CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

One VIN number can unlock years of driver tracking

A single VIN can seed a pipeline that re-identifies a driver's traces and pinpoints home and work.

CarThreat Staff
Last updated: August 9, 2026 10:43 pm
By
ctadmin
2 Min Read
One VIN number can unlock years of driver tracking
SHARE

A vehicle identification number, the 17-character code stamped on every car, can become the seed for a surveillance chain that ends in physical tracking. That is the argument of VIN2VICTIM, a research pipeline presented at VehicleSec ’26 in Baltimore by Hannaneh Pasandi of UC Berkeley and Mohammad Sepahi of Rivian.

The attack runs in four stages. First the owner is deanonymized from the VIN, then their driving traces are reidentified in location data, then home and workplace are inferred, and finally departure times are predicted.

The enabler is the telematics data trade. Connected vehicles stream GPS positions to manufacturers, and those companies routinely sell the records to data brokers, where the researchers say the information loses its link to consent.

Their experiments on public GPS traces show how strong the chain is. Two spatio-temporal points re-identified 96 to 99 percent of taxi traces and 82 percent of personal traces. Home clusters emerged for 92 to 100 percent of users, and the pipeline kept working even when location samples were thinned to one per hour.

The authors argue VINs make cars worse privacy devices than phones. A VIN never changes, consent is coarse and vehicle-scoped, and the number bridges the digital and physical worlds. The researchers also note the attack resists some protections: even geo-indistinguishability at low epsilon preserved 74 to 78 percent unicity.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityData PrivacyTelematics Control Units (TCU)Threat IntelligenceVulnerabilities
SOURCES:USENIX VehicleSec '26
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Developer workstation showing code analysis for QNX embedded systems
Cybersecurity

Unlocking QNX IFS Images for Binary Whitelisting in Automotive Embedded Systems

By
ctadmin
May 25, 2026
Cybersecurity

Vehicles are getting their own offline AI brain thanks to FEV and Microsoft

By
ctadmin
July 12, 2026
Cybersecurity

Believ and UrbanChain Deliver Verified Local Renewable Power to EV Chargers

By
ctadmin
June 17, 2026
Cybersecurity

Repeated patterns hijack depth readings of car stereo cameras

By
ctadmin
August 13, 2026
Cybersecurity

Camouflaged patches can hide traffic lights from self-driving cars

By
ctadmin
August 13, 2026
Cybersecurity

Deterministic ECU Protection: Preventing Exploits Without Redesigning CAN Bus Communication

By
ctadmin
May 22, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?