Threat · vehicle network
They do not need your key. They need your headlight.
CAN injection is the attack that made a lot of expensive car security look ornamental. The thief never goes near your key, never relays a signal, and never opens a door in the normal sense. They open a gap in the bodywork and talk to the car in its own language.
First, what the CAN bus actually is
A modern car contains somewhere between thirty and a hundred small computers. The engine management, the gearbox, the doors, the lights, the instrument cluster, the parking sensors, the seats. They need to talk to each other constantly, and running an individual wire between every pair would need a wiring loom the size of a bin bag.
So instead they share one conversation. The Controller Area Network — CAN — is a pair of twisted wires that every module listens to at once. Any module can put a message on it. Every other module hears it, and each one ignores the messages that are not its concern. It is elegant, it is reliable, it has been in cars since the early nineties, and it was designed in an era when the idea that someone might attach a hostile device to it was not on anybody's list.
Crucially, CAN has no concept of identity. A message does not carry a signature saying which module sent it. It carries an identifier saying what the message is about. If a message arrives with the identifier that means "the key has been verified and start is authorised", every module that cares will act on it, and none of them will ask where it came from.
CAN works exactly as intended. The problem is that "any module can speak and everyone believes it" is a fine rule inside a sealed metal box, and a terrible one once someone can attach a wire to that box from the pavement.
How the attack runs, step by step
- Find an exposed branch of the network. On many vehicles the CAN wiring reaches modules that sit outside the crash structure: headlight units, wing mirrors, bumper parking sensors, the rear light clusters. These are the softest points because a thief can reach them without opening a door.
- Get physical access. A headlight unit can be levered from its housing, or a wheel-arch liner pulled back, in well under a minute. Bodywork damage is minor and often not obvious in the dark.
- Attach the device. The tool is a small board with two wires and a connector, frequently hidden inside a harmless-looking object — the Bluetooth speaker and the mobile phone case are the two that made the news. It clips onto the pair of CAN wires.
- Inject. The device floods the network with the message that means the key was validated. It does not decrypt anything, because it does not have to. It skips the entire conversation between key and immobiliser and simply announces the conclusion.
- Drive. The doors unlock, the start authorises, and the car leaves. Total time on a well-practised model is often around two minutes.
Why this is hard for manufacturers to fix
Because the fix is architectural. Adding message authentication to the CAN bus means every module in the car must be able to sign and verify messages, which means new hardware, new software, revalidation of safety-critical systems, and a supply chain that spans dozens of suppliers. Manufacturers are doing it — newer platforms use gateway modules that segment the network so that a headlight cannot talk to the engine at all, and some now authenticate critical frames — but a car designed in 2018 cannot be retrofitted with a different network topology.
In the meantime the response has been software patches, gateway firmware updates and, in some cases, manufacturers funding aftermarket security fitment for owners of affected models. That last detail is telling: the manufacturer's own recommended answer to CAN injection has frequently been a second, independent immobiliser.
Which cars are exposed
Publicly documented cases have concentrated on premium SUVs and executive saloons, simply because that is where the resale value is and where organised export networks focus. But exposure is not really about the badge. It comes down to three things:
- Is a CAN branch reachable from outside the bodywork? Headlights and mirrors are the usual answer.
- Is the network segmented? Older single-bus designs are far more exposed than newer gateway architectures.
- Is there a known frame that authorises start? Once one team has reverse-engineered a model, the knowledge is a product. It gets sold, and every example of that model becomes a target.
Practically, this means theft of a given model can go from rare to epidemic in a matter of months, with nothing about the cars having changed. If your model appears in the news, assume the knowledge is already in circulation. See which models are currently being targeted →
What actually stops CAN injection
Physical barriers: partial help
Bonnet locks, headlight locking brackets and OBD port locks all raise the effort required. They are worth having on a high-risk model. They also announce that the car is protected, which some owners want and some do not. None of them is decisive on their own, because there is usually more than one way into the loom.
Manufacturer updates: take them
If your dealer offers a security software update, book it. Some have measurably reduced theft rates for specific models. Check whether one exists for your VIN — many owners have never been told.
An independent block on the bus: decisive
Here is the key insight. A CAN injection attack works by supplying a message the car's own systems expect. That works because those systems, and their message formats, are documented, standardised and reverse-engineerable.
An aftermarket immobiliser like LockCar CAN-IMMO is none of those things. It holds the engine blocked by default, and it releases that block only on an authorisation that arrives over an encrypted Bluetooth link from your paired phone or tag — not over the CAN bus at all. There is no frame a thief can inject to disarm it, because the disarm does not travel on the bus. Flooding the network with fake key-valid messages gets them past the factory immobiliser and no further.
And because the module is small, sealed, and concealed somewhere chosen for your specific car, there is no obvious box to find and unplug in a dark car park with a torch. The full technical explanation →
No security device is absolute. Anything with a physical presence can eventually be found by someone with unlimited time, the right knowledge and the car in a workshop. The realistic goal is to make your car take too long, too noisily and too uncertainly to be worth choosing over the next one — and on that measure, a hidden independent immobiliser is the single most effective thing you can add.
Questions we get asked
Is CAN injection the same thing as a relay attack?
No, they are opposites in method. A relay attack borrows your real key's signal from a distance. CAN injection ignores the key completely and forges the message the car produces after a key has been checked. A defence against one is not automatically a defence against the other — a signal-blocking pouch, for instance, does nothing against CAN injection.
Will my alarm sound if someone pulls off my headlight?
Usually not in a way that helps. Many alarms monitor doors, bonnet and ignition, not the front bumper or a headlight housing. Some tilt and shock sensors will trigger, which is one reason a shock sensor input on an aftermarket immobiliser is useful.
Does an OBD port lock prevent CAN injection?
It blocks one specific access point, and it is worth fitting. But CAN injection typically avoids the OBD port entirely by reaching the network through exterior modules, so a port lock alone is not a defence against it.
Can a CAN injection device be left in my car to be used later?
It has happened. A device can be attached and hidden for a return visit. If you ever find unexplained wiring, a loose light unit or an object that does not belong in your engine bay, treat it seriously and have the car checked.
If they can inject the start message, can they also disarm an aftermarket immobiliser?
Not if the immobiliser's authorisation does not travel over the CAN bus. LockCar CAN-IMMO is disarmed by an encrypted Bluetooth exchange with your phone or tag, so there is no on-bus message that releases the block.
A block that is not part of the protocol
LockCar CAN-IMMO sits hidden on the vehicle network and holds the engine blocked until it receives an authorisation no injected frame can supply.
Get a quote for your carLockCar · 06 modules · built in the UK
The full LockCar range
Visit the shop →CAN-IMMO is one module in a wider system. LockCar also builds trackers, 4G cameras, alarms, apps and fleet monitoring — and we fit and support all of them.
Category pages open on lockcar.co.uk — the manufacturer's shop
Autowatch and Ghost are trademarks of Autowatch Ltd. IGLA is a trademark of AUTHOR Ltd. LockCar is a trademark of its manufacturer. 5StarWin is not affiliated with, endorsed by or acting on behalf of Autowatch or AUTHOR. Comparisons on this page are based on publicly published manufacturer and installer information available in August 2026 and on our own fitting experience; specifications, approvals and prices change, so please confirm current details with each supplier before you decide. Nothing here is insurance advice — always tell your insurer about any security device fitted to your vehicle.