NewsStocksSan Francisco 'Tech Prankster' Ordered 50 Waymos to One Street, Exposing Robotaxis' Cybersecurity Gap

San Francisco 'Tech Prankster' Ordered 50 Waymos to One Street, Exposing Robotaxis' Cybersecurity Gap

Author: Fortune Crypto·

Key Takeaways

  • Robotaxi services are expanding quickly, with Waymo operating in 11 cities, Tesla's Cybercab in at least seven, and Zoox securing NHTSA approval for broader operations.
  • The complex interconnected systems and centralized fleet management platforms used by robotaxis significantly increase their vulnerability to cyberattacks.
  • A coordinated denial-of-service attack in San Francisco forced Waymo to suspend rides, highlighting real-world cybersecurity vulnerabilities.
  • The advancement of generative AI allows malicious actors to identify vulnerabilities and automate attacks much faster than before.
  • Unlike international standards such as the UN's Regulation No. 155, the United States currently lacks a federal cybersecurity mandate for vehicles.
San Francisco 'Tech Prankster' Ordered 50 Waymos to One Street, Exposing Robotaxis' Cybersecurity Gap

It took until 1998 for federal law to require airbags in every vehicle — over a century after the invention of the automobile and roughly three decades after airbags were first developed as a safety measure. A similar pattern is now unfolding with robotaxis and cybersecurity, according to industry experts.

Louay Abdelkader, director of product management at QNX — the BlackBerry-owned automotive software supplier whose real-time operating systems are embedded in more than 215 million vehicles worldwide — sees this as a critical issue for the sector. "Of course… keep in mind that in automotive safety, it took a while for it to adopt," he told Fortune. Abdelkader argues that lawmakers should elevate cybersecurity to the same level of priority as airbags, emphasizing that every connected vehicle introduces some degree of cyber risk.

Much of the public debate surrounding robotaxis, however, has centered on other questions: whether autonomous systems are sufficiently intelligent to avoid collisions, how insurance companies should assign liability in accidents, and how law enforcement should handle driverless cars that commit traffic violations.

Robotaxis are expanding rapidly across the United States. Zoox recently received regulatory approval from the National Highway Traffic Safety Administration (NHTSA) for a commercial exemption, granting the paid service broader access to operate without manual controls. Tesla has entered the robotaxi market with its Cybercab operating in at least seven cities. Alphabet-owned Waymo has grown from its Arizona origins to 11 major U.S. cities, even partnering with rideshare company Uber in select markets.

Unlike conventional vehicles, robotaxis rely on dozens of interconnected electronic control units, high-speed networking, cloud connectivity, GPS, cameras, lidar, radar, and AI models that continuously interpret the surrounding environment. Each of these components expands what cybersecurity professionals call the "attack surface" — the number of possible entry points that hackers can exploit. Crucially, robotaxis also depend on centralized fleet-management platforms that dispatch vehicles to pickup locations, meaning the ride-hailing infrastructure itself becomes a potential target, not just the cars on the road.

While Hollywood often depicts hackers remotely hijacking an entire vehicle, experts say modern attacks are more likely to target the broader ecosystem surrounding autonomous cars. Even if attackers cannot directly steer a vehicle, disrupted communications could degrade an autonomous system's ability to navigate safely.

In San Francisco, self-proclaimed "tech prankster" Riley Walz demonstrated this vulnerability by organizing a group denial-of-service (DDoS) attack on local Waymos. Walz documented the stunt on X. The prank involved 50 individuals simultaneously ordering a Waymo on the same dead-end street, creating a pileup that forced the company to suspend rides until the following morning.

The DDoS incident occurred despite California regulations — where Waymo operates in San Francisco and Los Angeles — requiring autonomous vehicle manufacturers to demonstrate that they can safely monitor, update, and maintain their fleets while complying with federal vehicle cybersecurity guidance. Waymo and the California DMV did not respond to requests for comment.

The rise of generative AI has further amplified cybersecurity risks. Historically, hackers needed significant time, technical expertise, and resources to identify and exploit vulnerabilities. AI has dramatically compressed that timeline, according to Abdelkader. He warned that malicious actors can now use AI to identify vulnerabilities, automate attacks, and develop exploits far faster — and with greater malicious intent — than Walz's prank.

Abdelkader said cybersecurity for robotaxis is the shared responsibility of manufacturers and lawmakers. He argued that manufacturers must build security into autonomous vehicles from the outset rather than treating it as an add-on. "When you're developing a cybersecurity system, you start from the ground up. It's like building a house," he said. "If your foundation is not strong, it becomes very difficult for you to build a robust and secure house."

Some jurisdictions have already begun treating cybersecurity as an integral part of autonomous vehicle regulation rather than an afterthought. Arizona has incorporated cybersecurity planning into broader autonomous vehicle deployment policies, while states like Michigan have established cybersecurity initiatives through partnerships with industry and research institutions.

International regulators have moved even further. The United Nations' UN Regulation No. 155 now requires automakers in many markets to maintain certified cybersecurity management systems throughout a vehicle's lifecycle, while ISO/SAE 21434 establishes engineering standards for cybersecurity across vehicle development. The U.S. has no equivalent federal mandate, leaving a patchwork of state-level requirements.

In New York City, however, where Mayor Zohran Mamdani has refused to renew Waymo's license, cybersecurity has been absent from the robotaxi debate. The mayor has instead focused on labor protection, citing taxi drivers as his primary concern. "If a company like Waymo finds itself in New York City, what they will also find is a City government that is committed to delivering for the workers who keep the city running," Mamdani said at a press conference. "Those workers also include our taxi drivers who, for far too long, have been sold a dream of being able to work their way to the middle class." Mamdani's office did not respond to a request for comment.

Abdelkader maintains that lawmakers nationwide should build on existing frameworks rather than waiting for a cyber incident to expose a weakness. He said policymakers too often separate safety from cybersecurity, even though the two are "tied at the hip."

"The legislators and politicians have to work with them to make sure that moving forward, if there are improvements that need to be done, what type of support is required," he told Fortune. "You need to be able to talk and share that feedback. That's the only way for the industry to grow effectively and benefit society."