Researchers Gained Control of Some Kia Models Using License Plate Numbers and a Simple Hack

Chris Teague
by Chris Teague

New vehicles are becoming more and more connected, bringing features and technologies that felt like science fiction a few years ago. That level of connectivity comes with considerable risk, however, as cars connected to the internet in any way creates a potential for hacking. While many vulnerabilities require a high level of skill and knowledge to exploit, a team of researchers recently discovered a new, much easier method for gaining access to connected cars.

The team announced that it had found a flaw in one of Kia’s web portals that gave them access to connected features in most of the automaker’s newer vehicles. They were able to exploit the flaw using a custom app to target vehicles and said they could quickly use the cars’ license plates to gain access to their location and other controls. The team could also remotely lock and unlock vehicles, honk their horns, and start the ignition.


Researchers told Kia of the problem in June, and the automaker seems to have closed the hole. It’s the second such vulnerability found in Kia’s systems, but the company is far from the only one at risk. A while back, Toyota’s supplier portal was hacked, giving researchers access to user data and more.

For now, the most significant problems have been found and reported by researchers and people with good intentions, but hackers’ ability to target vehicles and drivers based on license plate numbers, which are publicly visible at any time, should be a wake-up call that more serious problems could be ahead.


[Images: Kia]


Become a TTAC insider. Get the latest news, features, TTAC takes, and everything else that gets to the truth about cars first by subscribing to our newsletter.

Chris Teague
Chris Teague

Chris grew up in, under, and around cars, but took the long way around to becoming an automotive writer. After a career in technology consulting and a trip through business school, Chris began writing about the automotive industry as a way to reconnect with his passion and get behind the wheel of a new car every week. He focuses on taking complex industry stories and making them digestible by any reader. Just don’t expect him to stay away from high-mileage Porsches.

More by Chris Teague

Comments
Join the conversation
2 of 4 comments
  • Blueice Without a spec sheet, this missive is far from complete andwould not warrant a further due diligence. There appears to be a limitedfield of view and nor mention the lack of a test drive duringnight conditions.
  • Bd2 No sympathy for the death of someone who would gladly put the public at risk for his own views. I hope it happens to more of these people especially the Hyundai ones.
  • FreedMike RIP
  • 28-Cars-Later KIA is the gift that keeps on giving, to car thieves.
  • Dave M. Sorry to hear this. Was he "creating content" when this happened? Interesting tidbit about leading the high speed chase in Texas.....
Next