• News/
  • https://www.bleepingcomputer.com/news/security/flipper-zero-wifi-phishing-attack-can-steal-tesla-accounts-cars/

Flipper Zero WiFi phishing attack can steal Tesla accounts, cars

BleepingComputer
·
Bill Toulas
·
Published Mar 7, 2024
·
Updated

An easy phishing attack using a Flipper Zero device can lead to compromising Tesla accounts, unlocking cars, and starting them. The attack works on the latest Tesla app, version 4.30.6, and Tesla software version 11.1 2024.2.7. Security researchers Talal Haj Bakry and Tommy Mysk reported their finding to Tesla saying that linking a car to a new phone lacks proper authentication security. The car maker determined the report to be out of scope. An attacker at a Tesla supercharger station could deploy a WiFi network called"Tesla Guest," an SSID that is commonly found at Tesla service centers and car owners are familiar with it. Mysk used a Flipper Zero to broadcast the WiFi network but notes that the same can be accomplished using a Raspberry Pi or other devices that come with WiFi hotspot capabilities. Once the victim connects to the spoofed network, they are served a fake Tesla login page asking to log in using their Tesla account credentials. Whatever the victim enters on the phishing page, the attacker can see on the Flipper Zero in real time. After entering the Tesla account credentials, the phishing page requests the one-time password for the account, to help the attacker bypass the two-factor authentication protection. The attacker has to move before the OTP expires and log into the Tesla app using the stolen credentials. Once in the account, the threat actor can track the vehicle's location in real time. Access to the victim's Tesla account allows the attacker to add a ...

Read full article

Affected Software

2 affected components
Tesla Tesla App=4.30.6
Tesla Tesla software=11.1 2024.2.7
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a WiFi phishing attack using a Flipper Zero device that can compromise Tesla accounts and vehicles.

2

What security implications are discussed in the article?

The article highlights how attackers can unlock and start Tesla cars by exploiting vulnerabilities in the latest Tesla app and software.

3

What products or software are affected by this phishing attack?

The affected products include the Tesla app version 4.30.6 and Tesla software version 11.1 2024.2.7.

4

How does the Flipper Zero device execute the phishing attack?

The Flipper Zero device facilitates a simple phishing method that targets Tesla users to gain unauthorized access.

5

Who is at risk from this WiFi phishing attack?

Tesla owners using the vulnerable app and software versions are at risk of having their accounts and vehicles compromised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203