Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Study Finds 19 of 21 Car Brands Shared Driver Data With Advertisers and Tech Giants

Your car is a data broker's best friend
Researchers at Northeastern University, working with the nonprofit Consumer Reports, tested 21 vehicles from 19 different automakers and their 30 companion mobile apps. The question: what are these cars actually sending back to the manufacturer, and where does it go from there?
The answer, released Tuesday, isn't pretty. Northeastern cybersecurity professor David Choffnes and his team found that 19 of the 21 vehicles contacted at least one third party over Wi-Fi. Thirteen reached Google-owned domains. Eleven hit at least one domain tied to advertising, tracking, or analytics.
The apps were worse. Twenty-eight of 30 connected-car apps shared data with at least one third-party advertising or analytics firm, according to Consumer Reports. Seven of those 30 sent personally identifiable information, names, email addresses, or precise GPS coordinates to outside companies.
Four General Motors apps, myCadillac, myChevrolet, myBuick, and myGMC, along with apps from Honda, Nissan, and Lincoln, packaged Vehicle Identification Numbers together with either location data or email addresses. That combination is exactly what lets a data broker tie a specific car to a specific person's daily movements, Choffnes told Northeastern Global News.
Who's on the receiving end
The list of recipients includes Adobe Analytics and ContentSquare, plus the data broker Axciom. It also includes Alphabet's Google, Amazon, Microsoft, Meta, Reddit, and Pinterest, according to Consumer Reports. Many of these companies play a double role: they provide software tools to automakers while also running the ad-auction platforms that marketers use to target buyers.
Tesla's Model 3 was the worst performer in the raw numbers, contacting 34 unique advertising, tracking, and analytics domains, according to Ars Technica's review of the research. The Cybertruck contacted 23. By contrast, the Buick Envista and Mercedes-Benz EQS didn't reach any third-party advertising domains over Wi-Fi at all, according to Help Net Security's summary of the findings.
The researchers couldn't actually read the encrypted data coming out of the cars themselves, because every vehicle tested rejected the modified certificates they used to try to intercept traffic. That's a point in the automakers' favor on basic security hygiene. But the apps were a different story. Since researchers owned the test phones, they could decrypt what the apps were sending, and that's where the personal data showed up.
The methodology, and its limits
The team built a Wi-Fi access point on a Raspberry Pi and logged traffic while cars sat idle, while testers used doors and infotainment controls, and while vehicles were driven on private roads at a Consumer Reports test facility. They also parked 11 electric vehicles inside a Faraday tent to cut cellular signal and see if traffic shifted to Wi-Fi. For seven of those 11 EVs, it did. The Tesla Model 3 contacted 27 additional tracking domains once cellular was blocked; the Cybertruck added 14 more.
The authors were upfront that their numbers represent a floor, not a ceiling, since they couldn't see traffic sent over cars' own cellular connections for most vehicles, nor what happens once data lands on a third party's servers.
The automaker side of it
Automakers can fairly point out that every one of them disclosed, somewhere in an app privacy policy, that they may share data with third parties. That's technically true. The problem the researchers identified isn't that disclosure didn't exist, it's that it didn't say which companies get the data or why, leaving owners unable to make an informed choice.
Only Honda responded to Consumer Reports' request for comment among the automakers named in the findings. A Honda spokesperson said the company operates "from a customer-focused mindset" and, after being notified of the results, directed its data analytics vendor to wipe all collected location data and stop sharing it going forward.
GM already got hit, and a bill is sitting in the Senate
This isn't theoretical. The Federal Trade Commission settled with GM in January 2025 over its OnStar Smart Driver program, barring the company from sharing precise geolocation and driver behavior data with consumer reporting agencies for five years. That's a federal regulator acting on the exact kind of data-sharing this new study flags.
At the federal level, Oregon Senator Jeff Merkley has reintroduced his Car Privacy Rights Act, which would require automakers to get explicit consumer consent before selling or sharing driver data and give owners the right to see which third parties received their information. The bill is cosponsored by Senators Ben Ray Luján and Elizabeth Warren, both Democrats, and is endorsed by the ACLU. No Republican has signed on as a cosponsor, which means it faces the same fate as Merkley's earlier attempt at this: going nowhere in a divided Senate.
The FTC warned automakers about this exact problem back in 2024. Two years later, the data is still flowing, and enforcement so far has come case by case rather than through comprehensive federal rules.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.