ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

19-year-old claims he hacked into over 25 Tesla cars in 13 countries

A 19-year-old cybersecurity entrepreneur in Germany claims to have hacked remotely into more than 25 Tesla cars in 13 countries, including Switzerland.

 

In a series of tweets, David Colombo from Dinkelsbuhl claimed that a software flaw allows him to unlock doors and windows, flash their headlights, start the cars without keys, and even disable the Sentry Mode, anti-theft technology in which a built-in camera becomes a de facto alarm system.

 

He also claimed that he could query the vehicle’s exact location, check if the driver is present, and cause music to play on the Tesla’s sound system. The self-described IT security specialist and hacker made these claims via his Twitter account @David_colombo_ on Monday.

 

“I think it’s pretty dangerous if someone is able to remotely blast music on full volume or open the windows/doors while you are on the highway,” wrote Colombo on Twitter. “Even flashing the lights non-stop can potentially have some (dangerous) impact on other drivers,” he added.

 

Colombo contacted Tesla to inform them of the alleged problem, but he insisted that it was not caused by a security flaw in the vehicles. “This is not a vulnerability in Tesla‘s infrastructure,” wrote Colombo. “It’s the owners [sic] faults.”

 

The teen didn’t go into detail about the software flaw but said it wasn’t related to Tesla’s software or infrastructure and that only a small number of Tesla owners were affected globally. Colombo’s tweet went viral, garnering over 6,600 reactions, 1,300 shares, and nearly 300 replies.

 

According to his LinkedIn page, Colombo is a cybersecurity expert. He claims to have written the first piece of code at the age of 10 and developed a company called Colombo Technology, intending to “help every business to get protected from the ever-evolving and dangerous threat actors in the cyberspace.”

 

In a Monday tweet, Colombo originally claimed to have “full remote control” of the Teslas. However, he later clarified that he could never take over cars to “remotely control steering or acceleration and braking.”

 

“Yes, I potentially could unlock the doors and start driving the affected Tesla’s,” he tweeted. “No, I cannot intervene with someone driving (other than starting music at max volume or flashing lights), and I also cannot drive these Tesla’s remotely.”

 

On Tuesday, Colombo tweeted that his hack was “not a vulnerability in Tesla’s infrastructure” but rather “it’s the owners faults.” On Monday, he had tweeted that “There seems to be no way to find the owners and report it to them.”

 

Colombo wrote on Tuesday that Tesla’s security team had confirmed that they are investigating his claims and will keep him updated on their discovery.

 

U.S.-based Tesla has a vulnerability disclosure platform where security researchers can register their vehicles for testing, which Tesla can pre-approve. The company pays up to $15,000 for a qualifying vulnerability.

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543