Hacker says he can access 27K user accounts of GPS tracking services iTrack and ProTrack, which had weak default passwords, and can kill some users' car engines
Lorenzo Franceschi-Bicchierai / Motherboard :
Context & Ripple Effects
This report slots into a long-running pattern of connected-vehicle exposure: back in 2015 the OwnStar attack grabbed virtual keys of BMW, Mercedes, and Chrysler cars through a mobile app, and this year alone researchers have surfaced an unsecured Honda database with 134M rows that could aid system compromise. The common thread is that telematics features ship faster than their security.
What makes the iTrack and ProTrack disclosure distinct is scale plus physical consequence: a single researcher claims access to 27K user accounts on two consumer GPS tracking services, secured by nothing more than weak default passwords — and with the ability to remotely cut some engines. Three years later, BitSight found the same playbook still worked against Shenzhen-based Micodus's tracker, exposing at least 1M vehicles to tracking and engine cutoff.
First-order effects
- Roughly 27K iTrack and ProTrack users face immediate risk of location tracking, account takeover, and in some cases remote engine shutdown while driving; both vendors' first move must be forcing credential resets beyond the weak defaults.
Second-order effects
- Fleet operators and resellers who bundle these low-cost trackers into anti-theft or insurance products inherit the liability, pressuring the vendors to certify devices before deployment — a dynamic BitSight's later Micodus findings show was not resolved across the tracker market.
Third-order effects
- If default-password telematics keep surfacing, regulators and automakers will treat third-party aftermarket trackers as part of vehicle attack surface: the 2023 discovery of API flaws across nearly 20 carmakers' systems points toward connected-car security becoming a compliance requirement rather than a vendor afterthought.
The trend: Vehicle telematics is consolidating from a patchwork of insecure aftermarket gadgets and APIs into a regulated attack surface where default credentials and unauthenticated commands become unacceptable.