Black Hat Asia 2026 | Mass Scale Hijacking of Shared Mobility and EV-Charging Fleets

Black Hat Asia 2026 | Mass Scale Hijacking of Shared Mobility and EV-Charging Fleets

Source: YouTube · Black Hat · published Aug 28, 2026 · 30:02

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Rainbow IoT systems, such as shared mobility devices and EV chargers, suffer from critical security flaws where weak identifiers and poor backend authorization allow attackers to escalate local bugs into fleet-wide attacks, enabling free usage, denial of service, and data breaches 15:36.

Key Takeaways:
• Rentable IoT devices present unique risks because their central cloud control plane is directly connected to physical actions like unlocking and charging, meaning digital vulnerabilities quickly become operational and physical issues 02:10.
• Hardware security is often compromised by exposed debug interfaces and easily extractable firmware, allowing attackers to recover hardcoded credentials and reverse engineer protocols without physical access to the target device 04:00.
• Predictable and short identifiers act as a "scale amplifier"; when combined with weak authentication or missing authorization checks, they allow attackers to enumerate valid devices and users, turning a single-point bug into a large-scale attack 15:36.
• App-side vulnerabilities allow remote attackers to abuse the interface between the user and the backend, leading to payment bypasses, account hijacking, and unauthorized control of physical devices without needing to compromise the hardware directly 13:27.
• Live demonstrations confirmed that attackers can spoof device states to achieve free charging sessions and remotely disrupt services for specific devices in real-world locations, such as Shanghai, China 19:28.

The widespread use of short, human-readable identifiers and shared keys in manufacturing prioritizes convenience over security, creating systemic vulnerabilities across the IoT ecosystem. Vendors must implement strong per-device authentication, non-predictable identifiers, and robust authorization checks to prevent local flaws from becoming fleet-wide disasters.

Sources:

  • 02:10 Explanation of Rentable IoT architecture and its direct connection to physical infrastructure.
  • 04:00 Discovery of exposed debug interfaces and extractable firmware on hardware devices.
  • 13:27 Analysis of app-side vulnerabilities allowing abuse of the user-backend interface.
  • 15:36 Explanation of how weak identifiers enable scalable, fleet-wide attacks.
  • 19:28 Live demonstration of spoofing device states to achieve free charging.
  • 28:50 Conclusion on the necessity of fixing the trust model across devices, apps, and backends.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. It's really hard to get up early early, right? So, let me uh bring you something exciting. So, let me have our introduce. My name is Hu Tian Shu and just call me Mori Shu. Uh and I'm from Tsinghua University. Today, I want to talk about Rainbow IoT systems, things like shared mobility devices and electric vehicle chargers and why they create a very different stories uh about the from the traditional IoT. Before I start, just a quick intro. I worked on hardware and IoT security at Tsinghua University, especially physical layer and device side security problems. A lot of my work focuses on small implementation details that uh can create very large uh real-world security impacts. This is the road map of the talk. I will first explain why Rainbow IoT is different, then walk thr…