What Is the OBD-II Port?
OBD stands for On-Board Diagnostics. The OBD-II standard was made mandatory on all UK and EU vehicles from 2001 onwards. The port — a 16-pin trapezoid connector, almost always located under the dashboard on the driver's side — was designed for a single purpose: to give mechanics and emissions testers direct access to the vehicle's electronic systems.
Plug a compatible device in, and you can read fault codes, view live engine data, check emissions readiness monitors, and — on many vehicles — communicate directly with the ECU, the body control module, and the immobiliser unit. That last capability is where the security problem lies.
How the OBD Key Programming Attack Works
The theft sequence using OBD key programming typically follows these steps:
- Entry via relay attack or broken quarter light — the thieves need to get into the car first. For keyless vehicles, a relay attack (amplifying the key fob signal through the wall) gets them in with no damage. For older vehicles or as a fallback, a small quarter light window may be broken.
- OBD device plugged in — once inside, a thief plugs a handheld key programmer into the OBD-II port. These devices — sold legally for locksmiths and dealers but widely available online — can communicate with the vehicle's immobiliser unit.
- Blank key fob programmed — the device reads the vehicle's immobiliser data and writes it to a blank key fob. Depending on the make and model, this takes between 90 seconds and four minutes.
- Vehicle driven away with a working key — the new key starts the engine as if it were an original. The car drives away. There is no alarm, no forced start, no visible trace of what happened.
The entire process, from gaining entry to driving away, typically takes under four minutes for a well-practised team on a vulnerable vehicle.
"The vehicle's own security systems accept the newly programmed key as genuine. As far as the immobiliser is concerned, it's indistinguishable from the key that came with the car."
CAN Bus Injection: The Keyless Alternative
A related but technically distinct attack has emerged for specific keyless models — notably the Toyota RAV4, Lexus RX, and some Land Rovers. Instead of using the OBD port, thieves access the vehicle's CAN bus (the internal network connecting all electronic modules) through the headlight housing or wheel arch wiring.
By injecting commands directly into the CAN bus, they can bypass the immobiliser and start the engine without any key at all. This attack requires more preparation — the thieves need to know the specific wiring configuration for your model — but it defeats Ghost immobilisers that only operate on the OBD network, and it leaves no trace whatsoever.
Toyota's response to the RAV4 attacks included a software update to limit CAN bus responses to certain commands. If you own an older RAV4 or Lexus RX, check with your dealer whether the update has been applied to your vehicle.
Most Vulnerable Vehicles
OBD key programming vulnerability varies significantly by make, model, and year. Vehicles with older immobiliser protocols are generally more vulnerable than those with newer encrypted systems. The following have appeared most frequently in UK police reports and insurance data for OBD-related theft:
Newer vehicles (2022 onwards in particular) increasingly use encrypted immobiliser protocols and rolling security codes that make OBD key programming significantly harder. This has pushed some gangs toward the CAN bus injection method for newer keyless vehicles.
How to Protect Your Vehicle
1. OBD port lock — the most direct solution
A physical lock over the OBD-II port prevents a device being plugged in without a tool to remove the lock first. This adds a meaningful time barrier — thieves working quickly cannot plug in and programme a key in the same time window as an unprotected vehicle.
The most robust options:
Fitting is straightforward — these plug into the existing port and lock in place. No tools or professional installation needed.
2. Ghost II immobiliser — defeats both attack types
The Autowatch Ghost II intercepts the vehicle start sequence regardless of what key is used. Even if a thief successfully programmes a new key via the OBD port, the engine will not start without the correct PIN sequence entered on the vehicle's existing buttons. The Ghost operates on the CAN bus itself — meaning it also provides a layer of protection against CAN bus injection attacks, as it monitors for unauthorised start commands.
3. Relay prevention (for the initial entry)
OBD key programming requires the thief to get inside the car first. For keyless vehicles, preventing relay entry removes the primary route in:
4. Keep your V5C and spare keys secure
Never leave your V5C logbook or spare keys in the vehicle. In a small number of OBD key programming cases, thieves have used VIN information (visible on the dashboard and in documents left in the car) to prepare a blank key in advance — making the programming step faster.
5. Steering wheel lock for visible deterrence
A Disklok or Krooklok is not a technical countermeasure to OBD hacking, but visible deterrence works. If two identical vehicles are parked together and one has a visible steering lock, the gang will target the other one. Time is the enemy of car theft — any measure that adds perceived time slows the decision.
The Insurance Myth — "My Car Has an Immobiliser"
Many owners assume their factory immobiliser makes OBD key programming attacks impossible. It doesn't. The factory immobiliser is exactly what the OBD programming device is communicating with. On vulnerable vehicles, the factory system can be instructed to accept a new key without any existing key present.
This is not a flaw in the OBD standard itself — it's an implementation issue in how certain manufacturers secured their immobiliser protocols. Newer vehicles have improved significantly, but millions of UK cars registered between 2005 and 2020 remain vulnerable.
If your vehicle is in a high-theft category and you're relying solely on the factory immobiliser for security, you are relying on a system that organised gangs have already defeated.
OBD hacking is one of the least visible theft methods — there's no broken glass, no alarm, and the vehicle appears to leave entirely normally. The only way to know it's happened is when you go to use your car and it isn't there. The countermeasures exist, they work, and most of them are affordable. This is a problem with known solutions.