Your Executive's Car Is Now A Tracking Beacon With An Unlock Button
- Red Cell Security Operations Team

- 1 day ago
- 6 min read

A while back we ran an advance for a principal who was certain his risk started the moment he stepped out his front door. Route was tight. Venue was swept. The detail was sharp and the man leading it was good. Then we asked what was installed on his vehicles and got a shrug. A dealer had bolted an aftermarket alarm under the dash years earlier, nobody on the team knew it was there, and not one person could tell us what it talked to or who else had ever touched its settings. That shrug is the whole problem, and this month it stopped being a hypothetical we use to make a point.
Researchers found that roughly 2.2 million vehicles carry a dealer-installed aftermarket security system that uses the same hard-coded Bluetooth key on every single unit. From about five yards away an attacker can unlock the doors, flash the lights, sound the horn, and stop the engine from starting. The same system feeds a publicly accessible database that leaks vehicle location, so the attacker can find the target first and then walk up to it. The vendor pushed a firmware fix, which is good and which almost nobody will install, because most owners have no idea the hardware is even in the car. The patch is not the story. The story is what the design tells us about how these people get hurt.
Why one bad key breaks two million cars
Here is the part worth slowing down on. Good security gives every device its own secret. Your key opens your car and tells you nothing about anyone else's. This system did the opposite. It shipped the same secret to every unit that rolled off the line, which turns the whole fleet into one lock with two million copies of the key floating around. A researcher only has to pry that key out of a single device, once, and every car in the fleet is open. That is not a sophisticated attack. It is patient reverse engineering against a lazy shortcut, and it is the same shortcut we find over and over in the cheap radios, trackers, and remote-start modules that get sold as protection.
The lesson generalizes fast. Any device that guards a person and shares one secret across every customer is not a control, it is a single point of failure waiting for one motivated person to do the work once. When we assess a principal, the question we ask of every gadget around him is simple. Is this key ours alone, or is it the same key that shipped to a hundred thousand strangers. You would be surprised how often nobody can answer.
The attacker starts before he ever sees your principal
Unlocking the car is the loud part. The quiet part is worse. That same product left location data sitting in a database anyone could reach, which means an attacker does not have to sit outside a house and wait. He can pull patterns of life off a screen. Where the vehicle sleeps, when it moves, which gym on which mornings, which school pickup, which side entrance at the office.
And this is not unique to one alarm brand. There is an entire legal industry that buys and sells exactly this kind of data. For a few dollars, data brokers will hand over home addresses, relatives, vehicles, and rough daily patterns on almost anyone. Pair a cheap data broker profile with a leaky device and an attacker has built a target package before he has left his own kitchen. In our world that is the whole game. The people who mean harm do their homework online now, and the principal who is only protected once he is moving has already lost the part of the fight that happens in the dark.
The car is just the easiest example
Widen the lens and the vehicle is one node in a much larger surface. The principal's phone leaks location through apps he forgot he installed. The smart lock on the front door and the video doorbell are physical controls sitting on a home network nobody has ever patched, the same failure we wrote about with corporate cameras, just moved into the house. The fitness tracker publishes a running route. The teenager's social account geotags the family vacation in real time. Every one of these is a small door, and an attacker only needs the doors to line up once.
We watched a version of this play out with another principal whose own security was tight but whose household was wide open. The threat never went near him. It went at the people and devices around him, because that was the soft edge, and it nearly worked. That is the pattern. The principal is rarely the weakest point anymore. The weakest point is the technology and the people orbiting him, and almost no protection plan is scoped to see it.
Executive protection quietly split in two
Here is what all of this adds up to. Protecting a person used to be one discipline. It is now two, and they barely talk to each other. There is the physical side, the advance, the route, the venue, the hands and the driving. And there is the technical side, the devices, the networks, the data trail, the digital exposure that decides whether the attacker ever finds the principal in the first place. A guns-and-driving shop cannot read a vulnerability advisory. A pen test shop cannot run a detail. The person hunting your principal does not care about that line, and if your protection stops at one side of it, you are covering half the board and calling it a win.
What to check this week
You do not need us to start closing the obvious gaps. Run these yourself and see how far the rabbit hole goes.
Inventory every aftermarket device on the principal's vehicles. Dealer alarms, trackers, remote-start modules. If it talks Bluetooth or cellular it is an attack surface, and half the time the principal has no idea it is installed.
Get the principal and his family off the data broker sites. Location and pattern-of-life data sells cheap and it is where a real attacker starts. Opt out or run removal on the major people-search and location brokers so nobody can buy the starting point.
Treat the home the way you treat the office. Cameras, doorbells, and smart locks are physical controls sitting on a network nobody patches. Put them on their own segment and keep them off the principal's personal devices.
Ask one question of every protective device around him. Is the key unique to us, or is it the same one shipped to everyone. That question alone would have caught the car flaw.
Rehearse the technical failure, not just the physical one. Your advance covers the route and the venue. Add the scenario where the vehicle's locks, location, or comms are compromised before the movement even starts, and decide now who owns that answer.
Work that list honestly and you will hit a wall, not because you are bad at the job, but because it lives across two disciplines that almost never sit in the same person. That wall is the point.
Where this leaves you
We do this from both sides. We run target assessments the way the adversary runs them, and we run protective work for people who cannot afford to be found. So when we look at a principal we are not checking the route and calling it covered. We are mapping the car, the devices, the home, and the data trail the way the person hunting him would, and then we close what we find before anyone else maps it first.
The question worth sitting with is simple. When did anyone last look at your principal the way the person hunting him would, all of it in one pass, and hand you the gaps in writing before they got used. Most details have never had that done.
That is the work. Our principal exposure assessment maps the vehicles, the devices, the home network, and the data trail an adversary would use, then hands you a prioritized plan to close it. The checklist above is yours to run for free. Finding what it misses and shutting it down is the engagement.
If your protection stops at the physical side, book a call and we will scope the assessment for your principal.




Comments