← All guides

How it works

How thieves steal cars through the OBD port

There's no broken glass, no alarm, and often no sign anything happened until the driveway is empty. Modern vehicle theft is closer to a software exploit than a break-in.

The short version

Step 1 — Getting inside

The thief needs physical access to the cabin, but not violent access. Common methods include a relay attack (two devices relay your key fob's signal from inside your house to the car, unlocking it), exploiting an unlocked door, or in some cases jamming the lock signal as you walk away so the car never actually locks.

Australian Bureau of Statistics data shows the majority of car thefts happen at the owner's home — which is exactly where your keys sit near a front door, within relay range.

Step 2 — Finding the port

The OBD-II port is standardised. On almost every vehicle it's under the dash on the driver's side, within reach of the footwell. A thief doesn't need to search — they already know where it is on your make. Here's how to find yours.

Step 3 — Programming a key

This is the part people find surprising. The OBD port isn't just for reading fault codes. It's the same channel a locksmith uses to pair a replacement key when you lose one — a genuine, necessary function.

A key programmer plugs in, talks to the immobiliser, and enrols a blank transponder key. Depending on the vehicle it takes anywhere from 30 seconds to a few minutes. The car now has a second legitimate key that starts it.

No forced ignition, no hot-wiring. As far as the vehicle is concerned, an authorised key is being used.

Step 4 — Driving away

The alarm doesn't sound, because the car isn't being broken into. The immobiliser doesn't engage, because a valid key is present. Tracking devices help recovery but don't prevent the theft.

How common is this in Australia?

The numbers are significant and moving in the wrong direction:

Not every one of those is an OBD attack — but electronic methods now account for a substantial share, and they're the fastest-growing category.

Why traditional security doesn't help

DeviceWhat it doesAgainst OBD theft
Factory alarmDetects forced entryDoesn't trigger — entry isn't forced
ImmobiliserBlocks start without a valid keyThe cloned key is valid
Steering lockPhysical obstructionSlows them; can be cut
GPS trackerLocates after theftRecovery, not prevention
Faraday pouchBlocks fob signalStops relay entry — good, and cheap

What actually blocks it

Since the attack depends on the OBD port carrying data, the countermeasures all target that port:

  1. Physical port locks — a steel cover. Cheap, instant, but can be cut or pried. Compared here.
  2. Port re-pinning — rewires the connector so a scanner reads nothing. You carry an adapter for legitimate diagnostics.
  3. Aftermarket immobilisers — a hidden secondary cut-off. Effective, but usually needs professional installation.

Combine any of these with a Faraday pouch for your keys and you've addressed both the entry method and the theft method.

Free things worth doing tonight

Block the port, block the attack

OBD Shield PRO re-pins your port so a key programmer gets nothing. 100% passive, no subscription, 30-day money-back guarantee.

See the kits
Lock vs re-pinningWhich method actually holds up. Where is my OBD port?Find it in under a minute. Most stolen carsIs yours on the list?

Sources