Security researchers have found that GPS trackers meant to protect vehicles and children can be turned against their owners at scale. Vangelis Stykas and Felipe Solferini briefed their findings at Black Hat USA 2026 this week and will demo them again at DEF CON 34 on Saturday.
Using nothing more than a free account, with no device purchase required, the researchers say an attacker can silently wiretap a child’s watch, force video surveillance on, and remotely unlock and immobilize vehicles fitted with GPS trackers. The vehicle angle is the most dangerous: anti-theft trackers can locate, unlock, and shut down a car through unauthenticated API calls, and triggering fuel cutoff while the vehicle is moving creates a direct safety-of-life risk.
The scale is staggering. The research covers 36 million devices, with more than 76 brands across 50 countries funneling into just three platform families built in the Shenzhen ecosystem. The researchers found that 39 consumer brands in 20-plus countries all connect to the same backend server in China, meaning buyers who switch brands get no real security improvement. Hardcoded secrets shipped in downloadable apps make authentication largely cosmetic.
The team plans to release full proof-of-concept chains, CVE details, and a brand-to-backend mapping that shows how the industry actually works. For automakers, dealers, and fleet operators, the takeaway is that aftermarket trackers and dealer-installed anti-theft gear add an unmanaged attack surface to vehicles, with no single vendor under pressure to fix flaws that span dozens of white-label brands and multiple jurisdictions.