logo

MiTM phishing attack can let attackers unlock and steal a Tesla

ID: c4122fbf-d6e3-5d98-82eb-61218f46f0f4

STIX ID: report--c4122fbf-d6e3-5d98-82eb-61218f46f0f4

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-03-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers demonstrated a practical MiTM phishing attack at Tesla locations by spoofing a "Tesla Guest" WiFi SSID to capture account credentials and OTPs; with the stolen account the attacker can add a Phone Key to a nearby car (no card authentication or owner notification required) and unlock/start the vehicle, enabling theft of Tesla Model 3s without needing malware or physical intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.