CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Researchers find 36 million GPS trackers open to vehicle theft

Black Hat and DEF CON researchers show how free accounts on GPS tracker platforms can unlock and immobilize vehicles at scale.

CarThreat Staff
Last updated: August 6, 2026 8:55 pm
By
ctadmin
2 Min Read
SHARE

Security researchers have found that GPS trackers meant to protect vehicles and children can be turned against their owners at scale. Vangelis Stykas and Felipe Solferini briefed their findings at Black Hat USA 2026 this week and will demo them again at DEF CON 34 on Saturday.

Using nothing more than a free account, with no device purchase required, the researchers say an attacker can silently wiretap a child’s watch, force video surveillance on, and remotely unlock and immobilize vehicles fitted with GPS trackers. The vehicle angle is the most dangerous: anti-theft trackers can locate, unlock, and shut down a car through unauthenticated API calls, and triggering fuel cutoff while the vehicle is moving creates a direct safety-of-life risk.

The scale is staggering. The research covers 36 million devices, with more than 76 brands across 50 countries funneling into just three platform families built in the Shenzhen ecosystem. The researchers found that 39 consumer brands in 20-plus countries all connect to the same backend server in China, meaning buyers who switch brands get no real security improvement. Hardcoded secrets shipped in downloadable apps make authentication largely cosmetic.

The team plans to release full proof-of-concept chains, CVE details, and a brand-to-backend mapping that shows how the industry actually works. For automakers, dealers, and fleet operators, the takeaway is that aftermarket trackers and dealer-installed anti-theft gear add an unmanaged attack surface to vehicles, with no single vendor under pressure to fix flaws that span dozens of white-label brands and multiple jurisdictions.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Aftermarket DevicesAPI SecurityConnected VehiclesDEF CONGPS TrackersThreat IntelligenceVehicle TheftVulnerabilities
SOURCES:Black Hat USA 2026 BriefingsDEF CON 34 Main Stage Talks
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Vector Solectrix Collaboration Targets ADAS and Autonomous Driving Validation

By
ctadmin
May 22, 2026
Cybersecurity

Quantum-safe update handshake keeps low-power ECUs safe on the road

By
ctadmin
August 12, 2026
Cybersecurity

ECARX and TPK Partner on ORCA LiDAR Platform Targeting ADAS and Robotaxi Security

By
ctadmin
May 30, 2026
Cybersecurity

Volkswagen Golf EV Delayed Again as SSP Software Platform Stalls

By
ctadmin
May 26, 2026
Cybersecurity

Uber and Wayve Launch London Robotaxi Service with Mapless AI System

By
ctadmin
June 12, 2026
Cybersecurity

BYD’s New In-House Chip Reshapes Self-Driving Compute Strategy

By
ctadmin
May 30, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?