logo

More Of The Shame: Software Flaw Exposes Millions of Subarus, Rivers of Driver Data

ID: 2773088d-825f-5134-9462-c5c8f41bcd95

STIX ID: report--2773088d-825f-5134-9462-c5c8f41bcd95

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2025-01-26

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

A now-patched vulnerability in Subaru's STARLINK telematics backend (subarucs.com) allowed researchers to reset employee passwords and access customer records, enabling retrieval of a year of precise vehicle location history, PII (emergency contacts, billing, addresses), and remote control actions (lock/unlock, start/stop) for affected vehicles; the flaw was found by security researchers using public-facing employee applications and simple discovery/brute-force techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.