Threat Intelligence
~/ › Threat Intelligence › article
Keyless Relay Attacks: How Syndicates Steal Cars Without Breaking Glass
> By ChenHo | Aug 04, 2026 | 4 min read
Your smart car keys are safely resting on your kitchen counter, yet a thief just drove your brand new SUV off the driveway without triggering a single alarm or breaking a window.
⚠️ THREAT INTELLIGENCE ADVISORY:
Organized syndicates are utilizing low-cost radio frequency (RF) amplifiers to execute “Relay Attacks.” By tricking the vehicle into detecting the key’s proximity, attackers can unlock and start modern cars seamlessly.

The transition to keyless entry systems has inadvertently replaced physical security with a highly exploitable digital convenience.
Table of Contents
Context / Motivation
Luxury and mid-range SUVs are prime targets for international export syndicates. Traditional hotwiring is obsolete against modern immobilizers. Instead, attackers exploit the vehicle’s native “smart key” functionality, ensuring the car is stolen intact without any physical damage.
Technical Analysis: Signal Amplification
The attack requires two individuals working in tandem using a pair of radio transceivers.
- The Relay Bridge: Attacker A stands near the car with a transmitter. The car constantly polls for the key’s low-frequency signal. Attacker A’s device captures this “challenge” signal and transmits it via a high-frequency link to Attacker B.
- Key Interaction: Attacker B stands near the front door or window of the victim’s house. Their receiver amplifies the car’s challenge signal through the walls. The legitimate key on the kitchen counter responds.
- Authentication: The key’s valid response is relayed back to Attacker A, who transmits it to the car. The car unlocks and starts, believing the owner is in the driver’s seat.
This hardware-level exploitation takes less than 60 seconds.
Impact Assessment
Victims suffer total asset loss, often waking up to an empty driveway. Insurance claims can be complicated if there is no evidence of forced entry, leaving owners in protracted battles with their providers.
Mitigation Recommendations
- Use a Faraday Pouch: Store your keys in an RF-blocking Faraday bag or a metal tin box when at home to prevent the signal from being amplified.
- Disable Keyless Entry: Check your vehicle’s manual; some manufacturers allow you to disable the keyless entry feature entirely via the infotainment system.
- Steering Wheel Locks: Reintroduce physical security barriers. A heavy-duty steering wheel lock severely deters attackers seeking a fast, silent getaway.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Keyless Relay, Plainly
A relay attack stretches the radio handshake between your key fob in the kitchen and the car at the curb. Two people, two amplifiers, a few seconds. No broken glass. The car thinks the fob is in range. This is a physical radio attack, not an app hack. Faraday pouches and disabling walk-up unlock are the boring controls that work. After-market alarms that ignore the OEM radio do not always help.
Mitigation & Prevention Strategies
For owners.
- Keep fobs away from the front door. Use the brand’s “walk-away lock / disable comfort access” setting. A metal tin or certified Faraday pouch at night is cheap insurance.
- If the car supports a PIN to drive, turn it on.
For dealers / condos.
- Camera coverage on the drop-off lane. Do not leave keyless press cars on the street overnight with fobs at reception.
Condo Lobbies
Fobs on a bowl at reception are a relay gift. Ask the condo to keep them in a drawer, not on the marble. If you valet, take the fob into the restaurant. Comfort-access is a convenience feature designed for your driveway, not for a street with two people and a backpack.
Write the control you will actually keep. A rule nobody follows is not a control. Put it on a card on the router, in the family chat, or in the staff handbook. Review it when you change phones, move house, or hire. Most of the failures in this class are forgotten defaults, not genius attackers. If you do only one thing tonight with the fob location, do the one already listed in the mitigation bullets above, then tell one other person in the household or team that you did it so the knowledge does not sit in a single head. If you cannot name the last time you checked, assume it is already wrong and check tonight.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Keyless Relay Attacks: How Syndicates Steal Cars Without Breaking Glass is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
Threat Intelligence
Threat Intelligence
Hacker vs Hacktivist: 5 Dangerous Differences in Modern Cyber Warfare
> read
Threat Intelligence