EPISODE · Jul 15, 2026 · 35 MIN
Your License Plate Is the Password: What the Kia API Hack Revealed
from Cybersecurity Under Pressure. Real Attacks, Real Lessons · host Antonio Gonzalez
A modern vehicle can have secure boot, encrypted communications and protected ECUs, yet remain exposed through a dealer website.In this episode, we examine an automotive cybersecurity case where researchers began with a public identifier, a vehicle’s license plate, and built an attack chain capable of reaching personal data, vehicle location and remote functions.The compromise did not begin inside the vehicle. It began in the cloud.A license plate was converted into a VIN. A dealer-facing portal trusted the wrong identity. Excessive backend privileges allowed vehicle ownership to be reassigned. Legitimate APIs then delivered commands that the vehicle accepted as authorized.This episode explores why:• License plates and VINs are identifiers, not authentication factors• Dealer and after-sales portals form part of the vehicle attack surface• Weak API authorization can create cyber-physical consequences• Excessive privileges turn a local web flaw into systemic fleet risk• Automotive threat analysis must include cloud, mobile and business systems• OEMs need stronger ownership controls, dealer authentication and behavioral detectionThe main lesson is uncomfortable but necessary: the security boundary of a connected vehicle does not end at the CAN bus or the telematics unit.It extends to every portal, API and support process capable of issuing a trusted command.Cybersecurity Under Pressure. Real Attacks, Real Lessons.
Embed this episode
Ready to play
Your License Plate Is the Password: What the Kia API Hack Revealed
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.