What Happens If a Driverless Taxi Gets Hacked? The Cybersecurity Risks Nobody Talks About
What Happens If a Driverless Taxi Gets Hacked? The Cybersecurity Risks Nobody Talks About
In our last post, we looked at the robotaxis arriving on London's streets — the promise, the privacy questions, the climate debate. But there's one risk that deserves a post of its own, because it's the one that keeps security researchers up at night and gets the least airtime in the glossy launch announcements:
What happens when someone hacks a car that has no driver to grab the wheel?
A traditional car can be stolen. A connected, self-driving car can be commandeered — potentially from a keyboard on the other side of the planet. And when you scale that from one car to a fleet of thousands moving through a city, the question stops being about theft and starts being about public safety on a scale we've never had to think about before.
At RushXO, we run a human-driven private hire and airport transfer service across London and the UK — so we've got a foot in both worlds: we understand the technology's appeal, and we also understand why "trust us, it's secure" isn't good enough when it's your family in the back seat. This post breaks down what could actually go wrong, how serious it really is, how the industry is fighting back, and a question that matters just as much: can we even trust the safety statistics these companies publish?
Let's open the hood.
Why a Robotaxi Is a Hacker's Dream Target
Here's the uncomfortable truth the industry doesn't lead with: a modern autonomous vehicle is essentially a data centre on wheels. Today's high-end vehicles can run on over 100 million lines of code — more than a fighter jet or a modern operating system. Every line is a potential door.
And unlike your laptop, this computer:
Weighs two tonnes and moves at speed through crowded streets
Is permanently connected — to the internet, cellular networks, GPS, and its operator's cloud
Is one of thousands of identical units running the same software (hack one design flaw, and you've potentially found it in all of them)
Carries passengers who have zero ability to take manual control
Security researchers have been warning about this for a decade. The wake-up call came in 2015, when two researchers famously took remote control of a Jeep Cherokee on a highway — cutting its transmission from miles away through a weakness in its connected entertainment system. That single demonstration reshaped automotive security. Since then, researchers have repeatedly shown they can exploit vehicles — including taking control of a Tesla Model 3 in minutes at a hacking competition by exploiting its infotainment system. These were "white hat" (ethical) hackers proving a point. The point was made.
The unsettling headline stat: industry cybersecurity reports have found that the large majority of automotive attacks are carried out remotely — no physical access to the car required.
The Five Ways a Driverless Taxi Could Be Attacked
Not all hacks are the Hollywood "seize the steering wheel" scenario. The real risk landscape is broader — and some of it is more plausible than the dramatic version.
1. Remote vehicle takeover
The nightmare scenario: an attacker gains control of driving functions — steering, braking, acceleration. With no human driver as a fail-safe, this is far more dangerous in a robotaxi than in a conventional connected car. This is the hardest attack to pull off (the driving systems are the most heavily protected), but the highest consequence.
2. Sensor spoofing and "adversarial" tricks
You don't have to hack the computer if you can fool its eyes. Researchers have shown that autonomous systems can be deceived by manipulating what their sensors perceive — for example, specially designed stickers or patterns ("adversarial patches") placed on signs or roads that a human ignores but that cause the AI to misread a stop sign, a lane, or an obstacle. Spoofing GPS or LiDAR signals falls in the same category: the car isn't "hacked" in the traditional sense — it's lied to.
3. Fleet / cloud platform attack
This is the one that scales terrifyingly. Robotaxis aren't lone vehicles — they're fleets managed by cloud systems that push software updates and routing instructions. Compromise the platform rather than one car, and an attacker could, in theory, disrupt every vehicle at once: flooding one area with cars to cause gridlock, halting a fleet mid-journey, or worse. Security experts flag fleet-level attacks as a genuinely new category of risk — a kind of mass "car theft" or citywide denial-of-service that has no equivalent in the human-driven world.
4. Data breach
Every robotaxi harvests enormous quantities of data: interior camera footage, journey histories, payment details, precise location logs tied to your identity. That's a treasure chest for criminals. A breach could expose where you live, where you travel, and when you're not home — privacy violations with real-world safety consequences, layered on top of the standard financial fraud risk.
5. Ransomware and extortion
The business-model attack: lock down a fleet's systems and demand payment to release them. Ransomware has already crippled hospitals, pipelines, and airlines. A robotaxi operator whose entire fleet is frozen during rush hour is exactly the kind of high-pressure target extortionists love.
How Bad Is the Risk, Really? (A Reality Check)
Now the balance — because fear-mongering helps nobody, and the picture isn't all dark.
The reassuring side:
The dramatic "someone drives your car off a bridge from their basement" scenario is genuinely hard. Driving-critical systems are increasingly isolated from the internet-facing systems (infotainment, connectivity), so a breach of one doesn't automatically hand over the other
The industry has spent years preparing. International standards now exist specifically for this — ISO/SAE 21434 (automotive cybersecurity engineering) and UN regulations R155 and R156 (cybersecurity and software update management) mean new vehicle types must prove they were designed with security baked in before approval
Fleet operators use bank-grade defences: strong access controls, continuous activity monitoring, encrypted communications, and strict verification
A large, well-resourced operator arguably runs better security than the average individual driver's connected car ever will
The honest side:
"Hard" is not "impossible." As one security expert put it, defending cars from hackers is an ongoing journey, like defending PCs or phones — there will be attempts, and probably occasional incidents
The threat landscape is worsening, not stabilising. Experts warn that AI is already reshaping how attacks are built, and that today's encryption will eventually need "post-quantum" upgrades to stay ahead
More connectivity means more attack surface — and robotaxis are among the most connected machines ever put on public roads
Regulation and standards reduce risk; they don't eliminate it. The 100-million-lines-of-code problem means there will always be undiscovered flaws
The fair verdict: catastrophic mass-hacks are unlikely but not impossible, while smaller incidents (data breaches, localised disruption, spoofing pranks) are close to inevitable over time. The right posture isn't panic — it's insisting on transparency and accountability before these fleets scale, not after the first serious incident.
How the Risks Are Being Mitigated
For readers who want the solutions, not just the scares, here's how the industry, regulators, and you can each reduce the danger.
What manufacturers and operators are doing
Security by design — building protection into vehicles from the ground up, as ISO/SAE 21434 now requires, rather than bolting it on afterward
System isolation — walling off driving-critical systems from internet-connected ones so a breach of the entertainment screen can't reach the brakes
Over-the-air updates — patching vulnerabilities remotely and fast (the same channel that, ironically, must itself be ruthlessly secured — hence UN R156)
Continuous monitoring — 24/7 security operations watching fleets for abnormal behaviour, the way banks watch for fraud
Encryption everywhere — protecting data both inside the car and in transit to the cloud
Redundancy and fail-safes — systems designed so that if something goes wrong, the car defaults to a safe stop rather than chaos
Ethical hacking programmes — paying white-hat researchers to find flaws first (bug bounties), turning potential attackers into defenders
What regulators are doing
The UK's incoming self-driving framework sits alongside international standards (ISO/SAE 21434, UN R155/R156) that make cybersecurity a condition of approval. Expect data-protection law (UK GDPR) to govern the privacy side, and liability rules — still being finalised — to force clarity on who pays when a hack causes harm.
What you can do as a passenger
You have less control here than with, say, your email — but not zero:
Favour established operators with strong security track records and transparent policies over unknown newcomers
Protect your account — strong, unique passwords and two-factor authentication on ride-hailing apps, since your account is part of the attack surface
Mind what you connect — think twice before pairing your phone or logging into accounts on an in-car system
Read the data policy (at least once) — know what's collected and your rights to access or delete it under GDPR
Keep the human option open — which brings us to a point close to home
The Question That Gets Dodged: Can We Trust the Statistics?
Here's the part of this debate that deserves far more scrutiny than it gets. Robotaxi companies constantly tell us their vehicles are safer than human drivers — fewer crashes per mile, fewer injuries, a safety revolution. Those claims may well be true. But there's a problem worth stating plainly:
Almost all the safety data comes from the companies selling the product.
That's not an accusation of lying — it's a structural conflict of interest that any thoughtful reader should keep in mind. Consider the reasons for healthy scepticism:
The scorekeeper owns the game. When an operator publishes "X% fewer collisions," they typically chose the methodology, the comparison group, and which numbers to release. Independent, apples-to-apples verification is still scarce
Miles aren't equal. Robotaxis often rack up their impressive safety miles in favourable conditions — good-weather cities, mapped-in-advance zones, lower speeds, geofenced areas. Comparing those miles to a human's all-weather, all-road average isn't a fair fight
Definitions are slippery. What counts as a "crash," an "incident," or a "disengagement" (when a safety driver takes over) can be defined narrowly. Change the definition, change the headline
Near-misses go unreported. A robotaxi that freezes at a junction, blocks an ambulance, or gets confused by roadworks may cause no "crash" but plenty of real-world disruption — and those events don't always make the safety stats
Bad news gets managed. History across many industries shows companies are quicker to publicise favourable data than unfavourable data. Some robotaxi operators have faced regulator scrutiny for how transparently they disclosed incidents
None of this means robotaxis are secretly dangerous. It means the honest answer to "are they safer?" is currently: "the companies say so, some early independent data is encouraging, and we should demand rigorous, independent, standardised reporting before treating it as settled." Extraordinary claims deserve extraordinary evidence — especially when the entity making the claim profits from your belief in it.
The gold standard we should all be asking for: independent regulators and researchers, not manufacturers, verifying safety data using standardised definitions and fair comparisons, published transparently — including the failures. Until that's the norm, a little healthy scepticism is not being a luddite. It's being a responsible passenger.
Where RushXO Stands
We're not here to tell you robotaxis are evil — competition and innovation are good for London, and one day autonomous vehicles will have earned their place. But we believe the honest position, right now, is this:
When the technology is this new, the security risks this novel, and the safety statistics this self-reported — human accountability still matters.
When you book a RushXO airport transfer or private hire journey, there's a licensed, experienced, professional driver responsible for your safety — someone who can read a situation no algorithm has encountered, who can't be remotely commandeered by a hacker, and who is accountable to you and to the regulator. No beta software. No cloud platform between you and the brakes. Just a professional, a clean executive vehicle, a fixed price agreed upfront, and real-time flight monitoring so we're there when you land.
The future will almost certainly be a hybrid one — robots for some journeys, humans for others. Until autonomous vehicles have proven themselves through independent scrutiny rather than press releases, we're proud to be the option you can trust with the journeys that matter.
The Bottom Line
A driverless taxi is a computer on wheels running 100M+ lines of code — a large, mobile, always-connected attack surface
Real risks: remote takeover, sensor spoofing, fleet-wide cloud attacks, data breaches, and ransomware — with fleet-level attacks being a frightening new category
The dramatic "hack your car off a bridge" scenario is hard but not impossible; smaller incidents like data breaches are close to inevitable over time
Strong defences exist — ISO/SAE 21434, UN R155/R156, system isolation, monitoring, encryption, ethical hacking — but security is a permanent arms race, not a solved problem
Treat company-published safety stats with healthy scepticism: demand independent, standardised, transparent verification before accepting "safer than humans" as fact
Until then, human-driven services remain the accountable, un-hackable-by-remote choice for the journeys where reliability can't be a beta test
Travelling in London or across the UK and want a driver you can trust? RushXO provides fixed-price airport transfers and private hire — no meters, no surge pricing, no hidden charges — with professional drivers, executive vehicles, real-time flight monitoring, and 24/7 availability for Heathrow, Gatwick, Stansted, Luton, London City and beyond. Book with RushXO →
Continue the series: read Driverless Taxis Are Coming to London: Everything You Need to Know, and know your rights when journeys go wrong in Stuck at Heathrow? 12 Problems Solved.

Comments
Post a Comment