A Prank Exposed Waymo's Biggest Blind Spot: Why Robotaxis Need Cybersecurity Like Airbags
Robotaxis are proliferating across the United States, but they're missing a safety feature as fundamental as airbags once were: robust cybersecurity protections built into their core systems. A recent prank in San Francisco highlighted this vulnerability when a self-proclaimed "tech prankster" named Riley Walz organized a group denial-of-service (DDoS) attack by having 50 individuals simultaneously order Waymo robotaxis to the same dead-end street, creating a massive pileup that forced the company to disable rides until the next morning.
The incident exposed what cybersecurity experts have been warning about for months: unlike conventional vehicles, robotaxis depend on dozens of interconnected electronic control units, high-speed networking, cloud connectivity, GPS, cameras, lidar, radar, and artificial intelligence models that continuously interpret the world around them. Every one of those components expands what cybersecurity professionals call "attack surface," or the number of possible entry points hackers can exploit.
Why Is Cybersecurity Missing From the Robotaxi Debate?
Much of the public conversation about robotaxis has focused on whether they're intelligent enough to avoid collisions, how insurance companies should assign liability in accidents, or how police can handle driverless cars that commit traffic violations. But cybersecurity has largely been overlooked, even though it poses an equally serious threat to passenger safety. Waymo operates in 11 major U.S. cities, while Amazon's Zoox recently received regulatory approval for paid commercial service, and Tesla has launched its Cybercab in at least seven cities.
"In automotive safety, it took a while for it to adopt," said Louay Abdelkader, director of product management at QNX, noting that lawmakers should make cybersecurity a primary consideration akin to airbags. "Every connected vehicle introduces some degree of cyber risk."
Louay Abdelkader, Director of Product Management at QNX
The comparison to airbags is instructive. Federal law didn't require airbags in every vehicle until 1998, more than 100 years after the automobile was invented and roughly 30 years after airbags were first developed as a safety measure. Today, robotaxis face a similar regulatory lag: California, where Waymo operates in San Francisco and Los Angeles, requires autonomous vehicle manufacturers to demonstrate they can safely monitor, update, and maintain their fleets while complying with federal vehicle cybersecurity guidance. Yet the Walz prank succeeded despite these rules.
How Are Hackers Targeting Autonomous Vehicles?
While Hollywood often depicts hackers remotely hijacking an entire vehicle, cybersecurity experts say modern attacks are more likely to target the broader ecosystem surrounding autonomous cars. Even if attackers cannot directly steer a vehicle, disrupted communications could degrade an autonomous system's ability to safely navigate. The Walz prank demonstrated this principle: by flooding Waymo's ordering system with simultaneous requests, the attack didn't need to compromise the vehicles themselves to cause operational chaos.
The advent of generative AI has accelerated these risks. Historically, hackers needed significant time, technical expertise, and resources to identify and exploit vulnerabilities. But AI has dramatically compressed that timeline, allowing malicious actors to identify vulnerabilities, automate attacks, and develop exploits far faster than traditional methods would allow.
Steps to Strengthen Robotaxi Cybersecurity Standards
- Build Security From the Ground Up: Manufacturers must integrate cybersecurity into autonomous vehicles from the beginning of development, not treating it as an add-on. As Abdelkader explained, "When you're developing a cybersecurity system, you start from the ground up. It's like building a house. If your foundation is not strong, it becomes very difficult for you to build a robust and secure house."
- Establish Regulatory Frameworks: Some jurisdictions have already begun treating cybersecurity as part of autonomous vehicle regulation. Arizona has incorporated cybersecurity planning into broader autonomous vehicle deployment policies, while states including Michigan have established cybersecurity initiatives through partnerships with industry and research institutions.
- Adopt International Standards: The United Nations' UN Regulation No. 155 now requires automakers in many markets to maintain certified cybersecurity management systems throughout a vehicle's lifecycle, while ISO/SAE 21434 establishes engineering standards for cybersecurity across vehicle development.
Abdelkader emphasized that cybersecurity for robotaxis is largely the responsibility of both manufacturers and lawmakers working in concert. He argued that policymakers often separate safety from cybersecurity too often, even though "they are tied at the hip." He stressed that legislators and politicians must work with manufacturers to ensure improvements are made and support is provided when needed.
Abdelkader
What Are Regulators Doing About This Gap?
Internationally, regulators have moved further than most U.S. jurisdictions. However, in New York City, where Mayor Zohran Mamdani has refused to renew the license for Waymo, cybersecurity has been conspicuously absent from the debate over robotaxis. Mamdani has instead focused on labor protection, citing taxi drivers as the main point of concern with allowing robotaxis to roam Manhattan, arguing that a company like Waymo would find "a City government that is committed to delivering for the workers who keep the city running".
The contrast between New York's labor-focused approach and the cybersecurity concerns raised by experts highlights a broader regulatory fragmentation. While California has begun incorporating cybersecurity requirements, and international bodies have established standards, there is no unified U.S. federal framework that treats cybersecurity with the same urgency as traditional vehicle safety features. Abdelkader called for policymakers to build on existing frameworks rather than waiting for a cyber incident to expose a weakness, warning that "you need to be able to talk and share that feedback. That's the only way for the industry to grow effectively and benefit society".
The Walz prank, while presented as a harmless stunt, served as a proof-of-concept that robotaxis remain vulnerable to coordinated attacks. As robotaxis expand to more cities and carry more passengers, the stakes of these cybersecurity gaps will only grow higher.