logo

Kia dealer portal flaw could let attackers hack millions of cars

ID: 06aa790b-695a-5524-af29-7f4b09381b4c

STIX ID: report--06aa790b-695a-5524-af29-7f4b09381b4c

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Researchers disclosed critical flaws in Kia's dealer web portal that could allow someone with a registered dealer account to generate access tokens, pull vehicle owner PII (name, email, phone, address), add themselves as a second user, and remotely control millions of Kia vehicles made after 2013 (lock/unlock/start/locate/honk). The team built a demonstration showing an attacker could act within ~30 seconds; the issues were reportedly fixed and no evidence of malicious exploitation was found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.