There’s a new form of keyless car theft that works in under 2 minutes

Infrared image of a person jimmying open a vehicle.

Enlarge / Infrared image of a person jimmying open a vehicle.

Getty Images

When a London man discovered the front left-side bumper of his Toyota RAV4 torn off and the headlight partially dismantled not once but twice in three months last year, he suspected the acts were senseless vandalism. When the vehicle went missing a few days after the second incident, and a neighbor found their Toyota Land Cruiser gone shortly afterward, he discovered they were part of a new and sophisticated technique for performing keyless thefts.

It just so happened that the owner, Ian Tabor, is a cybersecurity researcher specializing in automobiles. While investigating how his RAV4 was taken, he stumbled on a new technique called CAN injection attacks.

The case of the malfunctioning CAN

Tabor began by poring over the “MyT” telematics system that Toyota uses to track vehicle anomalies known as DTCs (Diagnostic Trouble Codes). It turned out his vehicle had recorded many DTCs around the time of the theft.

The error codes showed that communication had been lost between the RAV4’s CAN—short for Controller Area Network—and the headlight’s Electronic Control Unit. These ECUs, as they’re abbreviated, are found in virtually all modern vehicles and are used to control a myriad of functions, including wipers, brakes, individual lights, and engine. Besides controlling the components, ECUs send status messages over the CAN to keep other ECUs apprised of current conditions.

This diagram maps out the CAN topology for the RAV4:

Diagram showing the CAN topology of the RAV4.

Diagram showing the CAN topology of the RAV4.

Ken Tindell

The DTCs showing that the RAV4’s left headlight lost contact with the CAN wasn’t particularly surprising, considering that the crooks had torn off the cables that connected it. More telling was the failure at the same time of many other ECUs, including those for the front cameras and the hybrid engine control. Taken together, these failures suggested not that the ECUs had failed but rather that the CAN bus had malfunctioned. That sent Taber searching for an explanation.

The researcher and theft victim next turned to crime forums on the dark web and YouTube videos discussing how to steal cars. He eventually found ads for what were labeled “emergency start” devices. Ostensibly, these devices were designed for use by owners or locksmiths to use when no key is available, but nothing was preventing their use by anyone else, including thieves. Taber bought a device advertised for starting various vehicles from Lexus and Toyota, including the RAV4. He then proceeded to reverse engineer it and, with help from friend and fellow automotive security expert Ken Tindell, figure out how it worked on the CAN of the RAV4.

Inside this JBL speaker lies a new form of attack

The research uncovered a form of keyless vehicle theft neither researcher had seen before. In the past, thieves found success using what’s known as a relay attack. These hacks amplify the signal between the car and the keyless entry fob used to unlock and start it. Keyless fobs typically only communicate over distances of a few feet. By placing a simple handheld radio device near the vehicle, thieves amplify the normally faint message that cars send. With enough amplification, the messages reach the nearby home or office where the key fob is located. When the fob responds with the cryptographic message that unlocks and starts the vehicle, the crook’s repeater relays it to the car. With that, the crook drives off.

“Now that people know how a relay attack works … car owners keep their keys in a metal box (blocking the radio message from the car) and some car makers now supply keys that go to sleep if motionless for a few minutes (and so won’t receive the radio message from the car),” Tindell wrote in a recent post. “Faced with this defeat but being unwilling to give up a lucrative activity, thieves moved to a new way around the security: bypassing the entire smart key system. They do this with a new attack: CAN Injection.”

Read More
Dan Goodin

Latest

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

Newsletter

Don't miss

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

2026 World Cup: Ex-Nigeria striker warns ‘tactically dull’ South Africa ahead of must-win Korea clash

Soccer South Africa head coach Hugo Broos. Copyright: Imago Former...

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID