Millions of Kia vehicles were vulnerable to remote attacks with just a license plate
by YourJob - Monday September 30, 2024 at 12:35 AM
#1
Millions of Kia vehicles were vulnerable to remote attacks with just a license plate

In June of 2024 security researchers uncovered a set of vulnerabilities in the Kia dealer portal that allowed them to remotely take over any Kia vehicle built after 2013—and all they needed was a license plate number.
According to the researchers:
“These attacks could be executed remotely on any hardware-equipped vehicle in about 30 seconds, regardless of whether it had an active Kia Connect subscription.”
How was this possible?
First, it’s important to understand that the Kia “dealer portal” is where authorized Kia dealers can match customer accounts with the VIN number of their new car. For the customer accounts, Kia would ask the buyer for their email address at the dealership and send a registration link to that address where the customer could either set up a new Kia account or add their newly purchased vehicle to an existing Kia account.
The researchers found out that by sending a specially crafted request they could create a dealer account for themselves. After some more manipulation they were able to access all dealer endpoints which gave them access to customer data like names, phone numbers, and email addresses.
As the new “dealer,” the security researchers were also able to search by Vehicle Identification Number (VIN) number, which is a unique identifier for a vehicle. With the VIN number and the email address of the rightful owner, the researchers were able to demote the owner of the vehicle so that they could add themselves as the primary account holders.
Unfortunately, the rightful owner would not receive any notification that their vehicle had been accessed nor their access permissions modified.
But to find the VIN number of a car you’ll need physical access to the vehicle, right? Not entirely.
In several countries, including the US and the UK, there are vehicle databases that you can query to provide you with a VIN number based on the license plate number. The researchers used a third-party API to convert the license plate number to a VIN.
Depending on the vehicle and whether Kia Connect was active, the primary account holder is able to remotely lock/unlock, start/stop, honk, and locate the vehicle.
The researchers created a proof-of-concept tool where they could enter the license plate and in two steps they could retrieve the owner’s personal information, and then execute remote commands on the vehicle.
 
https://www.malwarebytes.com/blog/news/2...ate-number
Reply
#2
Sam Curry always comes up with something special.
Reply
#3
Best deterrent against modern car thieves: Find a car with a fucking manual transmission, people these days can not drive stick!

My local news had these gen-Z car thieves on this guys security camera, they opened this man's garage and had his sports car turned on faster than a cat can lick its own ass....
They pushed it into the driveway and kept fucking stalling out trying to get it into 1st so they ran off; my god it was sad to watch.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Scattered Spider has a new Telegram channel to list its attacks lulagain 0 41 6 hours ago
Last Post: lulagain
  Google suffers data breach in ongoing Salesforce data theft attacks by the @ShinyHunt lulagain 1 171 08-07-2025, 10:19 PM
Last Post: Inexorable_Baer
  Pandora confirms data breach amid ongoing Salesforce data theft attacks lulagain 0 116 08-07-2025, 10:11 PM
Last Post: lulagain
  ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH lulagain 3 398 08-04-2025, 08:25 AM
Last Post: odin6699
  AI-powered Cursor IDE vulnerable to prompt-injection attacks lulagain 0 221 08-01-2025, 07:18 PM
Last Post: lulagain

Forum Jump:


 Users browsing this thread: