Home / Guides / OBD theft and cloning

Threat · diagnostic port

A brand new key for your car, in ninety seconds.

Every car built since 2001 has a socket under the dashboard that can reprogram the vehicle's security. It exists so a garage can do its job. It also means a thief with the right tool does not need your key — they can make their own.

Reading time: 6 minUpdated: August 2026Written by the 5StarWin fitting team

The port under your dashboard

OBD stands for On-Board Diagnostics. The connector is normally within arm's reach of the driver's seat, often just above the pedals or behind a small flap. Legislation required it so that emissions equipment could be tested and any garage — not only a franchised dealer — could diagnose a fault.

Over time it became much more than a diagnostic socket. Through the same connector a technician can read fault codes, recalibrate modules, update firmware, and, critically, add or delete keys. That last function has to exist. People lose keys. Cars are sold without a spare. A locksmith at the roadside needs a legitimate way to get you moving.

The trouble is that the port itself has almost no concept of authorisation. On many vehicles, the thing that authorises key programming is possession of the right tool, and on plenty of older models it is nothing at all.

The tools, and who has them

Key programmers are legitimate professional equipment. Locksmiths, independent garages, fleet operators and vehicle recovery firms all need them. They are sold openly, they come with subscription-based vehicle coverage databases, and the good ones cost roughly what a used hatchback costs.

Which means two things. First, the equipment is not exotic and possession of it proves nothing. Second, it leaks. Tools get stolen, resold, cloned and shared, and the knowledge of which sequence works on which model circulates in exactly the same way. Some models are protected by a manufacturer security-access process that requires an online account and leaves an audit trail; on others, the sequence is a known workaround that has been passed around for years.

Why the "just disable the port" idea fails

The OBD connector is not a separate system. It is a window onto the same CAN bus every module already shares. Disable the socket and the network is still reachable from any module's wiring — under the dashboard, behind a kick panel, or at a headlight. An OBD lock raises the effort. It does not close the door.

How the theft runs

  1. Entry. Sometimes a relayed key signal, sometimes a door lock attacked mechanically, sometimes simply a window. Once the objective is the OBD port, the entry method barely matters — many alarms will sound, and thieves accept that.
  2. Plug in. The programmer goes into the port. Some tools need the ignition on, which any entry method has already made possible.
  3. Write a key. The tool instructs the car to accept a new blank transponder or a programmable fob. On a supported model this is a menu selection and a wait.
  4. Drive. The new key is genuine as far as the car is concerned. It will start the vehicle today, next week and next year — which is why cars recovered after this kind of theft need their key list wiped before they are safe to use again.

Where an alarm sounds, the working assumption is that nobody comes. Alarms have been going off in British streets since the 1980s and most people no longer look out of the window. Ninety seconds is well inside the time it takes for a neighbour to decide it is worth investigating.

Cloning without ever entering the car

A related family of attacks copies the key rather than adding a new one. A device held near your key — in a pocket, on a cafe table, in a coat on a hook — reads the transponder's identity and writes it to a blank. On some systems this needs only proximity and a few seconds.

Two situations produce most of these thefts. The first is a valet, car park attendant, garage or car wash having your key unsupervised for a few minutes. The second is a public place where your key sits in a bag while you are not watching it. Neither leaves any evidence, which is why owners are so often certain nobody could have touched their key.

What works against OBD theft and cloning

OBD port locks: useful, not sufficient

A metal shroud or locking cover over the port costs relatively little and adds real time and noise to the attack. Fit one if you drive a targeted model. Understand that it protects a socket, not a network.

Mechanical deterrents: still valid here

A visible steering lock genuinely helps against this attack, because it means the thief who has just written a key still cannot steer the car away. It also means an angle grinder, which is loud. Deterrence works by moving the thief to another vehicle.

Key discipline: free and underrated

Never leave a key with anyone longer than the job needs. Ask a garage to keep your key at the desk rather than in the car. When you buy a used car, assume there is a key you do not know about and have the key list wiped — a dealer can do it, and almost nobody asks.

A second, independent authorisation: decisive

This is the attack where an aftermarket immobiliser is at its most obviously useful, because the attack's entire purpose is to produce a valid key — and a valid key is exactly the credential a second immobiliser does not care about.

With LockCar CAN-IMMO fitted, the newly written key satisfies the factory immobiliser perfectly. The engine still does not start, because a second module on the vehicle network is holding the block until your paired phone or proximity tag authorises it. The thief has spent ninety seconds, triggered your alarm, damaged a door and produced a key that starts nothing. How the second check works →

If you buy a used car, do this

Ask the seller how many keys ever existed. Then have the key list erased and re-registered anyway, whatever the answer. It costs far less than the alternative, and it is the single most neglected step in the whole of used car ownership.

Questions we get asked

Can a thief program a key without breaking into my car?

They need access to the OBD port, which normally means getting inside. However, the entry itself can be very quick and non-destructive on some models, and where it is not, they simply accept the noise and damage. A cloning attack, by contrast, needs access to your key rather than your car.

Does an alarm going off stop this kind of theft?

Rarely on its own. The job is finished inside the window in which a typical bystander is still deciding whether to look outside. Alarms are worth having, but they are a notification system, not a barrier.

Will an OBD port lock void my warranty or annoy my garage?

No, and a good garage will not mind — you simply unlock it for them. Some franchised dealers fit them as standard on high-risk models.

If my car is recovered after a key was programmed, is it safe to drive?

Not until the key list is cleared. The thief's key remains valid until the vehicle's stored key data is erased and your own keys are re-registered. Insist on this before the car goes back on your driveway.

Does LockCar CAN-IMMO block the OBD port?

It is not a port lock — it is an engine start block. A key programmed through the port will still be accepted by the factory immobiliser, but the vehicle will not start without a separate authorisation from your phone or tag.

Make a new key useless

If a second immobiliser is holding the engine, a freshly programmed key opens the doors and achieves nothing else.

Get a quote for your car

LockCar · 06 modules · built in the UK

The full LockCar range

Visit the shop →

CAN-IMMO is one module in a wider system. LockCar also builds trackers, 4G cameras, alarms, apps and fleet monitoring — and we fit and support all of them.

Category pages open on lockcar.co.uk — the manufacturer's shop