Blog

Hacking Cars Remotely With VIN Number

As cars become more connected, they become vulnerable to cyberattacks that could have devastating results for drivers. Security researcher Sam Curry has identified flaws that allow hackers for hacking cars remotely with VIN number. This allow them to remotely unlock, start, flash headlights and honk vehicles, which is visible on most vehicle windshields. SiriusXM Security […]
PX
Propelex team April 16, 2023 - 7 minutes read

As cars become more connected, they become vulnerable to cyberattacks that could have devastating results for drivers. Security researcher Sam Curry has identified flaws that allow hackers for hacking cars remotely with VIN number. This allow them to remotely unlock, start, flash headlights and honk vehicles, which is visible on most vehicle windshields.

SiriusXM

Security researcher Sam Curry has discovered a vulnerability in the SiriusXM Connected Vehicle Services telematics platform. He and his team were able to remotely unlock and start a vehicle.

SiriusXM powers many cars’ telematics and infotainment systems, including Acura, Honda, Hyundai, Infiniti, Nissan, Subaru, Toyota and Jaguar. Its platforms can collect personal data about a vehicle as well as remotely lock or unlock its door and start the engine.

Sam Curry, a white hat security researcher, recently identified an exploit in SiriusXM Connected Vehicle Services that allows someone to remotely unlock and start any car with just its VIN number. All they had to do was scan a vehicle’s VIN with their phone and send requests through the SiriusXM app for running commands such as unlocking or starting its engine.

This is a serious matter that could be used against you to steal your identity. In 2017, hackers exposed the personal details of more than 10 million U.S. car owners through an extensive leak of VIN numbers and other vehicle identification details.

SiriusXM reports they’ve identified and corrected the flaw, notifying all affected automakers of its existence. Furthermore, patches have been released for both their fleet management and digital license plate service Spireon as well as SiriusXM itself.

While these fixes are welcome, it’s essential to remember that Curry only identified vulnerabilities in vehicles with active SiriusXM telematics subscriptions. That means a malicious actor could have accessed a Nissan, Infiniti or Honda with just their VIN number and issued remote commands to locate, unlock and start their vehicle as well as flash its headlights and honk the horn.

The issue is that the telematics system utilizes the VIN number to authorize commands and grab user profiles, giving anyone with knowledge of it access to a full suite of personal information about the driver – including their name, address and phone number. This data could then be exploited by cybercriminals for illicit entry onto public roads.

Curry shared on Twitter the steps his team used to discover the vulnerability in SiriusXM’s telematics platform. They first identified that they needed to send an HTTP request to a domain used by SiriusXM when enrolling cars into its remote management service; these requests included the VIN number, which can typically be seen on cars’ windshields or other parts.

They were also able to control the steering of the vehicle.

Two security researchers are alerting about the growing danger of car hacking. They’ve noted that all modern vehicles use “Electronic Control Units,” or small computers, which allow them to perform various functions from heated seats to emergency crash avoidance.

Electronic Control Units (ECUs) can be easily compromised and used for malicious purposes, such as controlling brakes, steering and acceleration. Because ECUs are connected via a network that requires little authentication, hackers have the potential to gain access to vehicles’ systems without physical presence.

Miller and Valasek needed to connect their laptop to the car’s CAN bus in order to remotely access the ECUs. Once done, they could send various commands directly to the vehicle, overriding any instructions from the driver.

They could, for instance, turn the parking brake on or off. Furthermore, they had the capability of flashing headlights on and off as well as changing the radio station. Furthermore, they could track the GPS location of a car using special software.

Researchers hope their findings will prompt manufacturers to take these threats seriously. They’ve received an $80,000 grant from the US government to research these vulnerabilities and plan to present their findings at Def Con hacker conference in Las Vegas this summer.

One of the most alarming aspects of this hack is that it allows a remote attacker to completely disable a car’s brakes, leaving drivers helpless and unable to stop their vehicle. They’ve demonstrated this by cutting brakes on a Jeep while it was moving, causing it to slide uncontrollably into an embankment.

The team was able to achieve this by reversing the firmware of Jeep’s engine control unit. Doing so allowed them to inject fake CAN messages into the car, overriding steering and braking commands from the driver.

This year’s experiment has made significant improvements, and it could have a major effect on car safety. If so, it will likely be an innovation breakthrough for the automotive industry and serve as a wake-up call to drivers around the world.

They were able to disable the brakes.

Hackers have the potential to disable your car’s engine, control its steering or brakes, and even open and close its doors – potentially dangerous if there’s been an accident.

A car’s VIN, or vehicle identification number, is a set of three numbers that uniquely identify its make and model. The first two digits identify the manufacturer while the third differentiates models within that same manufacturer.

Cybersecurity researchers Charlie Miller and Chris Valasek previously discovered a way to remotely hijack a Jeep by using its VIN number to hack into its steering system and brake pedal. Now, they’ve devised another method which allows them to do this while the cars are in motion – without physical access to the car itself.

The researchers utilized an OBD II dongle to connect their vehicle’s computer systems. These devices, commonly used in service stations, connect to a car’s CAN bus–a software-hardware protocol that enables its various computer systems to exchange information with one another.

They gained root shell access on the car’s telematics control unit (TCU) by fiddling with its file system. This granted them command line privilege at the highest possible level, enabling them to disable brakes and drive at much faster speeds than usual.

Another way hackers can infiltrate a car is by altering its radio station or GPS destination without the driver knowing. While this may cause some inconvenience for the driver, hackers have the capability to accomplish this without detection.

Hackers may take control of air conditioning, radio or windshield wipers and adjust them according to their preference. This could be done for many reasons – including to distract the driver.

As vehicles become more interconnected, they become more susceptible to hacks and other types of cyberattacks. Therefore, it is essential that your vehicle’s security system remain up-to-date.

They were able to flash the headlights.

Cybersecurity researcher Sam Curry has recently discovered a way to remotely hack cars using just their VIN number. With this method, his team was able to unlock, start, honk, locate and flash the headlights of vehicles without needing access to login credentials. This trick was discovered in several automotivemaker applications such as Nissan, Honda, Infiniti and Acura’s respective remote car apps.

These car apps provide drivers with a convenient way to manage their vehicles from their phone. They allow users to lock, unlock, start and locate their vehicles through an app on their smartphone – typically for free. But be mindful: if you don’t take precautions beforehand, you could unwittingly grant hackers or criminals access to your personal information.

As technology develops, there will always be potential vulnerabilities to exploit. This is especially true for the automobile industry where hackers constantly search for ways to take advantage of new advances and stay one step ahead of law enforcement.

This week, security researchers discovered a vulnerability that allowed them to remotely unlock and start Nissan, Infiniti, Honda and Acura vehicles with just their VIN numbers. This was possible through SiriusXM’s Connected Vehicle Services telematics platform and retrieve data from these cars.

They could still send commands to these cars even if they weren’t active subscribers. All that was necessary for this was knowing the VIN of these vehicles – usually visible through the windshield.

Researchers were able to access this data for all the above-listed manufacturers, even those who had previously uninstalled or stopped using these apps. They identified this flaw by back-engineering these applications and discovering where the VIN was stored on each device.

These hacking techniques are similar to those employed by auto thieves in the past, who would smash windows and hotwire a car to take it. The only difference is that hackers now have access to computers through laptops and remote connections on their vehicles.

Work with Propelex

Ready to build AI
into your stack?

Propelex helps teams evaluate, integrate, and scale AI workflows — from MCP strategy to full agentic architecture. Let's find the right entry point for your organization.