Security researchers Charlie Miller and Chris Valasek showed that they could take control of a Jeep Cherokee remotely over the internet. Wired published the demonstration on 21 July 2015, and within days Fiat Chrysler recalled around 1.4 million vehicles in the US.
What happened
- The researchers got in through the vehicle’s internet-connected Uconnect entertainment system and from there sent commands to the dashboard, engine, steering, brakes, and transmission.
- In a highway demonstration they interfered with the wipers, radio, and engine while a journalist was driving. In separate testing they disabled the brakes.
- Fiat Chrysler released a software update. US Senator Ed Markey proposed legislation on vehicle cyber security the same day the story was published.
- On 24 July 2015 Fiat Chrysler announced a recall of around 1.4 million US vehicles across Jeep, Dodge, Ram, and Chrysler models from the 2013 to 2015 model years.
Why it mattered
It was widely reported as the first vehicle recall driven by a cyber security vulnerability. It showed that a connected product can be a physical safety risk as well as a data risk.
Lessons for organisations
Manufacturers of connected products should separate internet-facing components from safety-critical systems and plan how they will deliver security updates. Buyers should ask suppliers how products are tested and patched.
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.