Researchers drove a NIO ES8 electric SUV deep into a Norwegian underground mine specifically to sever its external connections. The car kept attempting to reach servers, most of them located in China. These findings echo broader concerns about hidden data collection, similar to how a surveillance app was built to covertly target users without their knowledge.

That finding sits at the center of Project Lion Cage, a multi-year study initiated in 2022 by Tor Indstøy, a risk management and threat intelligence executive at Telenor Group. Indstøy purchased the NIO ES8 as a dedicated research platform.

The project arrives as Chinese EV brands expand across European markets with assurances about local data processing. Observed network behavior appears to contradict those assurances.

    • ChicoSuave@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      1 day ago

      The more we learn about this story the more interesting it becomes, as the Newag trains in question began failing after service as far back as 2021. In desperation after services were affected by the number of non-functional units, an employee searched online for Polish hackers and found a group called Dragon Sector. The group was able to find the issue, and are now being threatened with legal action by the manufacturer, who are citing possible safety issues.

      A lot of ground was covered with so little info. How did they the employee contact hackers? Are they white hat or did they scour The Dark Web for Polish tech support? What was the issue that unbricked a train?

      • kreskin@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        did they scour The Dark Web for Polish tech support?

        yep, security departments of major corporations scour the dark web constantly looking for credentials that are stolen or other company assets for sale, or rumors about the company. Its a key part of finding out if you’ve been hacked. Hackers sell or brag about what they take. So finding hackers if you are already doing that activity is not too huge a project.