Subaru’s STARLINK connected-vehicle service had an employee admin portal that let researchers with little more than a plate (or email / phone / last name + ZIP) search customers, steal PII, add themselves as authorized users, and remotely unlock / start vehicles — without notifying the owner.
UH West Oahu’s Cyber weekly summary (Feb 6, 2025) condenses the case for students and practitioners. Primary technical write-up: Sam Curry — “Hacking Subaru” (Jan 23, 2025), with Shubham Shah. Discovery Nov 20, 2024; patched within ~24 hours. Malwarebytes later cited the same rapid fix when contrasting the 18-month KARR aftermarket alarm wait.
Naming note: Subaru STARLINK is the OEM telematics brand — not SpaceX Starlink satellite internet (our Musk portfolio email audit covers starlink.com separately).

Snapshot
| Field | Detail |
|---|---|
| System | Subaru STARLINK telematics + STARLINK Admin Portal |
| Host (research) | portal.prod.subarucs.com (found via my.subaru.com → mys.prod.subarucs.com) |
| Researchers | Sam Curry, Shubham Shah |
| Found | Nov 20, 2024 |
| Patched | ~24 hours after report |
| Geographic scope | U.S., Canada, Japan STARLINK / connected accounts |
| Search pivots | License plate → VIN; email; phone; last name + ZIP |
| Impact | Remote lock/unlock/start/stop; ~1 year location history (~5 m); PII / billing hints / VIN / emergency contacts |
| Owner signal | Friend demo: unlock succeeded with no SMS / email / push |
Affected vehicles (STARLINK-connected)
Researchers could target any STARLINK-connected Subaru in the United States, Canada, and Japan from the admin portal — not a single-model recall. Curry’s PoC used his mother’s 2023 Impreza (~1,600 location points) and unlocked a friend’s Subaru the same way. Cards below highlight common STARLINK-equipped body styles so owners can picture the class of vehicles in scope; enrollment / connectivity, not trim badge alone, determined exposure.
| Example | Role in the research / market |
|---|---|
| Impreza | Explicit PoC vehicle (2023) with full year of engine-start telemetry exported |
| Outback | Common STARLINK wagon / crossover sold across U.S. and Canada |
| Forester | High-volume compact SUV often sold with STARLINK packages |
| Crosstrek | Popular entry crossover in markets that push telematics enrollment |
| Ascent | Three-row SUV typically ordered with connected services |





If the car used MySubaru / STARLINK remote unlock or location features in those markets before the Nov 2024 patch window, treat it as in the affected class even when the specific model is not pictured here.
How the takeover worked
| Step | What happened |
|---|---|
| 1. Find admin host | Subdomain enumeration reached the STARLINK Admin Portal login. |
| 2. JS loot | /assets/_js/ includes a login.js path to forgotPassword/resetPassword.json without a confirmation token. |
| 3. Enumerate staff | getSecurityQuestion.json?email= differentiates valid vs invalid employee emails ([first_initial][last]@subaru.com). |
| 4. Reset | POST a new password for a valid staff mailbox → "success". |
| 5. Bypass 2FA | Custom security-question modal was client-side only — remove the overlay and the session works. |
| 6. Operate | Search any customer; pull year of GPS starts; add authorized user; send unlock / start. |

Curry’s PoC pulled ~1,600 coordinates from his mother’s 2023 Impreza — every engine start / telematics command for a year — then unlocked a consenting friend’s car from the same console.

Why auto dealers still own part of the trust story
OEM telematics bugs are Subaru’s to patch — but dealerships enroll buyers, explain STARLINK packages, and field confused owners when a research blog hits. Pair this with our dealer email posture work and Safeguards guidance:
| Related EmailMeNow coverage | Why it matters here |
|---|---|
| Hawaii Auto Dealerships | Same UH West Oahu information ecosystem |
| National Auto Dealers | Dealer group mail identity for spoofed “STARLINK notice” |
| California Auto Dealerships | Large Subaru retail presence + connected F&I |
| Texas Auto Dealerships | Safeguards + finance inbox risk |
| FTC Safeguards for Texas dealers | Written program expectations when explaining telematics risk to customers |
| Auto dealers hub | Vertical audit entry point |
UH West Oahu’s mitigation list is consumer-sane: stronger MFA, no weak passwords, restrict unused connectivity, keep apps updated — plus the industry reminder that admin planes need the same rigor as customer apps.
Independent cybersecurity audits
EmailMeNow domain audits on July 29, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture, not whether the Nov 2024 portal bug still exists (Subaru reports it patched in ~24 hours).
| Organization / role | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Research coverage (contrast) | malwarebytes.com | 72% | 90% | 45% | 45% | Good |
| OEM marketing | subaru.com | 59% | 65% | 15% | 40% | Average |
| University of Hawaiʻi system | hawaii.edu | 52% | 50% | 15% | 37% | Average |
| STARLINK / CS backend brand | subarucs.com | 45% | 40% | 15% | 40% | Below Average |
| UH West Oahu Cyber | westoahu.hawaii.edu | 28% | 0% | 15% | 37% | Weakest |
| MySubaru customer surface | mysubaru.com | 28% | 0% | 15% | 37% | Weakest |
| Researcher write-up | samcurry.net | 28% | 0% | 15% | 37% | Weakest |
Audit links: malwarebytes.com · subaru.com · hawaii.edu · subarucs.com · westoahu.hawaii.edu · mysubaru.com · samcurry.net
Pattern: mysubaru.com and westoahu.hawaii.edu both land at 28% with 0% identity — soft mail authentication on customer-facing or campus-adjacent hosts. subaru.com at 59% still sits 41 points under the 100% ideal, dragged by 15% transport. Spoofed “STARLINK enrollment / portal notice” mail remains a realistic secondary risk after the portal bug itself is gone.
Website stack note
Passive website-tech probes on July 29, 2026:
westoahu.hawaii.edu— WordPress (version hidden) with PHP 8.1.33 (EOL as of Dec 31, 2025) and plugins including Contact Form 7, Revslider, Megamenu Pro.subaru.com,mysubaru.com,subarucs.com,malwarebytes.com,samcurry.net,hawaii.edu— no notable CMS/PHP/TLS aging bullets in the same batch (malwarebytes.com has previously fingerprinted as WordPress with a hidden generator in other probes).
Campus CMS aging does not re-open the STARLINK portal bug — it does show how teaching summaries often sit on stacks that themselves need hygiene.
Priority actions
- Subaru owners: Keep MySubaru / STARLINK apps updated; treat unexpected “authorized user added” or silent unlocks as incident signals.
- Dealers: Train F&I / service to answer STARLINK privacy questions with facts — remote history exists when enrolled; point customers to OEM support, not random “portal reset” emails.
- Dealer IT / MSP: Block-list lookalike domains during news cycles; enforce DMARC on rooftops that send finance / delivery messages (national dealer audits).
- Compare aftermarket risk: Shared BLE keys on dealer-installed alarms — KARR / Acrisure coverage.
Related trackers
- KARR aftermarket alarm Bluetooth flaw
- Hawaii auto dealership email security
- National auto dealers email security
- California auto dealership email security
- FTC Safeguards Rule for Texas auto dealers
- Auto dealers industry hub
Sources: UH West Oahu — Subaru’s STARLINK Vulnerability · Sam Curry — Hacking Subaru · Malwarebytes (KARR contrast) · Subaru STARLINK overview