
A prank DDOS attack on Waymo robotaxis in San Francisco—where 50 people simultaneously ordered rides to the same street, causing gridlock—has exposed a fundamental gap in robotaxi cybersecurity.
Unlike traditional cars, robotaxis rely on dozens of interconnected digital systems, each a potential entry point for hackers.
While some states and international regulators have begun treating cybersecurity as a core regulatory requirement, the incident underscores that the industry may be repeating history: just as airbags took over a century to become federally mandated, cybersecurity protections for autonomous vehicles still lack consistent legal oversight.
What happened
A San Francisco 'tech prankster' named Riley Walz organized a group distributed denial-of-service (DDOS) attack by having 50 individuals simultaneously order Waymos to the same dead-end street, creating a pileup that forced Waymo to disable rides until the next morning.
Why it matters
The incident reveals a critical vulnerability in robotaxi systems: unlike traditional vehicles, robotaxis depend on dozens of interconnected electronic control units, cloud connectivity, GPS, cameras, lidar, radar and AI models—each expanding what cybersecurity professionals call the 'attack surface,' or the number of possible entry points hackers can exploit. Disrupted communications could degrade an autonomous system's ability to safely navigate, and the rise of generative AI has compressed the timeline for identifying and exploiting vulnerabilities far faster than before.
What to watch
California and some other jurisdictions (Arizona, Michigan) have begun treating cybersecurity as part of autonomous vehicle regulation, and international standards like UN Regulation No. 155 now require automakers to maintain certified cybersecurity management systems. However, in New York City, Mayor Zohran Mamdani has refused to renew Waymo's license while focusing on labor protection rather than cybersecurity concerns.
Ask the AI about this article →
The San Francisco DDOS prank—while lighthearted in nature—has exposed a troubling parallel to automotive safety history. Louay Abdelkader, director of product management at QNX, frames the current state of robotaxi cybersecurity as analogous to the pre-1998 era when airbags existed but lacked legal mandate. Just as it took over a century after the first automobile and roughly 30 years after airbags were invented for them to become federally required, robotaxis are now proliferating across the country—Waymo operates in 11 major U.S. cities, Zoox has received regulatory approval for a commercial exemption, and Tesla has launched the Cybercab in at least seven cities—without consistent, binding cybersecurity standards.
The architecture of robotaxis amplifies this vulnerability. Unlike conventional vehicles with a single control system, robotaxis depend on dozens of interconnected components: electronic control units, cloud connectivity, GPS, cameras, lidar, radar, and AI models. Each represents what cybersecurity professionals call an "attack surface"—a potential entry point. Modern attackers are unlikely to remotely hijack an entire vehicle, according to experts; instead, they may target the broader ecosystem. Disrupted communications alone could degrade an autonomous system's ability to navigate safely, as the San Francisco prank demonstrated.
The emergence of generative AI has further compressed the threat timeline. Abdelkader notes that malicious actors can now use AI to identify vulnerabilities, automate attacks, and develop exploits far faster and with greater intent than a prankster operating a simple DDOS. Yet regulatory response remains fragmented. Some jurisdictions—Arizona, Michigan, and California—have begun treating cybersecurity as a core regulatory requirement, and international standards like UN Regulation No. 155 have mandated certified cybersecurity management systems. In New York City, by contrast, Mayor Zohran Mamdani's refusal to renew Waymo's license has centered entirely on labor protection and taxi driver concerns, leaving cybersecurity absent from the debate. Abdelkader argues that all lawmakers should build on existing frameworks rather than wait for a cyber incident to expose weakness, calling for manufacturers to embed security from the ground up and for closer collaboration between industry and policymakers.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Toyota Motor, Denso, Woven by Toyota, and Toyota Industries are all hiring for self-driving roles, but the job…

Toyota Motor announced it will begin introducing Level 2++ autonomous driving in 2028, starting with the Corol…

Uber's president and COO Andrew Macdonald predicted that in 15 to 20 years, nobody will own a car or have a dr…

A Reddit user gave their AI agent Cleo a prepaid $150 card, and after their son asked for the same, set up a r…

Pony.ai and South Korea's FutureLink signed a strategic cooperation agreement on August 28 at the Conrad Seoul…

Toyota announced it will equip production passenger cars with AI-based autonomous driving technology starting…
