05-16-2020, 11:43 PM | #1 |
Lieutenant
601
Rep 455
Posts |
Did the BMW Connected App Just Get Majorly Hacked? Answer: No
Was sitting on the couch with the wife watching TV, suddenly she got an alert to her phone from the BMW connected app saying "The panic alarm on your X7 M50i is going off". We don't have an X7...we have an X5 and an M2.
So she logged into the app and now it shows someone else's 330i in Georgia (we live in Texas) as her registered vehicle. She is able to see all the personal information associated with this car, destinations, home address, sync'd calendar events, etc. I ran outside to make sure our cars were okay (they were). And we logged in and out of the app. Upon logging back in now it shows a 440i from Las Vegas. Again, we can see all the personal information associated with this new car. I had the ability to remote start, unlock, etc.... Tried calling BMW but they're closed. Will update as more happens but this appears to be a major breach of some sort. Edit: it's back to normal after 15-20 minutes but some of the calendar events and location history etc from other people's accounts are still visible. It also only happened on her iPhone and not to mine on Android. Last edited by Mosely; 05-17-2020 at 02:35 AM.. |
|
05-17-2020, 01:40 AM | #2 | |
Colonel
2278
Rep 2,808
Posts |
Quote:
__________________
2025 X7 40i, 2024 I7 60i, 2022 M8 Comp GC, 2021 AMG GT53, 2022 X5M Competition, 2021 X7 40i, 2019 M5, 2018 M550I, 2017 Audi Q7, 2014 M6 GC, 2013 Mercedes CLS550, 2011 750LI, 2008 M6 Cabrio, 2008 Porsche Cayenne S, 2004 Mercedes SL55 AMG, 2003 Mercedes SL500, 2000 Mercedes CL500, 1993 Lexus SC400, 1989 525i, 1985 318i
|
|
Appreciate
0
|
05-17-2020, 11:17 AM | #3 |
Major
1394
Rep 1,031
Posts
Drives: Like a bat out of hell.
Join Date: Apr 2019
Location: here and there
|
No issue here.
|
Appreciate
0
|
05-17-2020, 01:03 PM | #4 |
New Member
161
Rep 20
Posts |
Probably just normal database "maintenance"..
Or 5 + 2 = 7... Your choice.. Z |
Appreciate
0
|
05-17-2020, 07:48 PM | #6 | |
Lieutenant
601
Rep 455
Posts |
Quote:
|
|
Appreciate
0
|
05-17-2020, 09:24 PM | #8 |
Lieutenant
601
Rep 455
Posts |
That was the first thing I did, but it didn't impact anything at all. Basically every time I opened and closed the app, it would show a new car and new collection of information. No specific locations patterns (Atlanta, Vegas, Northern California, somewhere in France, and one in Germany)
|
Appreciate
0
|
05-17-2020, 09:34 PM | #9 |
New Member
161
Rep 20
Posts |
Not really. If someone was hacking you, odds are you'd never know it. What's the point of letting you know they have your info. Odds are also much greater they can get all that data somewhere else that's a lot easier to hack.
Not saying it's not possible, there are a lot of "script kiddies" out there running hacking scripts they've downloaded, that have no idea how to run them correctly. This sounds more like a normal maintenance cycle or software update (over the weekend typically) that went awry. Z |
Appreciate
0
|
05-18-2020, 12:19 AM | #10 | |
First Lieutenant
918
Rep 365
Posts |
Quote:
|
|
Appreciate
0
|
Bookmarks |
|
|