Researchers from IMDEA Networks Institute and European partners reported that many vehicles’ direct Tire Pressure Monitoring System (dTPMS) sensors broadcast unencrypted radio messages containing persistent unique identifiers, enabling passive tracking of cars over time. Using low-cost software-defined radio receivers (about $100 each), the team collected 6+ million TPMS messages from 20,000+ vehicles over roughly 10 weeks, with reception reported at 50–55 meters and even without line-of-sight; the broadcasts occur automatically while driving (and, for some brands, periodically while parked), giving drivers no indication the signals can be intercepted.
The reporting highlights that dTPMS messages can include pressure/temperature/battery data plus a 24–32-bit ID transmitted in cleartext over 315/433 MHz (with protocols/modulations such as ASK/FSK), and that the lack of encryption and ID rotation creates a stable “fingerprint” that can be correlated across locations. The researchers demonstrated scaling the approach with multiple receivers (e.g., RTL-SDR on Raspberry Pi) and commodity tooling such as rtl_433 with data pipelines (e.g., MQTT/InfluxDB), and described methods to associate the four tire IDs to a single vehicle to increase confidence in repeated detections; coverage included major brands cited in reporting such as Toyota, Renault, Hyundai, and Mercedes, while noting that some manufacturers use different approaches (e.g., indirect TPMS) that change the exposure profile.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The researchers publicly warned that TPMS safety systems can function as persistent tracking beacons because encryption and identifier rotation are commonly absent, while regulations such as UN Regulation No. 155 do not explicitly cover TPMS. They recommended mitigations including encrypting broadcasts, rotating identifiers, reducing beaconing behavior, and updating vehicle security rules to include TPMS protections.
Analyzing the collected data, the researchers showed that many direct TPMS sensors in vehicles from brands including Toyota, Renault, Hyundai, and Mercedes broadcast cleartext telemetry and long-lived unique identifiers. By correlating the four tire sensors on a vehicle, they demonstrated reliable passive re-identification and inference of routines such as arrivals, departures, and presence or absence patterns.
Researchers from IMDEA Networks and European partner institutions deployed a small network of low-cost software-defined radio receivers near roads and parking areas for 10 weeks, collecting more than 6 million TPMS transmissions from about 20,000 vehicles. The field study showed that direct TPMS signals could be captured at scale from over 50 meters away, including some non-line-of-sight scenarios.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcehelpnetsecurity.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.