MiTM phishing attack can let attackers unlock and steal a Tesla
ID: c4122fbf-d6e3-5d98-82eb-61218f46f0f4
STIX ID: report--c4122fbf-d6e3-5d98-82eb-61218f46f0f4
Feed Name: Bleeping Computer
Threat Score
Researchers demonstrated a practical MiTM phishing attack at Tesla locations by spoofing a "Tesla Guest" WiFi SSID to capture account credentials and OTPs; with the stolen account the attacker can add a Phone Key to a nearby car (no card authentication or owner notification required) and unlock/start the vehicle, enabling theft of Tesla Model 3s without needing malware or physical intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
