The Car That Knows Too Much: How the Connected Vehicle Became the Most Invasive Data Collection Device You Own
130,000 UK Mercedes records on a cybercrime forum. Toyota's decade-long location-data exposure across 2.15 million customers. VW feeding driver location to law enforcement. The Mercedes breach is the visible surface rupture; the architecture beneath is a surveillance contract you signed when you bought the car.
You Bought a Car. You Agreed to a Surveillance Contract.
The purchase contract you signed when you bought your car was several pages long. The privacy policy you accepted — scrolled past, did not read, or were never shown — was longer. Toyota's connected vehicle privacy architecture currently requires navigating twelve separate policy documents to understand what data the company collects, who it shares it with, and under what circumstances. Twelve documents. For a car.
Toyota vehicles log location, driving habits, voice commands, and even biometric data like facial recognition. Mozilla found that Toyota collects far more data than is necessary and shares it with marketers. In 2023, the company admitted a decade-long security lapse that exposed the location data of 2.15 million users.
A decade. Toyota was collecting and exposing the location data of its customers for a decade before it acknowledged the lapse. The data — precise location histories of 2.15 million vehicles — was accessible during that period to anyone who knew where to look. The owners of those vehicles did not know their location histories were being collected. They did not know those histories were accessible. They were driving their cars.
This week, researchers confirmed that an alleged dataset of 130,000 UK Mercedes-Benz customers had appeared on a cybercrime forum. The listing claimed to contain customer and vehicle data records including personal identifiers, vehicle details, and location-linked information. Researchers confirmed the dataset included sample records that appeared legitimate. One scheme the data enables is VIN cloning — criminals steal a legitimate VIN from a legally registered vehicle and attach it to a stolen car of the same make and model, allowing the stolen vehicle to be resold with counterfeit documentation.
130,000 UK drivers. One forum listing. The data sufficient for targeted phishing attacks that reference the victim's exact car model, lease details, and service schedule. For fake maintenance alerts directing victims to fraudulent payment portals. For synthetic identity fraud built on the combination of owner details and vehicle registration records. For VIN cloning operations that place stolen vehicles back into the market with legitimate-appearing documentation.
You did not have to be a Mercedes customer for this to concern you. The Mercedes breach is a symptom. The disease is the architecture of connected vehicle data collection that has been built, across every major manufacturer, over the past decade — an architecture whose fundamental premise is that the data your vehicle generates belongs to the manufacturer, not to you.
What Your Car Actually Collects
The phrase "connected vehicle" understates what modern cars have become. A connected vehicle is not a car with GPS. It is a data collection platform with wheels — equipped with sensors, cameras, microphones, accelerometers, and cellular connectivity that generates a continuous stream of information about its driver, its passengers, its surroundings, and its mechanical state, transmitted in real time to manufacturer servers and, through a cascade of data sharing agreements, to third parties whose identity and purpose most owners have never been informed of.
In its response to congressional inquiry, Toyota admitted to collecting a range of personal data from drivers, including their location, facial features similar to phone unlocking methods, and even voice recordings. Honda said it gathers automotive, electronic, visual data, searches, call history and voice commands. Senator Markey described modern cars as computers on wheels that amass vast quantities of personal information.
Toyota collects facial recognition data from the driver monitoring system designed to detect fatigue. It collects voice recordings from the in-car assistant. It collects precise location history from the navigation and telematics systems. It collects acceleration, braking, and engine data from the onboard diagnostics. It collects information about passengers through cabin-facing cameras. And it shares this data with marketers, insurance companies, and third-party analytics providers whose individual privacy commitments are not covered by Toyota's own privacy policy — which is one of twelve documents a customer would need to read to understand the full scope of what they have agreed to.
VW tracks age, gender, driving behaviour, GPS data, and voice interactions — using this data for targeted advertising. One VW subsidiary was caught quietly feeding location data to law enforcement. In 2021, 3.3 million customer records were exposed in a breach.
The law enforcement data sharing is the element that received the least public attention and deserves the most. A VW subsidiary feeding precise location data to law enforcement — without the knowledge of vehicle owners, without a warrant requirement, through a commercial data arrangement that the legal framework governing law enforcement data access was not designed to cover — is the automotive industry's version of the adtech surveillance architecture that the previous DSI article documented being used to track US military personnel in active war zones. The mechanism is identical. The data flows from the vehicle to the manufacturer to a third party who provides it to a law enforcement or intelligence customer. The vehicle owner is not informed. The vehicle owner has no recourse.
Connected vehicles generate vast amounts of data, from driver profiles and telematics to location tracking and nearby pedestrians. There are 26 million electric vehicles on roads globally, projected to reach 145 million by 2030. The data passes through a complex ecosystem of manufacturers, suppliers, connectivity providers, and service operators.
145 million connected vehicles by 2030. Each generating continuous data streams. Each transmitting that data through a supply chain of manufacturers, telematics providers, connectivity operators, and third-party analytics companies — every node of which is a potential breach surface, every data sharing agreement of which is a potential access pathway for any actor willing to purchase the data legitimately or steal it illegitimately.
The Breach History That Preceded Mercedes
The Mercedes UK breach is not an isolated incident. It is the most recent data point in a documented pattern of automotive industry data failures that stretches across every major manufacturer and every category of data the connected vehicle ecosystem collects.
Mercedes-Benz itself has a documented breach history that precedes the UK forum listing. In January 2024, RedHunt Labs researchers discovered that Mercedes-Benz had unintentionally left a private GitHub authentication token accessible online, exposing internal data including the company's source code — internal documents, API keys, and cloud access credentials included in the exposed repositories. The source code of a vehicle manufacturer's connected services infrastructure in the hands of a researcher who disclosed it responsibly is one outcome. The same data in the hands of a threat actor who does not disclose is a different one — and the gap between those two outcomes is the luck of who found it first.
This analysis is published. Your decision isn't.
We run the same cross-domain, scenario-based foresight on the decision in front of you — a deal, a market entry, a supplier dependency. Board-ready in five days, with a foresight indicator watchlist.