A dealership aftermarket alarm meant to protect cars has left millions of them easier to unlock and track. Researchers found that every KARR Security System unit since 2017 shares the same Bluetooth authentication key — and that key sits in plain text inside the KARR smartphone app.
Malwarebytes (July 23, 2026) covers work led by UC San Diego professor Aaron Schulman: roughly 2.2 million U.S. vehicles carry the hardware, installed mainly at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California. About half of owners do not know the device is present — dealers often install it before the sale, then pitch a subscription. Say no, and the hardware still stays.

Snapshot
| Field | Detail |
|---|---|
| Product | KARR Security System (Bluetooth aftermarket alarm) |
| Vendor | Acrisure Protection Group (SWDS / SouthWest Dealer Services lineage) |
| Researchers | UC San Diego (Aaron Schulman et al.) |
| Install base | ~2.2 million U.S. vehicles (research estimate) |
| Channel | Dealer install — SoCal Honda / Toyota / Mazda / Ford / Jeep called out |
| Core flaw | One shared auth key for all units; stored plaintext in the mobile app |
| Proximity impact | Within ~5 yards: unlock; disable ignition; no owner alert (brief beep / light flicker) |
| Tracking impact | Continuous BLE identifiers logged in crowdsourced radio DBs (e.g. WiGLE) |
| Disclosure → patch | Reported Jan 2025; firmware Jul 20, 2026 (~18 months) |
| Patch catch | Update ships via the KARR app — owners who never subscribed may never update |
Affected vehicles (dealer brands)
UC San Diego: most vulnerable cars were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 onward. The alarm is aftermarket KARR/SWDS hardware, not the OEM factory immobilizer — resale has carried units into other U.S. regions, Canada, and even Japan. Illustrations below are brand-channel cards (representative body styles), not an OEM recall VIN list.
| Dealer brand channel | What to look for |
|---|---|
| Honda | KARR / SWDS sticker on driver glass; under-dash blinking button |
| Toyota | Same sticker / button cues on lots that pre-install Acrisure protection |
| Mazda | Same — SoCal Mazda rooftops called out in coverage |
| Ford | Includes trucks and passenger vehicles sold through participating dealers |
| Jeep | Same SWDS/KARR channel; Chrysler/Dodge/Jeep rooftops also appeared in local reporting |





Second-hand buyers: if the car came from a SoCal franchise lot in the last decade, check for KARR/SWDS cues even if you never paid for monitoring.
How the attack works
| Step | What happens |
|---|---|
| 1. Shared secret | Attacker extracts the global Bluetooth auth key from the KARR app (or any compromised client). |
| 2. Approach | Stand within about five yards of a target vehicle with a KARR unit. |
| 3. Command | PoC tooling unlocks doors and can disable ignition — owner gets no push alert. |
| 4. Track | BLE IDs collected over years in public databases map historical parking patterns. |
| 5. Scale theater | Researchers demoed a “mayhem” mode that triggers horns/lights across many parked units at once. |
| 6. “Dormant” still counts | Units owners declined to subscribe still accept a Bluetooth wake and expose the same commands. |

Acrisure publicly framed real-world risk as low. Malwarebytes contrasts the ~18-month wait with Subaru’s STARLINK portal issues — fixed in about 24 hours after disclosure (see our companion post).
![]()
Why dealers — and FTC Safeguards shops — should care
KARR is sold through dealership F&I / protection channels. That puts the exposure next to finance, insurance binders, and customer PII already covered by the FTC Safeguards Rule for Texas auto dealers and by our dealer email audits:
| Related EmailMeNow coverage | Why it matters here |
|---|---|
| Major U.S. Auto Dealers | National dealer email / domain posture |
| California Auto Dealerships | Geography called out for KARR installs |
| Texas Auto Dealerships | Texas Safeguards + BEC-heavy finance threads |
| Auto Dealers vertical hub | Industry entry point for dealers running Instant Audits |
Hardware you install before delivery becomes your customer-trust problem when customers learn about it from a conference talk — not from the service desk.

What owners should do
| Check | Action |
|---|---|
| Window sticker | Look for KARR or SWDS on the driver-side glass |
| Under-dash button | Small button with a blinking light (per Malwarebytes / Wired guidance) |
| App update | Install the KARR app, connect, apply the July 20, 2026 firmware even if you never paid for monitoring |
| Stuck? | Call the selling dealer or KARR support — do not ignore “I declined the subscription” |
Independent cybersecurity audits
EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not Bluetooth radio design.
| Organization / role | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Parent brand (Acrisure) | acrisure.com | 78% | 75% | 45% | 87% | Good |
| Research coverage | malwarebytes.com | 72% | 90% | 45% | 45% | Good |
| OEM (Toyota) | toyota.com | 72% | 60% | 15% | 92% | Good |
| OEM (Ford) | ford.com | 58% | 65% | 15% | 37% | Average |
| KARR customer site | karrsecurity.com | 53% | 50% | 15% | 40% | Average |
| Acrisure Protection Group | acrisurepg.com | 53% | 50% | 15% | 40% | Average |
| Research lab | ucsd.edu | 52% | 50% | 15% | 37% | Average |
| OEM (Jeep) | jeep.com | 52% | 50% | 15% | 37% | Average |
| OEM (Honda) | honda.com | 42% | 25% | 15% | 37% | Below Average |
| OEM (Mazda USA) | mazdausa.com | 42% | 25% | 15% | 37% | Below Average |
| Crowdsource radio DB | wigle.net | 42% | 25% | 15% | 37% | Below Average |
Audit links: acrisure.com · malwarebytes.com · toyota.com · ford.com · karrsecurity.com · acrisurepg.com · ucsd.edu · jeep.com · honda.com · mazdausa.com · wigle.net
Pattern: Most OEM and dealer-adjacent domains in this set sit at 15% transport — the recurring gap that makes spoofed “update your alarm” / “recall firmware” mail easier to deliver beside a hardware story customers already distrust. Acrisure.com leads at 78%, still 22 points under the 100% ideal. KARR and Acrisure Protection Group land at 53% with soft transport.
Website stack note
Passive website-tech probes on July 29, 2026:
karrsecurity.com— Drupal 7 detected (latest public train referenced 11.4.4 at probe time) — far behind current major versions.acrisurepg.com— Drupal with PHP 7.4.33 (EOL since Nov 28, 2022) and jQuery 1.10.2 cues called out as outdated.- Other probed story domains in this set did not surface notable CMS/PHP/TLS aging bullets in the same pass.
Hidden or outdated stacks on alarm vendor marketing sites do not cause the shared Bluetooth key — but they are a poor look when customers are hunting for a trustworthy firmware path.
Priority actions
- Dealers: Inventory which lots still pre-install KARR/SWDS; script customer outreach so the app + firmware path is not left to a DEF CON headline.
- Owners: Check glass + under-dash cues; update firmware even if you never subscribed.
- Security / MSP for dealer groups: Treat spoofed “Acrisure / KARR update” mail as high-risk while news circulates; enforce DMARC and callback procedures on F&I vendors (FTC Safeguards dealer guide).
- Compare OEM lessons: Fast portal patches (Subaru STARLINK) vs slow aftermarket firmware reach — see Subaru STARLINK admin takeover.
Related trackers
- Subaru STARLINK admin-portal takeover
- California auto dealership email security
- National auto dealers email security
- Texas auto dealership email security
- FTC Safeguards Rule for Texas auto dealers
- Auto dealers industry hub
Sources: Malwarebytes · KARR Security · Acrisure Protection Group