BitSight: a popular GPS vehicle tracker made by Shenzhen-based Micodus can be easily exploited to track and remotely cut the engines of at least 1M vehicles
Security vulnerabilities in a popular Chinese-built GPS vehicle tracker can be easily exploited to track and remotely cut the engines …
Context & Ripple Effects
This is the third time researchers have flagged the same failure mode in cheap consumer GPS trackers. In 2019, a hacker demonstrated he could access 27K accounts on the iTrack and ProTrack tracking services via weak default passwords and kill some users' engines; weeks later, other researchers urged a recall over a tracker used with children and the elderly that leaked real-time location and could remotely activate its microphone.
What changes now is scale and who is saying it: BitSight, a cyber-risk ratings firm whose findings feed corporate vendor assessments, documents exploitable flaws in a single Shenzhen-built Micodus model fitted to at least 1M vehicles — moving the issue from niche gadget reviews to something procurement and insurance buyers are likely to price in.
First-order effects
- Owners and fleet operators running Micodus MV720-class trackers face immediate exposure: their vehicles' locations are trackable and their engines can be remotely shut off while driving until patches or firmware updates ship.
- Micodus and the resellers bundling its hardware face pressure to push fixes, disclose credentials handling, and answer questions about why default-password behavior persists years after the iTrack and ProTrack engine-kill disclosures.
Second-order effects
- Fleet buyers and insurers that rely on aftermarket telematics gain leverage to demand security attestations before deployment, shifting cost toward vendors like Micodus and favoring trackers with audited firmware.
- The 2019 precedent of researchers calling for a recall of a vulnerable child/elderly tracker sets an obvious playbook here — if regulators or large fleet customers echo it, Micodus faces a recall-or-lose-contracts decision rather than a quiet patch cycle.
Third-order effects
- If the pattern holds — insecure-by-default trackers surfacing roughly every few years since 2015's OwnStar virtual-key attacks on BMW, Mercedes, and Chrysler apps — aftermarket vehicle hardware becomes a regulatory target, with minimum security requirements imposed on low-cost telematics imports.
- Engine-cut capability in commodity trackers normalizes remote vehicle control as an attack surface independent of the automakers' own systems, pushing the industry toward treating any device wired into a car's CAN bus as safety-critical infrastructure.
The trend: Cheap connected-vehicle hardware keeps shipping with trivially exploitable defaults, and each disclosure converts more fleet buyers and regulators from trusting vendor claims to demanding verified security.