A vehicle identification number, the 17-character code stamped on every car, can become the seed for a surveillance chain that ends in physical tracking. That is the argument of VIN2VICTIM, a research pipeline presented at VehicleSec ’26 in Baltimore by Hannaneh Pasandi of UC Berkeley and Mohammad Sepahi of Rivian.
The attack runs in four stages. First the owner is deanonymized from the VIN, then their driving traces are reidentified in location data, then home and workplace are inferred, and finally departure times are predicted.
The enabler is the telematics data trade. Connected vehicles stream GPS positions to manufacturers, and those companies routinely sell the records to data brokers, where the researchers say the information loses its link to consent.
Their experiments on public GPS traces show how strong the chain is. Two spatio-temporal points re-identified 96 to 99 percent of taxi traces and 82 percent of personal traces. Home clusters emerged for 92 to 100 percent of users, and the pipeline kept working even when location samples were thinned to one per hour.
The authors argue VINs make cars worse privacy devices than phones. A VIN never changes, consent is coarse and vehicle-scoped, and the number bridges the digital and physical worlds. The researchers also note the attack resists some protections: even geo-indistinguishability at low epsilon preserved 74 to 78 percent unicity.