logo

Millions of Kia vehicles were vulnerable to remote attacks with just a license plate number

ID: 0cd710d2-8c69-5c13-80f9-26551f21a02d

STIX ID: report--0cd710d2-8c69-5c13-80f9-26551f21a02d

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2024-09-27

Date Updated: 2026-04-28

...
...

In June 2024 security researchers found vulnerabilities in the Kia dealer portal that allowed creation of fraudulent dealer accounts, access to customer PII, and reassignment of vehicle primary owners by converting license plates to VINs via a third-party API, enabling remote control of vehicles (lock/unlock, start/stop, locate, honk); the researchers produced a proof-of-concept tool, responsibly disclosed the issues to Kia, and Kia has since remediated the vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.