Tuesday, April 29, 2025
HomeHacksGPS Tracking Apps Flaw Let Hackers Remotely Hijack the Car & Kill...

GPS Tracking Apps Flaw Let Hackers Remotely Hijack the Car & Kill Engines to Create a Traffic Jam

Published on

SIEM as a Service

Follow Us on Google News

A critical security flaw in GPS Tracking Apps that allows remote hackers to hijack the car and kill the engine while the car moving on the road.

A Hacker who reportedly shared details with Motherboard that he broke into thousands of accounts belonging to users of two GPS tracker apps
 iTrack and ProTrack.

He compromised more than 7,000 iTrack accounts and more than 20,000 ProTrack accounts that managed by the respective car owners to
use to monitor and manage fleets of their vehicles through GPS tracking devices.

- Advertisement - Google News

Protrack is a professional Web-based GPS tracking software. A lot of customers from all over the world are using this software to provide live tracking service to the car owners.

iTrack is another app that provides GPS Tracking Security Systems, GPS Security System India, vehicle tracking system, vehicle protection, fleet management system.

Due to the critical security bug in both GPS tracking apps, he brute-forced “millions of usernames” via the apps’ API. Then, he said he wrote a script to attempt to login using those usernames and the default password.

This Flaw let the hacker to automatically break into thousands of accounts who all are using the default password.

Also, the hacker claims that he can track vehicles in some many countries around the world, including South Africa, Morocco, India, and the Philippines.

The hacker shared the alot more information to Motherboard including, name and model of the GPS tracking devices they use, the devices’ unique ID numbers (technically known as an IMEI number); usernames, real names, phone numbers, email addresses, and physical addresses. (According to L&M, he was not able to get all of this information for all users; for some users he was only able to get some of the above information.)

This data breach legitimacy was checked by the motherboard with some of the users and confirmed that the data provided by the hackers was completely original.

Hacker was never tried to kill any cars engine and he didn’t provide any evidence that he can do that. but one of the hardware GPS maker said “customers can turn off the engines remotely if the vehicles are going under 20 kilometers per hour”

GPS Tracking Apps


“My target was the company, not the customers. Customers are at risk because of the company,” L&M told Motherboard in an online chat. “They need to make money, and don’t want to secure their customers.” Hacker said.

ProTrack denied the data breach via email, but confirmed that its prompting users to change passwords.

“Our system is working very well and change password is normal way for account security like other systems, a company representative said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

PASTA – A New Car Hacking Tool Developed by Toyota to Test The Security Vulnerabilities

Modern Cars are Vulnerable to Hacking and Malware Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Researchers Uncover SuperShell Payloads and Various Tools in Hacker’s Open Directories

Cybersecurity researchers at Hunt have uncovered a server hosting advanced malicious tools, including SuperShell...

Cyber Espionage Campaign Targets Uyghur Exiles with Trojanized Language Software

A sophisticated cyberattack targeted senior members of the World Uyghur Congress (WUC), the largest...

Konni APT Deploys Multi-Stage Malware in Targeted Organizational Attacks

A sophisticated multi-stage malware campaign, potentially orchestrated by the North Korean Konni Advanced Persistent...

Outlaw Cybergang Launches Global Attacks on Linux Environments with New Malware

The Outlaw cybergang, also known as “Dota,” has intensified its global assault on Linux...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Europol Launches Taskforce to Combat Violence-as-a-Service Networks

Europol has announced the launch of a powerful new Operational Taskforce (OTF), codenamed GRIMM, to...

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network...

Detecting And Blocking DNS Tunneling Techniques Using Network Analytics

DNS tunneling is a covert technique that cybercriminals use to bypass traditional network security...