Most business owners think about vehicle security in terms of theft or break-ins. A recent discovery shows that digital threats can also put company cars at risk. Security researchers at UC San Diego uncovered a flaw that leaves cars vulnerable to Bluetooth hijacking.
Certain dealer-installed anti-theft and tracking devices have a serious vulnerability that could allow someone to unlock doors or even immobilize the engine from a Bluetooth connection up to five yards away. While the issue doesn’t affect every vehicle on the road, it’s an important reminder that modern Bluetooth vehicle security can introduce risks when left unprotected.
A Security Problem Created by a Security Feature
Since 2017, auto dealerships in Southern California have installed KARR and SWDS automotive security systems sold by SWDS/Acrisure. These help with theft recovery and vehicle tracking and allow users to secure their cars via a smartphone app.
The concern starts with how these systems were built. Every device shares common credentials, which allows hackers to exploit the technology if they gain access. A nearby attacker could use Bluetooth to interact with affected systems, potentially unlocking a vehicle and gaining additional control over certain functions.
The researchers also identified a publicly accessible database containing information about vehicles equipped with these devices, which could allow a hacker to target a specific vehicle.
Although Southern California dealerships originally installed the systems, used vehicles have since been sold across the country and even overseas, meaning cars vulnerable to Bluetooth hijacking are no longer limited to one region.
Why This Could Put Your Company at Risk
For companies that rely on fleet vehicles, even a single compromised car can create headaches. A disabled vehicle can disrupt deliveries or leave tools and equipment exposed.
The problem also points to a larger challenge facing connected vehicles: Every new digital feature can create new vehicle cybersecurity vulnerabilities. Modern vehicles contain connected technology that expands the number of potential entry points for cybercriminals. Keyless entry systems and automotive security systems were built to help combat theft, but they also created the risk of unauthorized remote digital access. Vehicle cybersecurity vulnerabilities tend to fly under the radar because most drivers assume aftermarket security add-ons make them safer, not more exposed.
Simple Ways to Lower the Risk
Not every vehicle with a Bluetooth-enabled security device is automatically at risk of theft, but taking a few practical precautions can make a meaningful difference in preventing Bluetooth hijacking attacks.
Start by checking company vehicles for KARR or SWDS stickers (usually found on the driver’s window) indicating they have one of the affected systems, then confirming whether affected systems have received the available firmware update. It is also worth reviewing vendor security practices and making sure the people responsible for IT or fleet management understand the potential risks.
The days when cybersecurity only meant protecting laptops and email accounts are over. Connecting to apps and digital systems is convenient, but with cars vulnerable to Bluetooth hijacking, businesses need to think about cars as part of their overall security strategy.

