Last week I kept the wheels section light on purpose and promised a proper dive into the dark side of car technology. This is that piece. I want to walk through four things that are happening right now, not hypothetically, not "coming eventually": the license plate readers that are getting innocent people pulled over at gunpoint, the cameras that will legally have to watch your face starting with the 2027 model year, the quiet pipeline that's already been selling your driving habits to your insurance company for years, and the fact that your car is a computer researchers are actively breaking into for sport and profit. None of this is a conspiracy theory. It's all public record, court filings, federal consent orders, and hacking competition results. That's what makes it worth forty-five minutes of your Sunday.

Part One: The Cameras on the Street Are Wrong a Lot More Than You'd Think

Start with Flock Safety, the company behind the automated license plate reader (ALPR) cameras that now sit on more than 120,000 poles, streetlights, and gates across 49 states, run by over 12,000 police departments, HOAs, and private customers [1]. The pitch is simple: cameras scan every plate that passes, check it against a hotlist of stolen vehicles and felony suspects, and ping an officer the instant there's a match. Roughly 20 billion plates get scanned this way every month [2].

The problem is the hit rate. An internal review by the Roseville, California police department found that of 1,427 hotlist alerts Flock sent officers over a two-year span, 71% were wrong [3]. Not "eventually cleared up," wrong — the car wasn't stolen, wasn't linked to a felony, wasn't the vehicle on the list at all. The Institute for Justice has tracked at least 29 documented cases nationwide since 2018 where a Flock misread led to a stop, the majority of them since 2023 as the camera network scaled up [4]. Some of what's in that record is hard to read past once: a camera misreading a "7" as a "2" led to a driver being detained at gunpoint with a police dog deployed against him [4]. A misread digit on an innocent couple's plate got them pulled from their car at gunpoint while their six-week-old baby was still alone in the back seat [5]. An auto journalist driving a press loaner Range Rover got pulled over in Nebraska after a nearly identical Range Rover was flagged in a different state entirely, and the officers never checked the actual photo Flock had captured before moving in [5].

Flock's own defense, when pressed, has mostly been that the underlying stolen-vehicle databases are stale, not that the optical character recognition is broken [2]. That's a real distinction, but it doesn't change what happens to the driver at the traffic stop. And the mission has already crept well past "find stolen cars." In one documented case, Georgia State Patrol cited a motorcyclist for holding a phone using a Flock camera capture as the evidence, a use case nobody sold to the public when these systems went in [6]. In Milwaukee, an officer allegedly used Flock's tracking capability to stalk a former romantic partner [7]. The ACLU filed an amicus brief in April arguing that the sheer scale of what ALPR networks can reconstruct about a person's movements amounts to a warrantless search under the Fourth Amendment [7]. Los Angeles let its three-year Flock contract lapse this July after its own inspector general found roughly one in three hotlist alerts reviewed were inaccurate [2]. Other cities are moving the opposite direction: my own back yard in New Jersey has townships approving new Flock contracts this summer without much public debate at all.

The honest version of this story isn't "ALPR is useless." Departments do recover stolen cars this way. The honest version is that a system built to generate probable cause is only as good as the humans trained to double-check it before they draw a weapon, and right now that verification step is optional in a lot of departments, not required.

Part Two: In 2027, the Camera Moves Inside

Here's the part that should actually concern you more, because it isn't aimed at your license plate. It's aimed at your face.

Buried in Section 24220 of the 2021 Infrastructure Investment and Jobs Act is a mandate requiring NHTSA to finalize rules forcing "advanced drunk and impaired driving prevention technology" into all new passenger vehicles [8]. The technology being developed to satisfy that mandate is infrared cabin cameras that continuously track eye movement, gaze direction, pupil dilation, and facial micro-expressions, in some proposals paired with ambient cabin sensors that passively test the air for alcohol without you doing anything at all [9]. This isn't science fiction pitched by a startup. Mobileye announced in March that a major US automaker has already committed to production integration of its Driver Monitoring System, targeting start of production in 2027 and spanning millions of vehicles across multiple models [10].

Worth being precise about where this actually stands: NHTSA itself has publicly said no technology yet reliably distinguishes impaired driving from ordinary distraction or fatigue, and the rule has already slipped past its original target [11]. So the honest 2026 answer is "delayed but real, not vaporware, not imminent for every car on a lot next year." What's not delayed is the hardware getting designed into 2027-model-year vehicle architecture right now, which means the sensor and the wiring will exist in your next new car whether or not the software behind it is fully switched on at delivery. Automakers are absorbing $100 to $500 per vehicle in added cost to install it [9], a cost that will find its way to a window sticker near you.

The part that should actually keep you up: nothing in the current federal mandate requires this biometric data to stay in the car. The law doesn't mandate external data sharing, but it also doesn't prohibit it, and once a system exists that's continuously mapping your face and behavior, the question of who else gets to see that feed is a business decision, not a technical one [9]. Given what I'm about to walk you through in Part Three, I don't think that's a hypothetical worth dismissing.

Part Three: Your Car Has Already Been Selling You Out

This part isn't coming in 2027. This is a business model that's been running for years, and it just got its first serious enforcement teeth.

In January, the FTC finalized a consent order against General Motors and its OnStar subsidiary. The agency's findings: GM collected detailed driving behavior data from more than 14 million vehicles, recording precise geolocation as often as every three seconds, along with hard braking, hard acceleration, speeds over 80 mph, late-night driving patterns, and seatbelt use, then sold that data to the consumer-reporting brokers Verisk Analytics and LexisNexis Risk Solutions [12]. Those brokers packaged it into driver risk scores and resold it to insurance companies, which used it to adjust individual premiums, often without the driver ever knowingly opting in [12]. GM made roughly $20 million nationwide doing this between 2020 and 2024 [13]. In May, California's Attorney General followed with a separate $12.75 million civil penalty against GM, the largest privacy penalty the state has ever assessed under its consumer privacy law, and California has since fined Honda $632,500 and Ford $375,703 for related practices [14]. Texas has now filed the first state action of its kind against Allstate and its telematics subsidiary Arity [14].

The consent buried in the paperwork is the part that should bother you most as a consumer, not as a privacy advocate. Automakers typically secure the right to collect and share this data through clauses tucked into purchase agreements and connected-app terms of service, the kind of document nobody reads at the finance desk while they're focused on the loan rate [15]. A New York Times investigation found one driver whose LexisNexis file ran 130 pages deep, cataloging trips he never knowingly agreed to share [16]. Only three states — Maryland, Oregon, and Virginia — currently ban the outright sale of this kind of geolocation and behavior data [13]. Everywhere else, it's a patchwork of disclosure requirements and hope.

If there's a silver lining, it's that you have more leverage here than with the other two stories in this piece. You can request your own file directly: LexisNexis and Verisk are both required under the Fair Credit Reporting Act to provide a free consumer disclosure report on request, the same right you have with a credit bureau [13]. It's worth doing once a year, the same way you'd check a credit report, just to see what your car has actually been saying about you behind your back.

Part Four: The Car Is a Computer, and Computers Get Hacked

The first three parts of this piece are about your car being used against you by design, by companies and agencies with a legitimate (if poorly executed) business or public-safety reason for collecting the data. This last part is different. This is about people getting into your car who were never supposed to be there at all.

The clearest recent proof point is Pwn2Own Automotive 2026, an annual hacking competition held in Tokyo every January where security researchers are invited to break into real production vehicles and infrastructure for cash prizes. This year's event saw 76 separate vulnerabilities demonstrated across multiple manufacturers, with researchers earning more than $1 million in payouts for zero-day exploits, security flaws nobody had ever reported before [17]. Tesla accounted for 37 of those vulnerabilities on its own, including one exploit that achieved full root access to the vehicle's systems through nothing more than a USB port [17]. In a separate demonstration at the same event, a researcher took over an EV charger, an Autel MaxiCharger, using only an NFC card tap, the same kind of contactless motion you'd use to pay for coffee [18]. No cable, no laptop, no physical breach of the vehicle at all, just a charging station that trusted the wrong signal.

This isn't confined to a hacking convention stage. Northeastern University researchers found vulnerabilities in the cellular modems of Tesla's Model 3 and Cybertruck that let attackers intercept the vehicle's wireless connectivity stack, track its location, and abuse its SMS and emergency-services messaging to send spoofed alerts or flood the system with junk traffic [19]. The researchers were careful to note this isn't full remote takeover of the driving controls, but it's a real foothold into a car's communication with the outside world, and the vulnerability traces back to shared modem components used across the industry, not something unique to one brand [19]. And it isn't only the newest, most connected cars at risk. UC San Diego researchers found that at least 2.2 million vehicles, most of them sold by Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California since 2017, came with aftermarket Bluetooth anti-theft devices carrying a vulnerability that let attackers unlock doors and immobilize the engine remotely from up to five yards away. The manufacturer didn't ship a fix until this past July, more than a year after researchers first flagged the flaw [20].

None of this is actually new, which is worth saying plainly. Automotive cybersecurity as a field traces back to 2015, when researchers famously took remote control of a Jeep Cherokee on a live highway through a vulnerability in its Uconnect infotainment system, an event serious enough that it led directly to a 1.4-million-vehicle recall and the creation of dedicated automotive bug-bounty programs and hacking-focused research communities like the Car Hacking Village that still run today. What's changed in the decade since isn't that the threat is new, it's that the attack surface has grown enormous. A modern car carries cellular and WiFi modems, GPS, Bluetooth, USB ports, and increasingly a payment-capable charging port, each one a door a researcher, or someone with worse intentions, can knock on.

This is also the section where last week's theft-ring story and this week's piece actually meet. The OBD2 reprogramming attack we covered last week, plugging a device into a car's diagnostic port to trick it into accepting a blank key fob, is low-tech, physical-access hacking. Everything in this section is the same underlying idea executed remotely, over Bluetooth, cellular, or NFC instead of a cable in your footwell. Different entry point, same result: someone who was never supposed to have access to your car, does.

Where This Leaves You

Put the four pieces next to each other and the pattern is uncomfortable: a plate-reading network with a real error problem making real-world stops, a face-reading mandate arriving in showrooms in roughly a year with the data-sharing question still wide open, a driving-behavior pipeline that's already been quietly running for the better part of a decade before anyone outside a regulator's office noticed, and a genuine, actively-researched hacking problem that grows every time an automaker adds one more wireless feature to the spec sheet. None of these four systems talk to each other yet, as far as any public reporting shows. But they don't need to. Each one on its own is already reshaping what "privacy" and "security" mean the moment you get behind the wheel, and all four are moving in the same direction: more sensors, more connectivity, more inference, less say for the person actually driving.

I'm not going to tell you to stop buying connected cars, because at this point that's close to not buying a car. What I'd actually suggest: pull your LexisNexis and Verisk files this year if you haven't. Read the data-sharing section of your next purchase agreement instead of skipping to the loan terms. Keep your infotainment and telematics software up to date the same way you'd patch a laptop, since most of the vulnerabilities above eventually got fixed, just slowly. And if a plate reader ever flags your car by mistake, know that the documented pattern isn't rare enough to assume it won't happen to you — ask to see the actual photo match before anything else happens.

Poured. Worn. Driven.
Wristmas & The W’s

-Mark, Chief Enthusiast

References

[1] "Flock Cameras Got the Wrong License Plate 71% of the Time in California City," Gizmodo, July 31, 2026.

[2] "Flock plate reader misreads keep flagging innocent drivers," AI Weekly, August 2026. 

[3] "Flock's AI License Plate Readers Are Wrong Most Of The Time, And That's Somehow Not The Craziest Part," Yahoo News, August 2026. 

[4] "Dozens of Innocent Motorists Have Been Pulled Over, Detained at Gunpoint, or Jailed Due to AI License Plate Camera Errors," Institute for Justice, July 2026. 

[5] "Case-by-Case: Every Reported Flock License Plate Camera Error to Date," The Auto Wire, July 18, 2026. 

[6] "Traffic Violation! License Plate Reader Mission Creep Is Already Here," Electronic Frontier Foundation, March 26, 2026. 

[7] "Get The Flock Out," ACLU, 2026. 

[8] "Mandatory Cameras in New Cars by 2027: What the Law Actually Says," WC Shipping Blog, May 1, 2026. 

[9] "Federal Surveillance Tech Becomes Mandatory in New Cars by 2027," Gadget Review, March 9, 2026. 

[10] "Mobileye Secures Major DMS Production Program with Leading U.S. Automaker," Business Wire, March 23, 2026. 

[11] "Government Requires Driving Monitoring By 2027," Motor1, April 28, 2026. 

[12] "Prevent This: Your Car Selling Your Driving Data," Intruvent, May 19, 2026. 

[13] "Prevent This: Your Car Selling Your Driving Data," Intruvent, May 19, 2026 (state bans, FCRA rights). 

[14] "Connected Car Data: Your Vehicle Is Reporting You to Insurers and Police," State of Surveillance, June 2026. 

[15] "Your Car is Selling Your Driving Data to Your Insurance Company Right Now," Auto Roamer, February 22, 2026. 

[16] "High Car Insurance? Your Car Maker May Be Selling Your Driving Data," Insurify via Key Biscayne Portal, May 2026 (citing New York Times investigation). 

[17] "Car Hacking Threats Surge as Security Gaps Expose Millions," FindTheBestCarPrice, February 20, 2026 (Pwn2Own Automotive 2026 results). 

[18] "Swipe, Plug-in, Pwned: Researchers Find New Ways to Hack Vehicles," Dark Reading, January 23, 2026. 

[19] "Connected cars can be hacked, research finds," Northeastern Global News, February 28, 2026. 

[20] "2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft," UC San Diego News, July 2026.

Reply

Avatar

or to participate