Back to news
Cybersecurity Alert
July 29, 2026 by EmailMeNow IT Consulting

Subaru STARLINK Admin Portal Let Attackers Track and Control Cars With License Plate Data

Sam Curry and Shubham Shah showed Subaru’s STARLINK admin portal allowed account takeover and remote unlock/start plus a year of ~5 m location history. UH West Oahu summarizes the patch-in-24-hours case. Domain audits (ideal 100%): subaru.com 59%, mysubaru.com 28%; none at 100%.

Source: UH West Oahu Cyber

NewsAuto DealersConnected CarsSubaruTelematicsAccount TakeoverCybersecurity
Connected car beside an admin dashboard showing remote unlock and location history risk

Subaru’s STARLINK connected-vehicle service had an employee admin portal that let researchers with little more than a plate (or email / phone / last name + ZIP) search customers, steal PII, add themselves as authorized users, and remotely unlock / start vehicles — without notifying the owner.

UH West Oahu’s Cyber weekly summary (Feb 6, 2025) condenses the case for students and practitioners. Primary technical write-up: Sam Curry — “Hacking Subaru” (Jan 23, 2025), with Shubham Shah. Discovery Nov 20, 2024; patched within ~24 hours. Malwarebytes later cited the same rapid fix when contrasting the 18-month KARR aftermarket alarm wait.

Naming note: Subaru STARLINK is the OEM telematics brand — not SpaceX Starlink satellite internet (our Musk portfolio email audit covers starlink.com separately).

Connected car beside an admin dashboard showing remote unlock and location history risk

Snapshot

FieldDetail
SystemSubaru STARLINK telematics + STARLINK Admin Portal
Host (research)portal.prod.subarucs.com (found via my.subaru.commys.prod.subarucs.com)
ResearchersSam Curry, Shubham Shah
FoundNov 20, 2024
Patched~24 hours after report
Geographic scopeU.S., Canada, Japan STARLINK / connected accounts
Search pivotsLicense plate → VIN; email; phone; last name + ZIP
ImpactRemote lock/unlock/start/stop; ~1 year location history (~5 m); PII / billing hints / VIN / emergency contacts
Owner signalFriend demo: unlock succeeded with no SMS / email / push

Researchers could target any STARLINK-connected Subaru in the United States, Canada, and Japan from the admin portal — not a single-model recall. Curry’s PoC used his mother’s 2023 Impreza (~1,600 location points) and unlocked a friend’s Subaru the same way. Cards below highlight common STARLINK-equipped body styles so owners can picture the class of vehicles in scope; enrollment / connectivity, not trim badge alone, determined exposure.

ExampleRole in the research / market
ImprezaExplicit PoC vehicle (2023) with full year of engine-start telemetry exported
OutbackCommon STARLINK wagon / crossover sold across U.S. and Canada
ForesterHigh-volume compact SUV often sold with STARLINK packages
CrosstrekPopular entry crossover in markets that push telematics enrollment
AscentThree-row SUV typically ordered with connected services

Representative Subaru Impreza-style hatchback used as the STARLINK research proof-of-concept class

Impreza (PoC) 2023 Impreza in Curry’s write-up — year of GPS history and remote commands demonstrated.

Representative Subaru Outback-style wagon in the STARLINK connected-vehicle class

Outback Representative STARLINK-capable wagon / crossover in the same admin search space.

Representative Subaru Forester-style SUV in the STARLINK connected-vehicle class

Forester High-volume SUV class typically offered with STARLINK remote services.

Representative Subaru Crosstrek-style crossover in the STARLINK connected-vehicle class

Crosstrek Entry crossover frequently enrolled in telematics at delivery.

Representative Subaru Ascent-style three-row SUV in the STARLINK connected-vehicle class

Ascent Three-row SUV class with the same portal-searchable connected account model.

If the car used MySubaru / STARLINK remote unlock or location features in those markets before the Nov 2024 patch window, treat it as in the affected class even when the specific model is not pictured here.

How the takeover worked

StepWhat happened
1. Find admin hostSubdomain enumeration reached the STARLINK Admin Portal login.
2. JS loot/assets/_js/ includes a login.js path to forgotPassword/resetPassword.json without a confirmation token.
3. Enumerate staffgetSecurityQuestion.json?email= differentiates valid vs invalid employee emails ([first_initial][last]@subaru.com).
4. ResetPOST a new password for a valid staff mailbox → "success".
5. Bypass 2FACustom security-question modal was client-side only — remove the overlay and the session works.
6. OperateSearch any customer; pull year of GPS starts; add authorized user; send unlock / start.

Password-reset endpoint and client-side 2FA overlay enabling admin portal takeover

Curry’s PoC pulled ~1,600 coordinates from his mother’s 2023 Impreza — every engine start / telematics command for a year — then unlocked a consenting friend’s car from the same console.

Year of connected-car GPS breadcrumbs exposed from telematics admin access

Why auto dealers still own part of the trust story

OEM telematics bugs are Subaru’s to patch — but dealerships enroll buyers, explain STARLINK packages, and field confused owners when a research blog hits. Pair this with our dealer email posture work and Safeguards guidance:

Related EmailMeNow coverageWhy it matters here
Hawaii Auto DealershipsSame UH West Oahu information ecosystem
National Auto DealersDealer group mail identity for spoofed “STARLINK notice”
California Auto DealershipsLarge Subaru retail presence + connected F&I
Texas Auto DealershipsSafeguards + finance inbox risk
FTC Safeguards for Texas dealersWritten program expectations when explaining telematics risk to customers
Auto dealers hubVertical audit entry point

UH West Oahu’s mitigation list is consumer-sane: stronger MFA, no weak passwords, restrict unused connectivity, keep apps updated — plus the industry reminder that admin planes need the same rigor as customer apps.

Independent cybersecurity audits

EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not whether the Nov 2024 portal bug still exists (Subaru reports it patched in ~24 hours).

Organization / roleDomainOverallIdentityTransportWebsiteRisk
Research coverage (contrast)malwarebytes.com72%90%45%45%Good
OEM marketingsubaru.com59%65%15%40%Average
University of Hawaiʻi systemhawaii.edu52%50%15%37%Average
STARLINK / CS backend brandsubarucs.com45%40%15%40%Below Average
UH West Oahu Cyberwestoahu.hawaii.edu28%0%15%37%Weakest
MySubaru customer surfacemysubaru.com28%0%15%37%Weakest
Researcher write-upsamcurry.net28%0%15%37%Weakest

Audit links: malwarebytes.com · subaru.com · hawaii.edu · subarucs.com · westoahu.hawaii.edu · mysubaru.com · samcurry.net

Pattern: mysubaru.com and westoahu.hawaii.edu both land at 28% with 0% identity — soft mail authentication on customer-facing or campus-adjacent hosts. subaru.com at 59% still sits 41 points under the 100% ideal, dragged by 15% transport. Spoofed “STARLINK enrollment / portal notice” mail remains a realistic secondary risk after the portal bug itself is gone.

Website stack note

Passive website-tech probes on July 29, 2026:

  • westoahu.hawaii.eduWordPress (version hidden) with PHP 8.1.33 (EOL as of Dec 31, 2025) and plugins including Contact Form 7, Revslider, Megamenu Pro.
  • subaru.com, mysubaru.com, subarucs.com, malwarebytes.com, samcurry.net, hawaii.edu — no notable CMS/PHP/TLS aging bullets in the same batch (malwarebytes.com has previously fingerprinted as WordPress with a hidden generator in other probes).

Campus CMS aging does not re-open the STARLINK portal bug — it does show how teaching summaries often sit on stacks that themselves need hygiene.

Priority actions

  1. Subaru owners: Keep MySubaru / STARLINK apps updated; treat unexpected “authorized user added” or silent unlocks as incident signals.
  2. Dealers: Train F&I / service to answer STARLINK privacy questions with facts — remote history exists when enrolled; point customers to OEM support, not random “portal reset” emails.
  3. Dealer IT / MSP: Block-list lookalike domains during news cycles; enforce DMARC on rooftops that send finance / delivery messages (national dealer audits).
  4. Compare aftermarket risk: Shared BLE keys on dealer-installed alarms — KARR / Acrisure coverage.

Sources: UH West Oahu — Subaru’s STARLINK Vulnerability · Sam Curry — Hacking Subaru · Malwarebytes (KARR contrast) · Subaru STARLINK overview