AI News Feed
Market watch
Cybersecurity

Studies find connected cars and free Android games routinely send personal data to trackers

Two studies released this week found that all 21 tested connected vehicles sent data to third-party domains and that most popular free Android games share personal data with foreign ad-tech companies.

The Verge reported on a study by researchers at Northeastern University and Consumer Reports that examined 21 late-model vehicles from 19 brands sold in the United States and 30 companion mobile apps linked to active vehicles. Every one of the 21 vehicles transmitted data to at least one third-party domain over Wi-Fi, and more than half contacted domains specializing in advertising, tracking or analytics, including Adobe, LexisNexis and Amplitude. Vehicles with advanced infotainment systems, particularly those running Google’s Android Automotive OS with Google Automotive Services, contacted the highest number of third-party domains, according to project lead David Choffnes, former director of Northeastern’s Cybersecurity and Privacy Institute.

To capture the traffic, researchers placed a Raspberry Pi inside each car, connected it to the vehicle’s Wi-Fi and routed internet through a mobile hotspot. For cellular traffic, they built a car-sized Faraday tent that blocked signals between the vehicle and external cell towers, forcing the car to use the controlled Wi-Fi connection. The encrypted payloads could not be decrypted without hacking the vehicles, but the researchers identified destination domains, including third-party tracking companies.

The companion apps also raised concerns. Seven apps — HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick and myGMC — sent sensitive details such as vehicle identification numbers, phone numbers and precise locations directly to advertising networks, The Verge reported. More than 70 percent of the tested companion apps contacted at least five unique advertising, tracking or analytics domains. Researchers said the pairing of a VIN with identifiable personal data could allow data brokers to build detailed dossiers on individual drivers. Choffnes told The Verge, “I think the conclusion is that there’s a lot to be worried about,” and said cars are “essentially turning into the global smartphones.”

The legality of such data harvesting remains disputed. Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without informed consent. Ford and Honda faced minor fines for making it overly difficult for customers to opt out, according to The Verge. Automakers offered mixed reactions to the new findings, with some defending their practices as legally compliant and others acknowledging vulnerabilities and issuing software fixes, according to The Verge.

TechRadar reported that Proton, a secure email and VPN provider, analyzed the top 100 free-to-play Android games on the Google Play Store, which have been downloaded almost 20 billion times worldwide. Proton found that the vast majority send gamers’ personal data abroad, much of it to ad-tech companies headquartered in China, Russia, Israel and Five Eyes nations. The games include Block Blast!, Disney Solitaire and Subway Surfers. Proton said the trackers can harvest device type, usage habits, payment information, age, gender and physical location, although developers obscure exactly what is collected.

Proton examined the top 100 games across multiple regions for May 2026. In the United States, the top 100 games were downloaded almost 20 million times in a single month; games sharing data with Chinese companies accounted for 15.8 million downloads, while 13.7 million downloads involved games sharing data with Russian entities. In the United Kingdom, out of 3.6 million downloads in May, 3 million contained Chinese trackers and 2.7 million contained Russian trackers. Proton also found that 99 percent of total UK downloads included trackers funneling data back to Five Eyes entities, and that games in the UK contained up to 36 different trackers per app.

Location tracking drew particular attention. In the United States, games containing location trackers were downloaded 1.7 million times in May; in the UK, the figure was 300,000. Proton warned that location data “is not just data. It’s a record of your life,” and can reveal where a person works, sleeps, attends a protest, visits a medical clinic or place of worship. The report also cited a November 2025 data breach at Mixpanel, a product analytics platform used by games including Roblox, which allowed hackers to steal user-identifiable metadata.

Proton’s advice to consumers was to block tracking at the source by using a VPN with built-in ad and tracker blocking, or to pay for ad-free games. The company said the free-to-play model depends on sending personal data to data-broker networks, adding, “If you don’t pay for a product, you are the product.”