ροδος ιστοσελιδες κατασκευη

CAR RENTAL NEWS

Get the latest car rental news and analysis on industry around the world.

  • HOME
  • INDUSTRY NEWS
  • BUSINESS IDEAS
  • HOTELS
  • BOAT TRIPS
  • WEB DEVELOPMENT
  • TOURISM – TRAVEL
You are here: Home / INDUSTRY NEWS / My Tesla Model Y Was Remotely Unlocked By Thieves Who Compromised My Tessie API Token, Then They Arrived Three Minutes Later To Ransack The Vehicle
rhodes rental cars
.

My Tesla Model Y Was Remotely Unlocked By Thieves Who Compromised My Tessie API Token, Then They Arrived Three Minutes Later To Ransack The Vehicle

08/09/2025

Follow us today…

 

 

 

Tinkering with your car has always been part of the American automotive experience. Back in the day, it meant fitting headers or rejetting a carburetor. Then came the era of piggyback ECUs and turbo timers. 
But now, in the all-electric world of smart mobility, tweaking your ride means giving it digital appendages, API hooks, smart home integration, and app-based automation. 
As one Tesla Model Y owner recently discovered, however, the pursuit of digital convenience can come with very real risks, especially when your car decides to unlock itself in the middle of the night and thieves show up three minutes later to rummage through your belongings.
“Update 4: Still working to figure out how they accessed the API Token from Tessie. I thought it was younger folks messing around and stumbled onto it. They were smart enough to get into the car but dumb enough to miss that I could track a pair of Earbuds they stole; they live less than a mile from me. Back to the breach: Haven’t found any evidence of network intrusion in the router logs, but still looking at it between other tasks. Starting to suspect a third-party app on my Garmin Smartwatch that I forgot I gave API Access to (Definitely on me for using it and forgetting to remove it).
Update 3: The folks at Tessie have been incredibly responsive. They were able to trace the unlock command internally. They tracked the access to their API token, which I was using for Home Assistant. The weird part is they said the call didn’t from from their integration, which is the only place I use it. Still investigating and confirming, but it seems like my token may have been compromised.
Unfortunately, the API token is much less secure than the App, which explains how it could have been used remotely, bypassing MFA. That said, I’m still really not sure how they managed to get a hold of it!
Will keep updating as I find out more.
Update 2: Found that they gained access to the car via Tessie! Not sure how they gained access to that account…honestly, pretty impressive for Chicago street crime!
Last night, my car was broken into. Somehow, thieves managed to remotely unlock the car, and I am trying to figure out how they did it so I can better protect myself.
I have a Ring camera, and it shows the car being locked for several hours…The car then unlocks, and about 3 minutes later, two guys show up and ransack the car. The car was definitely locked; you can clearly see it being remotely unlocked, and I know I did not unlock it.
Has anyone heard of this or had it happen to them?
Update: After a couple of calls with Tesla, it looks like I will have to create a service ticket and go in for them to pull the logs, just glad they should have the info!”

That quote, posted by Reddit user TheRuinedOne on r/TeslaModelY, reads like a passage from a cyberpunk novel. Only this wasn’t fiction. The break-in was silent, surgical, and digital. No shattered glass. No broken locks. Just a ghostly unlock signal sent from somewhere, followed by a pair of young men casually entering the vehicle and helping themselves. The whole thing was captured on a Ring camera, and the evidence was as chilling as it was clear. A Tesla that had been locked all night suddenly popped open without the owner touching a thing.
Tesla Model Y Performance Options

  • The Model Y offers a range of performance options, from the brisk acceleration of the rear-wheel-drive model (0-60 mph in 5.4 seconds) to the powerful dual-motor all-wheel-drive version (0-60 mph in 3.9 seconds).
  • With an EPA-estimated range of up to 357 miles and the ability to add up to 182 miles of range in just 15 minutes at a Supercharger, the Model Y is well-suited for both daily commutes and long-distance travel.
  • The minimalist interior is dominated by a large touchscreen that controls most of the vehicle’s functions. The spacious cabin, panoramic glass roof, and optional third-row seating make it a practical choice for families.
  • The Model Y delivers a smooth and quiet ride with a low center of gravity that contributes to stable handling. However, some drivers may find the ride to be on the firmer side.

Digging into the digital forensics, the owner found that the breach came not through Tesla’s app or servers, but via a third-party companion app called Tessie, a popular tool among Tesla enthusiasts for adding smart features and deeper insights. 

Advertising

The API token used by Tessie had somehow been compromised. As the owner wrote in an update, “Mystery solved! It was hacked third-party access, it was unlocked via Tessie!” Tessie’s development team responded quickly and confirmed the unlock command had passed through their system, but not from the user’s known integrations. This wasn’t a hack of Tesla itself; it was a compromise of the connective tissue Tesla owners often add to their vehicles themselves.
What makes this case unique is its combination of technical subtlety and real-world impact. The unlocked car wasn’t driven off. Instead, it was ransacked for valuables, including a pair of earbuds that, ironically, led the owner straight to the culprits’ front door thanks to tracking features. 
Tesla Model Y Hacked
As he explained, “Thinking it was younger folks messing around and stumbled onto it. They were smart enough to get into the car but dumb enough to miss that I could track a pair of Earbuds they stole, they live less than a mile from me.” That detail is almost too poetic. In a world of digital vulnerabilities, it was an analog theft that unraveled the scheme.

The weak link turned out to be an API token, a string of code that grants remote access, which the owner had generated months earlier for Home Assistant integration. More importantly, it wasn’t protected by multi-factor authentication like the official Tesla app. In one of his updates, the owner admitted to overlooking an old Garmin smartwatch app he had once connected to his Tesla through Tessie: “Definitely on me for using it and forgetting to remove it.” In many ways, that single lapse, an unused app with lingering access, was the modern equivalent of forgetting you gave your neighbor a spare key.
Tesla Model Y Safety Features

  • Tesla has a strong focus on safety, and the Model Y comes standard with a suite of active safety features, including automated emergency braking and lane-keeping assist.
  • While owners generally praise the Model Y’s performance and technology, some have reported issues with build quality and customer service.
  • The Model Y has a thriving aftermarket scene, with many owners personalizing their vehicles with everything from custom lighting to performance upgrades.
  • The Model Y, like other Tesla vehicles, has a polarizing effect, with some seeing it as a symbol of innovation and others as a controversial status symbol.

Community members like pomokey chimed in with thoughtful, surgical troubleshooting: Was it a used car? Were other phone keys active? Could the login credentials have been guessed? The answer to all was no. TheRuinedOne was the original owner, had no other phones paired, and used a complex password, though he admitted it lacked 2FA. The conclusion was clear. This wasn’t sloppy ownership. It was a quiet reminder that when you start adding third-party access points, you expand the attack surface in ways even a seasoned technophile can forget.
Security researchers have long warned about this. A 2023 paper from the NDSS Symposium emphasized that unofficial access points and third-party apps can become major liabilities. While Tesla’s built-in systems remain secure and well-supported, the API tokens used by apps like Tessie and S3xy Commander aren’t nearly as protected. According to research by IOActive, even keyless entry systems can be bypassed with enough knowledge, and in this case, knowledge wasn’t even necessary. Just an opportunity.
To his credit, TheRuinedOne handled the situation with remarkable clarity. He updated the community regularly, coordinated with Tessie, and combed through router logs to rule out a network-level intrusion. The community, in turn, responded not with mockery but with concern and curiosity. There was no scapegoating, no finger-pointing. Just a collective realization that as our cars become smarter, the ways they can be misused evolve just as quickly. It was, in its own way, a modern rendition of the old muscle car warning: “Fast, loud, and loose gets you into trouble”, only now the warning is digital, silent, and potentially invisible.
This isn’t a call to uninstall every third-party app or go full analog, far from it. Apps like Tessie provide real value to owners and continue to support a robust ecosystem of Tesla enthusiasts. But as with any performance mod or aftermarket tweak, due diligence is essential. Know what you’ve installed. Know what access you’ve granted. And above all, remember that in this new world of over-the-air everything, your car isn’t just a machine, it’s a node on your personal network. And like any device, it’s only as secure as you make it.
Image Sources: Tesla Media Center

Noah Washington is an automotive journalist based in Atlanta, Georgia. He enjoys covering the latest news in the automotive industry and conducting reviews on the latest cars. He has been in the automotive industry since 15 years old and has been featured in prominent automotive news sites. You can reach him on X and LinkedIn for tips and to follow his automotive coverage.

Follow us today…

 

 

 

Source: torquenews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-16

I Bought a 2016 Toyota Highlander with 129K, and the Prior Owner Must Have Been a Toyota Dealer’s Nightmare, Or Maybe I’m Dreaming?

Follow us today...       Is this the perfect used car, or just a dream?  Robert found a 2016 Toyota Highlander with a flawless 129k-mile service history. Now he's ready to make some upgrades. What would you do?  Robert Doren II on the Toyota Highlander Owners Club Facebook page says,  "I just bought … [Read More...]

Tesla Cybertruck Owner Says, “It’s a Futuristic Chrome-Plated Dumpster Designed On an Apple II By a Stoned Elon Musk, But Requires Less Maintenance Than a Goldfish”

Follow us today...       A Tesla Cybertruck owner knows it's a "futuristic chrome-plated dumpster," but he doesn't care.  He says it goes from 0 to 60 in 2.5 seconds and has "less maintenance than a goldfish." Find out why this rolling trapezoidal toaster is an unbeatable daily driver. Do you think this … [Read More...]

2020 Honda CR-V Owner Says, “The Dealer Is Threatening Me With a $175 Inspection Fee For An AC Leak That Is Caused By a Recall Issue”

Follow us today...       Should a Honda dealer charge a CR-V owner to diagnose a problem that a recall might cover? Here's a story that affects all Honda owners.  This report is based on a post from Kent Hankesh on the Honda CR-V Community Facebook page:  He says, "I have a 2020 Honda CR-V EX. Can a … [Read More...]

car rental news

Old Dominion Connects Country Music and Cars

Talking music and cars with Grammy-nominated Old Dominion. Source: caranddriver.com … [Read More...]

car rental news

Tested: 2002 Maserati Spyder Cambiocorsa, the Brand's Comeback Car

From the archive: An Italian feast for the automotive senses. Source: caranddriver.com … [Read More...]

car rental news

View Photos of the 2002 Maserati Spyder Cambiocorsa

See the interior and exterior of the 2002 Maserati Spyder Cambiocorsa from every angle. Source: caranddriver.com … [Read More...]

car rental news

1981 Toyota 4×4 Pickup on Bring a Trailer Sports Awesome '80s Graphics

Transmission: manual. Windows: manual. Front locking hubs: manual. This truck is Clint Eastwood, the Toyota. Source: caranddriver.com … [Read More...]

Tesla Buyer Says, “I Was Supposed To Take Delivery of This Model 3 and the Dealer Said It Got Sent Back, I Think They Lied To Me and Sold It To Someone Else"

Follow us today...       When Vanessa went to buy her dream Tesla, the dealership swapped her clean car for an accident-damaged one—is this a hidden disaster or a deal worth the risk? Vanessa Von Graff on the Tesla Model 3 and Model Y Owners Club Facebook page says, "I'm supposed to pay for this car tomorrow. After … [Read More...]

car rental news

This Ex-IndyCar Driver Wants to Completely Rethink Motorsports

J.R. Hildebrand has envisioned a more dynamic, more exciting way to go racing by going back to the basics and ditching downforce. Source: caranddriver.com … [Read More...]

Maserati MCPura launched in India at ?4.12 cr: Italian V6 pushes over 630 bhp

Share via: The Maserati MCPura has been launched in India at ₹4.12 crore (ex-showroom). Offered in coupe and Cielo convertible variants, the supercar gets the 3.0-litre twin-turbo V6 engine with 630 bhp. ...Read More <div class="imgWrapper" data-item-event="image_clicked" data-ga-widget="Image Interactions" … [Read More...]

Tags

Source-1 Source-2 Source-10 Source-11 Source-12 Source-13 Source-14 Source-16 Source-17

Car Rental

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Rent a car

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Car News

HOTELS – CRUISES – TRAVEL – TECH

Recent Posts

  • I Bought a 2016 Toyota Highlander with 129K, and the Prior Owner Must Have Been a Toyota Dealer’s Nightmare, Or Maybe I’m Dreaming?
  • Tesla Cybertruck Owner Says, “It’s a Futuristic Chrome-Plated Dumpster Designed On an Apple II By a Stoned Elon Musk, But Requires Less Maintenance Than a Goldfish”
  • 2020 Honda CR-V Owner Says, “The Dealer Is Threatening Me With a $175 Inspection Fee For An AC Leak That Is Caused By a Recall Issue”
  • Old Dominion Connects Country Music and Cars
  • Tested: 2002 Maserati Spyder Cambiocorsa, the Brand's Comeback Car

Rental News

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
CAR RENTAL NEWS @ COPYRIGHTS 2023