Automotive

I Am In Your Car. I Am In Your Maps. Abuser Terrorizes Ex Using Parental Controls And Tesla’s App

The integration of advanced digital ecosystems into modern vehicles was designed to offer unprecedented convenience, safety, and connectivity. However, a recent criminal case in Australia has illuminated a harrowing secondary reality: the same tools intended to protect drivers and assist with fleet management can be weaponized as instruments of stalking, control, and psychological abuse. Enrico Pucci, a 50-year-old man, was recently convicted of 30 charges related to the stalking and harassment of an ex-partner, identified in legal records by the pseudonym "Stacey." Among the most alarming aspects of his campaign of terror was his use of the Tesla mobile application to remotely manipulate, track, and restrict the victim’s vehicle long after their relationship had ended.

This incident serves as a stark case study in the intersection of domestic violence and the "Internet of Things" (IoT). As vehicles become increasingly reliant on cloud-based accounts and smartphone integration, the perimeter of personal security has expanded to include digital access points that, if left unmanaged, can become tools for perpetrators.

A Chronology of Digital Abuse

The foundation for this abuse was laid under the guise of technical assistance. While the couple was still in a relationship, Stacey purchased a Tesla. Unfamiliar with the intricacies of the car’s interface and the associated mobile app, she accepted help from Pucci. He insisted that the vehicle be registered in his name, claiming it was necessary to grant him administrative access to the Tesla app to "assist her" with software updates and navigation.

Stacey ended the relationship in October 2025. By November 2025, the utility of the application shifted from maintenance to malice. The harassment began with the repeated activation of the car’s alarm system during the night. For a victim of domestic abuse, these alarms were not merely an annoyance; they were a psychological trigger, creating a constant state of fear that her former partner was physically present at her home.

Once he had established this environment of anxiety, Pucci utilized the vehicle’s "Parental Controls"—a suite of features intended for parents monitoring teenage drivers—to limit the vehicle’s functionality. By activating these settings, Pucci remotely blocked access to the car’s web browser, entertainment systems, and arcade games. More dangerously, he set speed limiters and capped the vehicle’s acceleration. For a driver commuting on high-speed thoroughfares, such limitations are not just inconveniences; they represent a significant safety hazard, potentially forcing the driver to operate at speeds incompatible with the flow of traffic.

The harassment extended to the physical environment inside the cabin. Pucci leveraged his access to the car’s climate control, alternating between extreme heat and freezing temperatures to ensure the victim remained uncomfortable during her commutes. He also remotely interrupted charging sessions, ensuring that the vehicle would be underpowered when the victim needed it most. Finally, he used the car’s integrated GPS tracking to monitor her movements in real-time, culminating in an encounter where he followed her in another vehicle, shouting that he could see her location through the app’s mapping feature.

The Vulnerability of Modern Connectivity

The case of the Tesla application is not an anomaly restricted to a single manufacturer. Modern automotive design has shifted toward a "connected car" paradigm, where almost every major automaker—including Ford, General Motors, Toyota, and Hyundai—offers mobile applications that provide remote access to vehicle telemetry.

Data from the automotive security sector suggests that as vehicles become more software-defined, the attack surface grows. A report from the Mozilla Foundation’s "Privacy Not Included" project recently highlighted that the automotive industry is one of the worst sectors for data privacy. Many manufacturers collect vast amounts of information, including location data, driving habits, and even biometric data, which is often shared with third parties or remains accessible through shared account credentials.

'I Am In Your Car. I Am In Your Maps,' Abuser Terrorizes Ex Using 'Parental Controls' And Tesla's App

In the case of Pucci and Stacey, the vulnerability was not a "hack" in the traditional sense of bypassing security protocols. Instead, it was an exploitation of the legitimate administrative privileges granted to the account owner. When a vehicle is tied to a single user account, that user becomes the "superuser" of the car. If the relationship between the primary account holder and the driver changes, the digital tether remains unless explicitly revoked.

Institutional Responses and Industry Standards

While manufacturers provide mechanisms for transferring ownership or resetting account permissions, these processes often require cooperation from the previous owner or a visit to a service center. For victims of domestic violence, such requirements can be physically dangerous or logistically impossible.

Industry experts argue that automakers must implement more robust "safety off-ramps" for victims of domestic abuse. This could include:

  1. Streamlined Account Migration: Simplified methods for transferring primary account control without needing the previous owner’s authorization, provided that legal documentation of ownership or a protective order is presented.
  2. Emergency Revocation: A "panic button" feature within the vehicle’s physical interface that instantly severs all remote app connections and forces a factory reset of user permissions.
  3. Multi-User Transparency: Clearer dashboards that notify all users if a remote restriction (such as a speed limiter) has been enabled, preventing a perpetrator from silently imposing limitations.

Tesla, in its official owner’s manual, provides instructions on how to add or remove drivers and how to manage access. However, these instructions assume a cooperative environment. There is currently a lack of a "victim-centric" recovery protocol within the automotive industry that accounts for scenarios where the primary account holder is an abuser.

Broader Implications for Personal Security

The legal implications of this case are significant. Enrico Pucci’s conviction demonstrates that the law is beginning to catch up with "cyber-stalking" involving IoT devices. However, the legal system moves slowly compared to the rapid evolution of technology.

For the average consumer, this case serves as a warning about the necessity of "digital hygiene" in physical assets. The days of simply handing over a set of keys are over. When a vehicle is purchased or shared, the following steps are increasingly viewed as standard practice:

  • Account Ownership: The primary driver should always be the primary account holder. Allowing a partner to register the vehicle in their name to "assist" with the app provides them with permanent, administrative control.
  • Credential Security: Passwords for automotive apps should be treated with the same sensitivity as banking passwords.
  • Periodic Audits: Drivers should periodically check their vehicle’s infotainment system for linked phones and user accounts. Removing unauthorized devices is a critical step in maintaining security.
  • Emergency Reset: In cases of separation, individuals should contact the manufacturer’s support line immediately to understand the process for disabling remote access, often requiring a reset of the vehicle’s telematics unit.

Conclusion

The terror experienced by the victim in this case highlights a profound failure in the design philosophy of modern connected vehicles: the assumption that the primary account holder is always the primary user. By prioritizing administrative control over the safety of the individual behind the wheel, manufacturers have inadvertently created tools that can be used to isolate and endanger victims.

As society becomes increasingly reliant on connected technologies, the protection of personal autonomy must be baked into the design of these systems. Security is not merely about preventing hackers from stealing a car; it is about ensuring that the person in the driver’s seat maintains exclusive control over their own movement and safety. The case of Enrico Pucci is a somber reminder that in the age of the connected car, the most dangerous intrusion may not come from a faceless cyber-criminal, but from someone who already holds the keys to your digital life.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
GIYH News
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.