Your ELD is a backdoor. Most carriers have no idea.
The device your driver is required by federal law to carry is also one of the least-secured pieces of technology on your fleet. Here is what researchers found — and what you need to do about it.
In 2024, researchers at Colorado State University presented a paper at the Network and Distributed System Security Symposium that won runner-up for best paper. The finding: commercial ELDs — the devices every US carrier is legally required to run — can be wirelessly compromised over Bluetooth or Wi-Fi, used to spread malware from truck to truck while moving down a highway, and in some cases leveraged to force vehicles to pull over remotely.
A bridge that runs in both directions
The FBI issued a bulletin years earlier. Their language: ELDs "create a bridge between previously unconnected systems critical to trucking operations." That bridge runs in both directions.
Why the mandate created the risk
The FMCSA ELD mandate that went into full effect in 2019 required carriers to log hours of service electronically. What it did not require was any security standard for the devices doing that logging. No encryption requirements. No third-party audits. No cybersecurity certification before self-certification.
The result: a market flooded with cheap, compliant-on-paper devices that do little to nothing to follow security best practices — a finding confirmed by FBI-referenced research on devices purchased directly off the shelf at retail stores.
In 2026, FMCSA updated compliance expectations to require encrypted data transmissions and mandatory over-the-air update capabilities. That is progress. But most fleets are still running devices purchased years before those standards existed.
What an attack through an ELD actually looks like
An attacker does not need to be inside your office. They need to be within wireless range of one of your trucks — a truck stop, a weigh station, a yard. From there:
- ★They access the ELD over an unencrypted Bluetooth or Wi-Fi connection.
- ★They load malware onto the device.
- ★That malware spreads to other vehicles the truck comes within range of — including loading docks and distribution centers.
- ★From the ELD, the attacker pivots to connected systems: your TMS data feed, driver communication logs, DOT compliance records.
The Colorado State team demonstrated this in a controlled environment. They were not speculating.
The three questions every carrier needs to answer today
When did your ELD vendor last push a security update?
If you cannot answer this, your device may be running firmware with known vulnerabilities. Ask your vendor directly. If they cannot answer either, that is your answer.
Does your ELD encrypt data in transit?
Unencrypted Bluetooth connections are no longer compliant under 2026 FMCSA standards. If your device is still transmitting data in the clear, you are exposed — legally and operationally.
What connects to your ELD network?
ELDs are increasingly integrated with TMS platforms, fuel card systems, and fleet management software. An attacker who enters through the ELD does not stay there.
What the We Secure partnership covers
Our cybersecurity offering, delivered through We Secure, includes endpoint detection on all devices with network access — including telematics systems — and continuous monitoring for lateral movement between systems. If an ELD on your fleet is behaving like an entry point, we see it.
Start with a free exposure check
We will run the same scan an attacker would run on your network — including your connected telematics — and tell you exactly what they see.
Book a 30-minute strategy call.
Walk away with a plan — even if we never work together.
Book a call →
