NewsE-scooters are easy to monitor and manipulate

E-scooters are easy to monitor and manipulate

The apps of the rental companies are very informative. With the transferred data, an e-scooter can even be switched off while driving.

Manufacturers of electric scooters don’t take IT security too seriously. This was shown in a lecture at the BSI’s IT security congress on Wednesday. By accessing the company’s APIs, movement profiles can be created or even keys can be read out, which can be used to switch off passing e-scooters.

Bugged app communication

Jan-Niclas Hilgert, research assistant at Fraunhofer FKIE, demonstrated that the APIs of some providers can be read out without major problems. To get access to the data from the provider Lime, the researchers used a jailbroken iPhone. This enabled them to constantly read the information that the app received. By reading out or generating a new user token, the iPhone was no longer necessary, so that the forensic experts could call up data directly via the API. These data turned out to be amazingly detailed. This made it possible to read user data which, with PayPal, also contained the user’s email address as a payment method.

There was plenty of information about the e-scooters: The apps of all rental companies contain an overview of where vehicles are available for rent nearby. After the IT forensic scientists had analyzed this data once, they found out that, for example, the servers of the Tier provider sent significantly more information than was displayed in the app. In addition to the location and license number, status information such as the battery charge level and the internal number of the electric scooter was also available.

All information about all e-scooters

Further experiments quickly showed: The Tier API not only lists scooters in the area, it also allows direct queries about specific vehicles. The IT researchers automatically queried all the data on all e-scooters and thus got an overview of the entire fleet. While the Tier servers reported almost 24,000 active loan devices in February 2020, there were over 56,000 in December. The API also provided information about stolen, damaged or taken out of service e-scooters without any problem.

Since the position data of the scooters is continuously transmitted, it can in principle also be used to track individual users. All that was necessary was the license plate of the electric scooter. With a duration query over several hours, the researchers were even able to generate a movement overview of all scooters.

Switch off via Bluetooth

The provider Spin offers a special feature, whose e-scooters not only contain GPS and mobile communications, but also a Bluetooth connection. Hilgert and colleagues followed up the locking and unlocking process using reverse engineering. The only thing missing was the associated Bluetooth key, which is exchanged every 24 hours. But here too, the provider’s API proved to be chatty. A query provided the researchers with the key free of charge. Result: In a practical test, they were able to switch off a passing electric scooter via Bluetooth.

“If that happens in flowing traffic, it might not be the best thing,” summarized Hilgert. The researchers want to publish the results of the API analyzes on Github in the coming weeks.

Florent Malice
Florent Malicehttps://www.newsalarms.com/
Florent is a passionate blockchain enthusiast, dedicated to exploring the intersection of technology and finance. With a focus on blockchain, web crypto, and NFTs, he contributes insightful analyses and updates to NewsAlarms, offering clarity on the evolving landscape of digital assets.

Latest news

SiGMA Euro-Med 2025: Where Innovation Meets the Mediterranean

Birkirkara, Malta, 26th August 2025, ZEX PR WIRE, SiGMA Euro-Med returns to Malta from 1st to 3rd September 2025, powered...

SHHEIKH Token Presale Phase 1 Sells Out in Record Time – Phase 2 Launches at $0.00405

The crypto world is buzzing—and SHHEIKH Token is at the center of it all. In an impressive display of investor...

Irys Raises $10M Series A to Unlock $3 Trillion Data Economy With First Programmable Datachain

CoinFund-Led Round Accelerates Institutional Adoption of Infrastructure For Datachains London, UK, Aug 22, 2025, ZEX PR WIRE, Irys, the world’s...

Monsters, Ducks, and Multi-Chain Magic: 5 Things You Should Know About ArchLoot

Singapore, 21st August 2025, ZEX PR WIRE, If you’ve been following ArchLoot, you already know it’s far more than...

Hamza Automates Leads Hexona Systems to $100K MRR, Powering 1,000+ Agencies With Agentic AI.

Toronto, Canada, Aug 20, 2025, ZEX PR WIRE, In the fast-moving world of AI and automation, Hamza Baig isn’t just...

SiGMA Euro-Med 2025 launches with exclusive affiliate retreat in Gozo.

Malta, 20th August 2025, ZEX PR WIRE, In the lead-up to SiGMA Euro-Med 2025, SiGMA Group is extending an...

Must read

SHHEIKH Token Presale Phase 1 Sells Out in Record Time – Phase 2 Launches at $0.00405

The crypto world is buzzing—and SHHEIKH Token is at...

SenturoPay Goes Live with All-in-One Crypto Spend App and Card Solution

Launch introduces a streamlined platform where users can send,...

MFEV Marathon Success in Serbia: Celebrating Runners, Community, and Charity

MFEV proudly announces the successful conclusion of the MFEV...

Top Cryptos Under $1 to Buy in 2024: Invest Now!

Top Cryptocurrencies to Consider for 2024: Best Picks for...

Must-Grab Crypto Airdrops This August 2024

Get Ready for Exciting Upcoming Crypto Airdrops! Prepare yourself for...

You might also like
Recommended to you