A forensic investigator recently pulled data from a rental car and found records from 70 prior drivers: calls, texts, and social media history from connected phones. The car itself was never hacked. The data was simply there, collected by design.
This is the reality of what some have started calling "snitchware," a term for the microphones, cameras, and sensors now embedded across consumer technology. These components exist for legitimate purposes. They power voice assistants, enable hands-free calling, and support safety features. They also create an infrastructure that state actors, hackers, and data brokers can exploit.
The Car Problem
Security vulnerabilities in Skoda and Volkswagen systems allow hackers remote access to microphones, according to recent reporting. The FBI was able to surreptitiously turn on the built-in microphones in automotive systems like General Motors' OnStar to snoop on passengers' conversations as far back as 2003. When FBI agents remotely activated the system and were listening in, passengers in the vehicle could not tell that their conversations were being monitored.
The Dutch intelligence service AIVD has reportedly begun warning personnel to avoid holding confidential conversations in or near modern vehicles, citing the risk that microphones can be switched on remotely. According to these advisories, some state actors can request car data directly from manufacturers or hack in to obtain it themselves. The guidance reportedly goes further: skip wireless charging and Bluetooth or Wi-Fi pairing, use a USB data blocker when charging phones, and avoid bringing vehicles with external cameras to sensitive locations. Glitchwire was unable to independently verify the specific AIVD advisory, though the agency has been increasingly vocal about threats to national security that have not come from so many directions since the founding of the AIVD after World War II.
Ford has literally patented cabin conversation recording for targeted advertising purposes. Audio gets shared with insurers who might adjust rates based on detected stress, marketers crafting personalized ads, and sometimes law enforcement through emergency microphone access.
Smart Glasses and the Bystander Problem
Meta moved approximately seven million Ray-Ban co-branded units through 2025, meaning camera-equipped smart glasses had shifted from niche enthusiast hardware into mainstream retail.
Two Harvard University students demonstrated that footage from Meta's Ray-Ban smart glasses could be connected to external facial recognition systems to identify strangers in public. In October 2025, the University of San Francisco issued a warning after reports that a man wearing Ray-Ban Meta smart glasses was approaching women on and around campus and recording interactions that may have been shared on social media.
The Atlantic Council's Trisha Ray put it plainly: "The people being watched cannot consent, because the surveillance is invisible in ways that even the smartphone era did not surface." A similar dynamic applies to wearable AI devices that record ambient audio. The wearer opts in. Everyone nearby does not.
In a lawsuit filed March 2026 in federal court, plaintiffs alleged that Meta paired privacy-centric marketing claims with insufficiently clear disclosures regarding transmission, cloud processing, and human review of captured media. The complaint points to slogans like "designed for privacy, controlled by you," arguing they gave buyers false assurance.
The Infrastructure Already Exists
A vulnerability found in KARR and SWDS automobile security systems manufactured by Acrisure enables remote control via Bluetooth. Dealerships install the device to manage vehicle inventory, then typically market it to buyers as a paid security upgrade. But the vulnerability exists whether or not the buyer accepts. If a customer declines, the device stays installed and active.
The intelligence community's interest in these capabilities is well documented. The special powers of the AIVD and MIVD include tapping phones, installing cameras and microphones in private rooms, raiding houses, hacking computers and routers, and tapping internet traffic. In 2024, the Dutch Review Committee TIB received 4,445 requests from the Dutch intelligence agencies to use their special powers to collect information secretively, an increase of more than 30% compared to the year before.
The capabilities exist because the hardware is already there. Every car with a telematics system, every pair of smart glasses with a microphone, every wearable with an always-listening assistant creates an endpoint. Whether that endpoint gets exploited depends on software architecture, legal frameworks, and the priorities of whoever wants access.
The AIVD's reported advice to use USB data blockers and avoid Bluetooth pairing near sensitive conversations sounds paranoid until you remember that with the right equipment, it is possible to remotely activate the microphone of cellular phones, even when a call is not being made, to listen to conversations in the vicinity of the phone. The threat model has simply expanded to include the car.


