logo

Millions of Kia Vehicles Open to Remote Hacks via License Plate

ID: eea72edc-fb19-53a8-9955-bd026b5f4d03

STIX ID: report--eea72edc-fb19-53a8-9955-bd026b5f4d03

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-27

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Independent researchers discovered an API authentication flaw in Kia vehicles that let attackers register dealer accounts, obtain dealer API tokens, and, using just a vehicle's license-plate, execute remote commands (ignition, locks, lights, horn), obtain precise geolocation and owner PII across model years 2013–2025; a proof-of-concept demonstrated rapid exploitation and the issue was reportedly fixed in mid‑August following disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.