Millions of Kia Vehicles Open to Remote Hacks via License Plate
ID: eea72edc-fb19-53a8-9955-bd026b5f4d03
STIX ID: report--eea72edc-fb19-53a8-9955-bd026b5f4d03
Feed Name: Dark Reading
Threat Score
Independent researchers discovered an API authentication flaw in Kia vehicles that let attackers register dealer accounts, obtain dealer API tokens, and, using just a vehicle's license-plate, execute remote commands (ignition, locks, lights, horn), obtain precise geolocation and owner PII across model years 2013–2025; a proof-of-concept demonstrated rapid exploitation and the issue was reportedly fixed in mid‑August following disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
