Back to Insights Network Security

Smart Cities – New Cybersecurity Challenges in the Modern Era

Smart cities can marvelously improve the quality of life for their residents—yet new technology brings with it cyber challenges and new vulnerabilities for criminals to exploit. Here is where and how to be cautious…

In the past, most citizens lived outside the city—in villages, suburbs, and open areas, where they grew food for personal consumption or for sale in the nearest town. Today, however, in the 21st century, approximately 55% of the world’s population resides in cities. To put this in perspective, there are 47 mega-cities worldwide—cities with over 10 million residents (and often many more). Compared to global trends, the statistics in Israel are even more significant. According to a UN report on urbanization, approximately 68% of the country’s population will live in cities by 2050, representing 2.5 billion residents globally.

But will the city of tomorrow look like the city of yesterday? We already see today that the answer is no, with the proliferation of smart cities worldwide, including in Israel. These cities integrate Information and Communication Technologies (ICT) to improve the quality of life for their residents—by optimizing the quality and performance of municipal services, reducing costs, minimizing resource consumption, and above all, creating public engagement mechanisms.

Smart cities provide residents and visitors with several unique attractions and perks—such as free city-wide Wi-Fi. On one hand, such a Wi-Fi network sounds like a dream: internet everywhere, anytime, without cellular data charges. However, there is another implication that many may not consider. Many municipalities use public networks to collect data on resident locations and “hot zones” to determine crowded areas, using this information to recommend that users avoid them. On the surface, this is an innocent and appropriate exchange for a free service, but what happens when malicious actors connect to this network alongside “neutral” users?

Using public networks, whether provided by cafes, museums, or the municipality itself, exposes the user to Man-in-the-Middle (MiTM) attacks. These attacks are used by hackers to secretly eavesdrop on data the user discloses to a website or application—information that could be used for identity theft and performing actions in the user’s name.

Furthermore, many cities worldwide are networking their streets with security cameras that record urban activity. The reasons for these cameras vary—London, for example, is one of the most heavily surveilled cities, aiming to prevent crime and increase the personal security of residents and tourists. In Tel Aviv, security cameras are placed in public spaces, as well as cameras designed to document traffic violations, such as driving in public transportation lanes during restricted hours.

Despite the immense benefits, this is a double-edged sword. Here too, there is the potential to collect data on residents and visitors for more or less appropriate uses. For example, the city of Dubrovnik in Croatia—whose beautiful historical sites you likely saw in the hit “Game of Thrones”—suffers from a surge of tourists that exceeds its capacity and could harm the level of services provided to its residents. Therefore, the city utilizes a camera network that identifies faces and counts the number of people entering a specific site.

It should be noted that facial features are a unique characteristic of every individual, like a fingerprint; thus, a person’s facial image allows for a one-to-one identification if it can be cross-referenced with information on the internet or accessible databases. According to privacy protection laws, information regarding facial features is classified as “sensitive data” and is private property. In fact, under the European GDPR, individuals are given the right to request that data about them not be included in such databases.

Facial recognition technologies have advanced significantly recently. Today, algorithms can identify a person’s face based on an image fed into a computerized system, easily locating them if they are captured by a camera in a public space. Just as legitimate entities can do this, so too can malicious actors track an individual’s most current location to commit crimes against their property—ranging from simple pickpocketing and NFC-based credit card theft to breaking into their residence by finding their address in databases and networks.

Another topic gaining momentum in smart cities is transportation. Our definition of transportation is very intuitive—private vehicles, public transport, trains, buses, and taxis. However, few of us realize that the Ministry of Transport’s new reform, requiring passengers to use “Rav-Kav” cards based on NFC operations, is not sufficiently secured. Just as NFC-enabled credit card details can be stolen, the Rav-Kav card is vulnerable to the transfer of virtual money from an innocent passenger to a thief—stealing “Monthly Pass” value or accumulating small funds for trips, bit by bit, essentially accruing infinite free rides at our expense.

Generally, NFC-based services are vulnerable to hackers. If an attacker knows of an NFC-based service offered to city residents—for instance, gym equipment that uses NFC to track a trainee’s progress—they could replace the NFC chip and infect any mobile device that reads the chip with malware. Such malware could allow a hacker to track the trainee, connect to the phone’s camera, and gain access to everything stored on it—gallery, contacts, various correspondence, etc.

QR codes can also be used by criminals. A hacker can examine the data required from users in a specific application and use that to build a new, malicious QR code. For example, a hacker could generate a malicious QR code, replace the original one, and trick an innocent user into scanning it, providing a gateway for the hacker. QR-based products are designed to pull data required for the offered service (for example, hourly car rentals). By generating a fake QR code, a hacker can duplicate this data and transfer it to another vehicle belonging to the same company—so the innocent user pays twice: for their own vehicle and for the hacker’s vehicle.

In another layer of shared transportation, “micro-mobility” refers to the rental of bicycles and scooters scattered throughout the city for resident convenience. These platforms are used for short trips within the city but require users to pay by credit card and monitor location through an app that tracks the company’s property—justifiably so. We are not implying that these platforms are insufficiently secure, but rather that their existence poses a risk—as a sufficiently skilled attacker can always be found to exploit vulnerabilities in their design.

Progress cannot be stopped—the world we were born into is not the one we will leave behind. It is not advisable to stop progress, given the benefits it brings to medicine, communication, technology, and more. However, as with many other aspects of life, regarding smart cities and the fast, convenient, and innovative solutions they offer—smart and informed behavior is essential. Criminals’ abilities to disrupt our lives are evolving alongside the rest of the world; therefore, one must always stop and ask: Is the product or service presented to me reliable?

Remember: a public network is a public space in every sense and requires caution like any other public area—just as you are careful when crossing the road, as you hold your bag close in a crowded street, and as you would not give your home address to a stranger.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation