Flipper Zero WiFi phishing attack can unlock and steal Tesla cars
ID: 28317833-e9fa-59c6-b0b2-c46dd9e91c0b
STIX ID: report--28317833-e9fa-59c6-b0b2-c46dd9e91c0b
Feed Name: Bleeping Computer
Threat Score
Researchers demonstrated a MiTM phishing attack using a spoofed 'Tesla Guest' WiFi (performed with a Flipper Zero but reproducible with other devices) to steal Tesla account credentials and OTPs; once authenticated the attacker can add a new Phone Key without requiring the vehicle owner's physical key card, allowing them to unlock and start the car while in close proximity. Tesla reviewed the report and considered the behavior intended; no mitigation was described in the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
