Millions of Cars Hacked (Again)

At DEF CON 33, a researcher showed how two API authentication flaws in a centralised dealer portal for a top automaker enabled national admin access across 1,000+ US dealers. With weak VIN/name lookups and broken enrolment/pairing, attackers could remotely unlock/start cars, track location, and even transfer ownership silently.

This video breaks down the attack path, why centralisation magnifies risk, and what owners and teams can do: lock down dealer workflows, remove weak lookups, and harden API auth.

// YouTube video REFERENCE //
You’re privacy and security nightmare: Your Privacy and Security Nightmare: Hacke…

// David’s Social //

================
Coect with me:
================
Discord: http://discord.davidbombal.com
X: https://www.x.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube Main Chael https://www.youtube.com/davidbombal
YouTube Tech Chael: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A
YouTube Clips Chael: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Shorts Chael: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg
Apple Podcast: https://davidbombal.wiki/applepodcast
Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ

================
Support me:
================
Or, buy my CCNA course and support me:
DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna
Udemy CCNA Course: https://bit.ly/ccnafor10dollars
GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10

// MY STUFF //
https://www.amazon.com/shop/davidbombal

// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

// MENU //
0:00 – Coming Up
0:13 – Another example from Defcon 2025

0:24 – Flaws found in a carmaker’s web portal

0:35 – What the hacker found
01:03 – The takeaway
01:21 – It’s ridiculous that cars are connected this way

01:36 – Doxxing from parking lot
03:56 – Phishing on the dealer’s dime
04:00 – Final takeaways

Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Disclaimer: This video is for educational purposes only.

#hack #carhack #api

subscribe
  • David Bombal