CAN Injection Car Theft: How Thieves Can Steal Your Car and How to Stop Them
Your car key is stored away from exterior walls, windows, and outside doors. The alarm is armed, and yet, by morning the driveway is empty with no visible signs that criminal activity took place overnight.
That is CAN injection car theft. The thief never needs to touch your car key or clones its signal.
They reach the wiring behind a headlight, plug in a box the size of a Bluetooth speaker and tell the car a valid key is present. It unlocks, starts and drives away in silence. This guide shows how it works, which cars have been targeted, where the new UK law stands and the fitted defence we recommend first. Data and legal status checked September 2026.
In 30 seconds: CAN injection theft bypasses the key completely. A Faraday pouch does nothing against it.
The attack came to light after a security researcher’s Toyota RAV4 was stolen this way in 2022. Theft devices have been advertised for Toyota, Lexus, Nissan, Ford, BMW, Volkswagen and ten other makes. A new UK offence of possessing these devices in suspicious circumstances, with up to five years in prison, has been passed but is not yet in force. A PIN-based immobiliser such as the Autowatch Ghost is designed to stop the drive-away. Car Keys Solutions fits it at your home across London and the Home Counties.
Table of contents
- What is CAN injection car theft?
- Relay attack or CAN injection: which one are you protected against?
- The RAV4 detective story that exposed the attack
- What was for sale.
- The RAV4’s three CAN buses, simplified.
- How does a headlight CAN bus attack work, step by step?
- Which cars are at risk of CAN injection theft?
- How common is car theft in the UK?
- Is CAN injection illegal in the UK?
- Can car makers fix CAN injection?
- How do you protect your car from CAN injection theft?
- Frequently Asked Questions
- Conclusion
- References
What is CAN injection car theft?
Definition: Every modern car has a CAN bus (Controller Area Network), the internal network that lets the engine, door locks, immobiliser and lights exchange messages. CAN injection theft is when a thief connects a device directly to that network, usually through the headlight wiring, and sends forged messages saying a genuine key has been validated. The car unlocks and starts without the real key.
The vulnerability has its own public record, CVE-2023-29389, which describes the attack on 2021 Toyota RAV4 vehicles and gives July 2022 as an example of it being exploited in the wild (NVD, 2023).
Three things make it different from the theft methods most drivers have read about:
- No key needed. The device impersonates the car’s own smart-key receiver. It does not clone, relay or copy your fob.
- No alarm. The car believes its own components sent the messages, so the factory alarm has no reason to trigger.
- No forced entry to the cabin. The damage is at the front: bumper clips and a headlight connector, which few owners check. A car stolen through headlight wiring often shows little sign it was touched.
Relay attack or CAN injection: which one are you protected against?
Most UK drivers have heard of keyless car theft, where thieves relay the signal from a key fob inside the house. Almost all of the advice you have seen, including the Faraday pouch, is written for that attack. CAN bus car theft is a different problem with a different fix.
If your security plan is built around a pouch, you are covered for the first column and not the second. That is the gap this article is about.
The RAV4 detective story that exposed the attack
The technique was not found in a lab. It was found on a driveway. In April 2022, automotive security researcher Ian Tabor posted that vandals had pulled apart the headlight on his Toyota RAV4 and unplugged the cables. Three months later it happened again, this time with the bumper pulled away. A couple of days after that, the car was gone. Shortly afterwards a neighbour’s Toyota Land Cruiser was stolen too. Tabor investigated and brought in Dr Ken Tindell, chief technology officer of Canis Automotive Labs, to work out how the device behaved on the CAN bus. Tindell’s detailed write-up is the main public account of the attack.
What the car itself recorded. Toyota’s MyT telematics system sends diagnostic trouble codes to Toyota, and the MyT app can show them. Around the time of the theft, Tabor’s car logged a large number of them. Communication with the lighting control unit had been lost, and systems including the front cameras and the hybrid engine control had reported faults. The common factor was the CAN bus.
Two attacks, one lesson
Set the two sequences side by side and the difference is not in the outcome. Both end with the doors open and the engine running. The difference is in what the thief needs before that moment.
What happens in a relay attack
- The attack starts with the owner’s key fob, which must be transmitting.
- The thief captures and amplifies that signal and carries it to the car.
- The car is deceived about where the key is. It is not deceived about whether the key exists.
- Remove the signal and the attack has nothing to work with.
What happens in a CAN injection attack
- The attack starts at the front bumper, with physical access to the headlight wiring.
- The thief feeds the car a fabricated “key validated” message from inside its own network.
- The car is deceived about whether the key exists at all. No key is captured, copied or extended.
- Blocking the fob changes nothing, because the fob was never part of the chain.
What protects against a relay attack
- A Faraday pouch, which removes the signal the attack depends on. This is a useful layer, not a complete defence, because it relies on the owner using it every time and on the spare key being treated the same way.
- Keeping keys away from external doors and windows, which reduces the chance of the signal being picked up.
- An aftermarket immobiliser that requires a PIN sequence before the engine will run, which stops the car driving away even if the doors are opened (Met Police, n.d.).
- A tracker for recovery if the other layers fail.
What protects against a CAN injection attack
- An aftermarket immobiliser that does not accept a “key validated” message as permission to start. This is the primary layer, because it acts at the point the attack is designed to reach. No independent published test measures this against CAN injection, so it should be treated as a strong additional layer, not a guarantee.
- An alarm with tilt and intrusion sensors, which responds to the bumper being disturbed before any door opens.
- A parking-mode dashcam, which records the attempt and supports the police report and insurance claim.
- A tracker for recovery, which addresses the second stage of the theft, driving away, when the first stage has already succeeded.
- A Faraday pouch provides no protection here, for the reason stated above.
The conclusion that follows
The relay attack is defeated by controlling the key. The CAN injection attack is defeated by controlling the car. An owner who has invested only in key-side measures has addressed one of the two methods and left the other untouched. The measures that address both are the ones fitted to the vehicle: an immobiliser that ignores the car’s own trust in its network, an alarm that notices tampering early, and a tracker that gives police a location when prevention fails. Those three, installed together, are the common defence across both attack types. The pouch is an addition to that setup, not a substitute for it.
What was for sale.
Tabor tracked down a website selling more than a hundred products for bypassing car security, including so-called “emergency start” devices. Tindell calls the sales pitch “a fiction that these products are for owners who have lost their keys or somehow reputable locksmiths will use these”. After discussing the device with vehicle forensics specialist Noel Lowdon of Harper Shaw, Tabor bought one to reverse engineer. It arrived looking like this:

The disguise matters. A thief stopped by police appears to be carrying a speaker, not a car theft tool.
What was inside. Tabor melted away the resin with a heat gun. The speaker itself was missing, and grafted onto the JBL circuit board were:
- a PIC18F microcontroller with built-in CAN hardware and pre-loaded firmware
- a standard CAN transceiver chip
- a small extra circuit wired to that transceiver, which turned out to be the clever part
- the speaker’s own battery as the power supply
Tindell put the component cost at about ten US dollars. The finished devices were being sold for thousands.
The RAV4’s three CAN buses, simplified.
Tindell’s analysis of the stolen RAV4 found that the car runs three separate CAN networks, joined by a single gateway module (Tindell, 2023):
What is the diagram saying
A modern car does not run on one network. The RAV4 in Tindell’s analysis has three CAN buses, each carrying a group of related control units, all joined by a single gateway module. The left and right headlights sit on the same bus as the smart key receiver and the door control module. That is the whole vulnerability. A thief who reaches a headlight connector is physically connected to the bus that decides whether the key is present and whether the doors unlock. The gateway then passes the “key validated” message through to the powertrain bus, where the engine control unit releases the immobiliser. The driver assistance and powertrain buses are buried inside the car and cannot be reached from outside. The body bus can, because the headlights are mounted at the front, behind a plastic bumper (Tindell, 2023).
How a CAN injection theft unfolds(based on the RAV4 reference case)
Notice where the headlights sit. They share the control bus with the smart key receiver, the door control unit and the gateway. Anyone who can reach a headlight connector is on the same wire as the car’s key system.
The attack in 5 steps
- Access. The bumper is pulled away near a headlight and the connector unplugged. Tindell describes this as by far the easiest route into the control bus on the RAV4.
- Connection. The injector is connected to the CAN wires and sends a wake-up frame several times a second until a control unit answers.
- Silence. The extra circuit changes how the bus behaves so that other control units cannot transmit, although the gateway can still listen. It also blocks the CAN error mechanism, so security transceivers that would normally detect and destroy a forged frame cannot do so.
- Injection. The device sends forged “key validated” messages in a burst repeated about twenty times a second, because the gateway’s CAN hardware sometimes resets itself and the burst has to keep catching it.
- Compliance. The gateway copies the fake message to the powertrain bus and the engine control unit deactivates the immobiliser. Pressing the speaker’s Play button changes the messages to tell the door unit to unlock. The thief unplugs the device, gets in and drives away.
Which cars are at risk of CAN injection theft?
It is not only a Toyota problem. The website Tabor found listed products for Jeep, Maserati, Honda, Renault, Jaguar, Fiat, Peugeot, Nissan, Ford, BMW, Volkswagen, Chrysler, Cadillac,GMC and Toyota models. The Toyota listing named the Lexus ES, LC, LS, NX and RX and the Toyota GR Supra, Prius, Highlander, Land Cruiser and RAV4 (Tindell, 2023). A listing is not proof that every model on it is vulnerable. Exposure depends on how each manufacturer wired
the lighting system into the rest of the network, so it varies by model and model year as well as by brand. UK theft data does not record the method used, so no official source counts CAN injection thefts. What the data does show is which cars are being taken. DVLA figures for 2025, analysed by Tempcover and reported by Carwow, rank individual variants (Carwow, 2026):
- Toyota C-HR Dynamic HEV CVT: the most stolen single variant, with 437 taken
- Ford Fiesta Zetec, Titanium Turbo and Zetec Turbo: second to fourth, with 1,071 taken between them
- Nissan Juke Tekna CVT: fifth, with 290 taken.
Toyota and Nissan both appear on the list of makes with injectors for sale. That overlap does not prove those cars were stolen by CAN injection, and this article does not claim it. It does mean owners of those models have good reason to take precautions. If your car is on either list and it sleeps on a driveway or street in London or the Home Counties,this is the point to act rather than read on.
Car Keys Solutions can check your model against the known device listings and recommend the fitted defence that suits it. Call us now to book a security assessment.
How common is car theft in the UK?
Vehicle crime is falling but remains high. Most official figures cover England and Wales rather than the whole UK:
| Measure | Figure | Source |
|---|---|---|
| Police recorded vehicle offences, England and Wales, year ending March 2026 | 312,250, down 11% | ONS (2026) |
| Vehicles stolen, England and Wales, April 2023 to March 2024 | 129,159, against 130,119 the year before | AA (2024) |
| Vehicle thefts where a remote locking signal was manipulated, Crime Survey for England and Wales 2022 to 2023 | 40% | GOV.UK (2025) |
| Price of theft devices for higher-end vehicles | More than £20,000, with prices falling | RUSI (2025) |
| Most stolen single variant, UK, 2025 | Toyota C-HR Dynamic HEV CVT, 437 | Carwow (2026), DVLA data |
Two points from that table deserve a second look:
- The 40% figure comes from the Crime Survey for England and Wales and describes thefts where “an offender manipulated a signal from a remote locking device” (GOV.UK, 2025). That is relay and signal attacks on the key. CAN injection is not counted separately in any UK statistic, and a victim may not know which method was used.
- RUSI’s study of organised vehicle theft describes CAN bus injection as a technically complex method and says devices for higher-end vehicles “can sell for more than £20,000”. It also warns that prices are falling, that “Chinese knockoffs” are appearing and that online videos have “partially democratised” the technique (RUSI, 2025). The tools started as organised-crime equipment and are spreading to a wider range of thieves.
Is CAN injection illegal in the UK?
Stealing a car by CAN injection is theft, which is already a crime. What is new is an offence aimed at the tools, and it is not in force yet.
- What it will ban: section 149 of the Crime and Policing Act 2026 makes it an offence to possess, import, make, adapt, supply or offer to supply an electronic device “in circumstances which give rise to a reasonable suspicion that the device will be used in connection with a relevant offence”. It applies in England and Wales, Scotland and Northern Ireland.
- Defence: a person charged can show that they did not intend or suspect that the device would be used in a vehicle offence.
- Maximum sentence: five years’ imprisonment, a fine, or both, on indictment (legislation.gov.uk, 2026a).
- Status: the Act received Royal Assent on 29 April 2026, but section 149 needs commencement regulations. It was not included in the first set, which took effect on 29 June 2026 (legislation.gov.uk, 2026b), and the Home Office says the remaining provisions will be commenced “in due course” (Home Office, 2026).
- Industry reaction: Jonathan Hewett, chief executive of Thatcham Research, called the Act “a landmark moment, and one Thatcham Research and the wider industry have been working towards for many years” (Thatcham Research, 2026).
Even once it is in force, the law targets the tools. It does not change the wiring already built into millions of cars on UK roads, and devices already in criminal hands do not vanish when a law passes. Owner-side protection still matters.
Can car makers fix CAN injection?
Tindell argues that CAN injection can be defeated in software, so cars already on the road could be updated. He sets out two levels of fix (Tindell, 2023):
- A quick fix. Reprogram the gateway, or the immobiliser unit on other models, to notice the rare bus errors the injector causes and to stop forwarding key messages for a few seconds afterwards. This buys time, but the criminals who designed the injector could adapt it.
- The permanent fix. Protect key CAN messages with cryptographic authentication so a forged “key validated” frame is rejected. Tindell says this can run as software on existing control units, but each vehicle needs its own secret keys, provisioned at the factory, and replacement parts need re-keying. That requires key-management infrastructure the industry has to build.
Regulation covers new cars, but only in general terms. The UK’s Vehicle Certification Agency applies UN Regulation No. 155 on cyber security from 6 July 2022 for new whole-vehicle type approvals and from 7 July 2024 for existing type approvals (VCA, n.d.). R155 requires manufacturers to run an audited cyber security management system. It does not prescribe a particular fix such as CAN message authentication, so it does not guarantee that a newer car is immune, and it does nothing for cars built before those dates.
How to protect your car against CAN injection theft
Because the weakness is in the car’s wiring, the defences that work do not depend on the key.
| Measure | What it does | Against CAN injection |
|---|---|---|
| Faraday pouch | Can prevent relay attack only | No effect |
| Steering wheel lock | Visible deterrent | Slows, does not stop |
| Thatcham tracker | Recovery after theft | Does not prevent |
| Ghost immobiliser (PIN on factory buttons) | PIN needed to drive | Designed to stop the drive-away |
Check your car for signs of tampering
Thieves sometimes try to reach a car’s wiring before they steal it. The access point varies by model, so treat any unexplained damage around the headlights, bumper or wheel arches as a warning, not as vandalism. If you notice any, don’t wait: get a Ghost immobiliser and an alarm fitted as soon as you can.
Start with a Ghost immobiliser
CAN injection works by sending the car a forged “valid key” message, so it behaves as if the real key were present. The Ghost Immobiliser adds a check the thief cannot forge: a PIN-style disarm sequence, entered with buttons already in the car (on the steering wheel or dashboard), which must be completed before the engine will run. Without it, the car should not drive away, even if the doors open.
It works through the car’s CAN network and uses no radio signals, so there is nothing for a thief to pick up with a scanner. Autowatch makes no specific claim about CAN injection, but the logic is straightforward: an injector can fake a key message, yet it cannot enter your sequence. Fitted by one of ours expert installers, it is built to be discreet, and you can change the sequence whenever you like. See our Ghost immobiliser fitting service for the models covered.
Then add a tracker and an intelligent alarm
These work alongside the Ghost, not instead of it.
- Thatcham-approved tracker. A tracker will not prevent a theft, but it improves your chances of getting the car back. Ask your insurer whether they require or recognise one for your model.
- Alarm with tilt and interior sensors. The factory alarm stays silent because the car believes a valid key was used. An aftermarket alarm has its own sensors, so it does not depend on that logic.
Car Keys Solutions fits Ghost immobilisers, Thatcham-approved trackers and alarm upgrades across London and the Home counties.
Frequently Asked Questions
Which cars are most at risk of CAN injection theft?
Devices have been advertised for Toyota, Lexus, Jeep, Maserati, Honda, Renault, Jaguar, Fiat, Peugeot, Nissan, Ford, BMW, Volkswagen, Chrysler, Cadillac and GMC models. Exposure varies by model and year, and a listing does not prove every model is vulnerable. In DVLA data for 2025, the Toyota C-HR Dynamic HEV was the UK’s most stolen single variant, though the theft method is not recorded.
Is it illegal to own a CAN injection device in the UK?
Not yet under the new law. Section 149 of the Crime and Policing Act 2026 will make it an offence anywhere in the UK to possess, import, make, adapt or supply an electronic device where there is reasonable suspicion it will be used in vehicle crime, with up to five years in prison. As of 23 September 2026 the section is not in force.
How long does a CAN injection theft take?
No published primary source gives a reliable timing. The vulnerability record and Ken Tindell’s analysis describe the attack as needing only physical access to the headlight connector and a device that sends forged key messages. The “90 seconds” figure repeated online comes from vendor blogs, not from research or police data, so treat it with caution.
How does a Ghost immobiliser work against CAN injection?
The Ghost 2 only lets the engine run after a personal disarm sequence is entered on the car’s existing buttons. Autowatch says it uses the on-board CAN network and no transmitted radio signals. Because the sequence is entered by hand, an injector that forges key messages should not be able to supply it, so the car should not drive away even if the doors open.
What is the CAN bus in a car?
The CAN bus, or Controller Area Network, is the internal wiring network that lets a car’s control units talk to each other, including the engine, door locks, immobiliser and lights. CVE-2023-29389 describes the weakness that CAN injection exploits: the 2021 Toyota RAV4 vehicles “automatically trust messages from other ECUs on a CAN bus”.
How do I know if my headlight has been tampered with?
Look for a bumper edge that no longer sits flush, a wheel-arch liner that is loose or missing clips, and a headlight that has moved or has marks around it. Ian Tabor found this kind of disturbance on his RAV4 twice before it was stolen. If you see it, avoid leaving the car on the drive overnight and get the wiring inspected.
Does car insurance cover CAN injection theft?
Theft cover is a matter for your policy wording, and insurers set their own conditions for high-risk models. Before fitting security, ask your insurer whether a Thatcham-approved tracker or immobiliser is required or recognised on your car. This article makes no claims about premiums because no insurer or industry body publishes a figure for CAN injection specifically.
Theft cover is a matter for your policy wording, and insurers set their own conditions for high-risk models. Before fitting security, ask your insurer whether a Thatcham-approved tracker or immobiliser is required or recognised on your car. This article makes no claims about premiums because no insurer or industry body publishes a figure for CAN injection specifically.
Conclusion
CAN injection car theft is real and documented, and a UK offence aimed at the devices has been passed, although it is not yet in force. The attack bypasses the key entirely, so the Faraday pouch that protects against keyless car theft does nothing here. The evidence supports a short list of actions: know whether your make appears on the list of targeted brands, check the front bumper and headlight for tampering, park nose-in where you can, and fit a PIN-based immobiliser so that even an unlocked car should not drive away. Car Keys Solutions fits Ghost immobilisers, Thatcham-approved trackers and alarm upgrades across London and the Home Counties. Get in touch to book a security assessment before the next attempt, not after it.
References
AA (2024) Car crime 2023 to 2024. The AA newsroom, 24 July. Available at: https://www.theaa.com/about-us/newsroom/insurance-news/car-crime-2023-to-2024
Carwow (2026) The UK’s most stolen cars revealed: is yours on the list? 17 February. Analysis of DVLA data by Tempcover. Available at: https://www.carwow.co.uk/news/9018/cars-most-likely-to-be-stolen-dvla-data
GOV.UK (2025) Vehicle theft equipment to be banned under new government law. Home Office, 24 February. Available at: https://www.gov.uk/government/news/vehicle-theft-equipment-to-be-banned-under-new-government-law
Home Office (2026) Circular 004/2026: Crime and Policing Act 2026. 29 June. Available at: https://www.gov.uk/government/publications/circular-0042026-crime-and-policing-act-2026/circular-0042026-crime-and-policing-act-2026-accessible
legislation.gov.uk (2026a) Crime and Policing Act 2026, section 149: electronic devices for use in vehicle offences. Available at: https://www.legislation.gov.uk/ukpga/2026/20/section/149
legislation.gov.uk (2026b) The Crime and Policing Act 2026 (Commencement No. 1 and Saving Provision) Regulations 2026 (SI 2026/689), regulation 2. Available at: https://www.legislation.gov.uk/uksi/2026/689/regulation/2/made
NVD (2023) CVE-2023-29389. National Vulnerability Database, 5 April. Available at: https://nvd.nist.gov/vuln/detail/CVE-2023-29389
ONS (2026) Crime in England and Wales: year ending March 2026. Office for National Statistics, 23 July. Available at: https://www.ons.gov.uk/peoplepopulationandcommunity/crimeandjustice/bulletins/crimeinenglandandwales/yearendingmarch2026
RUSI (2025) Glantz, E., Williams, M. and Greig, A. Organised vehicle theft in the UK: trends and challenges. Royal United Services Institute, June. Available at: https://static.rusi.org/organised-vehicle-theft-in-the-UK-trends-and-challenges-june-2025.pdf
Thatcham Research (2026) Crime and Policing Act 2026 strengthens UK vehicle security, but more industry collaboration needed to combat criminal gangs. 30 April. Available at: https://www.thatcham.org/crime-and-policing-act-2026-strengthens-uk-vehicle-security-but-more-industry-collaboration-needed-to-combat-criminal-gangs/
Tindell, K. (2023) CAN injection: keyless car theft. Canis Automotive Labs, 3 April. Available at: https://kentindell.github.io/2023/04/03/can-injection/
VCA (n.d.) Cyber security and software updating. Vehicle Certification Agency. Available at: https://www.vehicle-certification-agency.gov.uk/connected-and-automated-vehicles/cyber-security-and-software-updating/
Share