stranger remotely steering a car down the road.
That distinction is reassuring, but it also explains why automotive cybersecurity remains an important issue as vehicles become increasingly connected.
Frequently Asked Questions
- What is car hacking?Car hacking refers to unauthorized access or manipulation of a vehicle's electronic systems, often through connected features.
- Can hackers remotely control a car's driving functions?While remote attacks on driving functions have been demonstrated in labs, there are no known successful real-world attacks of this nature.
- What are common targets for car hackers?Common targets include infotainment systems, telematics, and connected services, which can be exploited to access non-driving functions.
- How can I protect my car from cyber threats?Keep software updated, use strong passwords, be cautious with third-party devices, and regularly check for physical tampering.




