Back to news
Cybersecurity Alert
July 29, 2026 by EmailMeNow IT Consulting

Dealer-Installed KARR Alarms Left Millions of Cars Unlockable Over Shared Bluetooth Keys

UC San Diego found every KARR Security System since 2017 shares one plaintext Bluetooth auth key. ~2.2M U.S. cars — many via SoCal Honda/Toyota/Mazda/Ford/Jeep dealers — can be unlocked nearby and tracked via WiGLE. Domain audits (ideal 100%): acrisure.com 78%, karrsecurity.com 53%; none reach 100%.

Source: Malwarebytes

NewsAuto DealersConnected CarsBluetoothAutomotiveFTC SafeguardsCybersecurity
Dealership lot car with aftermarket alarm sticker and shared Bluetooth unlock risk highlighted

A dealership aftermarket alarm meant to protect cars has left millions of them easier to unlock and track. Researchers found that every KARR Security System unit since 2017 shares the same Bluetooth authentication key — and that key sits in plain text inside the KARR smartphone app.

Malwarebytes (July 23, 2026) covers work led by UC San Diego professor Aaron Schulman: roughly 2.2 million U.S. vehicles carry the hardware, installed mainly at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California. About half of owners do not know the device is present — dealers often install it before the sale, then pitch a subscription. Say no, and the hardware still stays.

Dealership lot car with aftermarket alarm sticker and shared Bluetooth unlock risk highlighted

Snapshot

FieldDetail
ProductKARR Security System (Bluetooth aftermarket alarm)
VendorAcrisure Protection Group (SWDS / SouthWest Dealer Services lineage)
ResearchersUC San Diego (Aaron Schulman et al.)
Install base~2.2 million U.S. vehicles (research estimate)
ChannelDealer install — SoCal Honda / Toyota / Mazda / Ford / Jeep called out
Core flawOne shared auth key for all units; stored plaintext in the mobile app
Proximity impactWithin ~5 yards: unlock; disable ignition; no owner alert (brief beep / light flicker)
Tracking impactContinuous BLE identifiers logged in crowdsourced radio DBs (e.g. WiGLE)
Disclosure → patchReported Jan 2025; firmware Jul 20, 2026 (~18 months)
Patch catchUpdate ships via the KARR app — owners who never subscribed may never update

Affected vehicles (dealer brands)

UC San Diego: most vulnerable cars were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 onward. The alarm is aftermarket KARR/SWDS hardware, not the OEM factory immobilizer — resale has carried units into other U.S. regions, Canada, and even Japan. Illustrations below are brand-channel cards (representative body styles), not an OEM recall VIN list.

Dealer brand channelWhat to look for
HondaKARR / SWDS sticker on driver glass; under-dash blinking button
ToyotaSame sticker / button cues on lots that pre-install Acrisure protection
MazdaSame — SoCal Mazda rooftops called out in coverage
FordIncludes trucks and passenger vehicles sold through participating dealers
JeepSame SWDS/KARR channel; Chrysler/Dodge/Jeep rooftops also appeared in local reporting

Representative Honda-style compact sedan with aftermarket Bluetooth unlock risk highlighted

Honda SoCal Honda dealers are among the primary install channels named by UC San Diego.

Representative Toyota-style sedan with aftermarket Bluetooth unlock risk highlighted

Toyota Toyota rooftops in Southern California account for a large share of identified installs.

Representative Mazda-style crossover with aftermarket Bluetooth unlock risk highlighted

Mazda Mazda dealerships are explicitly listed in the UC San Diego dealer set.

Representative Ford-style pickup with aftermarket Bluetooth unlock risk highlighted

Ford Ford sellers (cars and trucks) appear in the same SoCal dealer pattern.

Representative Jeep-style SUV with aftermarket Bluetooth unlock risk highlighted

Jeep Jeep (and related FCA rooftops in local follow-ups) round out the named channels.

Second-hand buyers: if the car came from a SoCal franchise lot in the last decade, check for KARR/SWDS cues even if you never paid for monitoring.

How the attack works

StepWhat happens
1. Shared secretAttacker extracts the global Bluetooth auth key from the KARR app (or any compromised client).
2. ApproachStand within about five yards of a target vehicle with a KARR unit.
3. CommandPoC tooling unlocks doors and can disable ignition — owner gets no push alert.
4. TrackBLE IDs collected over years in public databases map historical parking patterns.
5. Scale theaterResearchers demoed a “mayhem” mode that triggers horns/lights across many parked units at once.
6. “Dormant” still countsUnits owners declined to subscribe still accept a Bluetooth wake and expose the same commands.

Nearby Bluetooth attacker unlocking a parked car with shared aftermarket alarm keys

Acrisure publicly framed real-world risk as low. Malwarebytes contrasts the ~18-month wait with Subaru’s STARLINK portal issues — fixed in about 24 hours after disclosure (see our companion post).

Crowdsourced radio map tracing historical parking of cars broadcasting alarm identifiers

Why dealers — and FTC Safeguards shops — should care

KARR is sold through dealership F&I / protection channels. That puts the exposure next to finance, insurance binders, and customer PII already covered by the FTC Safeguards Rule for Texas auto dealers and by our dealer email audits:

Related EmailMeNow coverageWhy it matters here
Major U.S. Auto DealersNational dealer email / domain posture
California Auto DealershipsGeography called out for KARR installs
Texas Auto DealershipsTexas Safeguards + BEC-heavy finance threads
Auto Dealers vertical hubIndustry entry point for dealers running Instant Audits

Hardware you install before delivery becomes your customer-trust problem when customers learn about it from a conference talk — not from the service desk.

18-month firmware wait versus 24-hour OEM portal fix timeline comparison

What owners should do

CheckAction
Window stickerLook for KARR or SWDS on the driver-side glass
Under-dash buttonSmall button with a blinking light (per Malwarebytes / Wired guidance)
App updateInstall the KARR app, connect, apply the July 20, 2026 firmware even if you never paid for monitoring
Stuck?Call the selling dealer or KARR support — do not ignore “I declined the subscription”

Independent cybersecurity audits

EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not Bluetooth radio design.

Organization / roleDomainOverallIdentityTransportWebsiteRisk
Parent brand (Acrisure)acrisure.com78%75%45%87%Good
Research coveragemalwarebytes.com72%90%45%45%Good
OEM (Toyota)toyota.com72%60%15%92%Good
OEM (Ford)ford.com58%65%15%37%Average
KARR customer sitekarrsecurity.com53%50%15%40%Average
Acrisure Protection Groupacrisurepg.com53%50%15%40%Average
Research labucsd.edu52%50%15%37%Average
OEM (Jeep)jeep.com52%50%15%37%Average
OEM (Honda)honda.com42%25%15%37%Below Average
OEM (Mazda USA)mazdausa.com42%25%15%37%Below Average
Crowdsource radio DBwigle.net42%25%15%37%Below Average

Audit links: acrisure.com · malwarebytes.com · toyota.com · ford.com · karrsecurity.com · acrisurepg.com · ucsd.edu · jeep.com · honda.com · mazdausa.com · wigle.net

Pattern: Most OEM and dealer-adjacent domains in this set sit at 15% transport — the recurring gap that makes spoofed “update your alarm” / “recall firmware” mail easier to deliver beside a hardware story customers already distrust. Acrisure.com leads at 78%, still 22 points under the 100% ideal. KARR and Acrisure Protection Group land at 53% with soft transport.

Website stack note

Passive website-tech probes on July 29, 2026:

  • karrsecurity.comDrupal 7 detected (latest public train referenced 11.4.4 at probe time) — far behind current major versions.
  • acrisurepg.comDrupal with PHP 7.4.33 (EOL since Nov 28, 2022) and jQuery 1.10.2 cues called out as outdated.
  • Other probed story domains in this set did not surface notable CMS/PHP/TLS aging bullets in the same pass.

Hidden or outdated stacks on alarm vendor marketing sites do not cause the shared Bluetooth key — but they are a poor look when customers are hunting for a trustworthy firmware path.

Priority actions

  1. Dealers: Inventory which lots still pre-install KARR/SWDS; script customer outreach so the app + firmware path is not left to a DEF CON headline.
  2. Owners: Check glass + under-dash cues; update firmware even if you never subscribed.
  3. Security / MSP for dealer groups: Treat spoofed “Acrisure / KARR update” mail as high-risk while news circulates; enforce DMARC and callback procedures on F&I vendors (FTC Safeguards dealer guide).
  4. Compare OEM lessons: Fast portal patches (Subaru STARLINK) vs slow aftermarket firmware reach — see Subaru STARLINK admin takeover.

Sources: Malwarebytes · KARR Security · Acrisure Protection Group