Toyota GB statement on vehicle theft

Diversity at Toyota

We take the issue of Toyota and Lexus vehicle theft very seriously. We are continuously developing technical solutions to make our vehicles more secure, to help reduce the risk of theft.

An enhanced security hardware system was introduced in October 2021 (Lexus) and October 2022 (Toyota) on the latest models targeted by criminals. Since which, we have seen a significant drop in thefts of those models.

For older models, we endeavour to create solutions that can offer enhanced protection to our customers.  Following significant investments by Toyota GB, in line with that of other vehicle manufacturers, newly developed official Toyota and Lexus security hardware components will very soon be available to fit to those targeted models registered before October 2021.

Following communication from Toyota and Lexus in the coming weeks, owners should contact their local dealer to arrange fitment. Customers can already speak to their local dealer about the fitment of a protective plate to block access to the vehicle’s electronics. This is a nationwide customer care offering available on Toyota RAV4 Hybrid, Lexus RX and Lexus NX.

As a vehicle manufacturer, we can never completely eliminate the risk of vehicle theft. This is an industry-wide issue, concerning all vehicle manufacturers and affecting the most popular models first.

In order to further reduce the theft risk, we regularly collaborate and share information with insurance associations, police and law enforcement authorities, theft prevention experts and other key stakeholders around the world. This enables us to understand new threats and techniques used by thieves and develop more secured systems. 

Alongside our efforts, we urge those authorities to focus on reducing the number of thefts. We would also like to see action taken that leads to the end to the online sale of devices used by criminals to steal cars without using the car keys, as these devices serve no purpose other than a criminal one.

How do thieves manage to steal cars in this manner?

The thieves disconnect part of the headlamp and use a malicious device to send signals to the control CAN bus (the communication ‘backbone’ within a car) that allow the doors to open and the car to start without the key or remote control.

Thieves need to:

  • Purchase a relatively expensive rogue device (third-party ‘emergency start‘ device which costs around £2500 – £4000 each)
  • Gain physical access to the vehicle’s CAN bus communication wires for an uninterrupted period.

The third-party ‘emergency start‘ device has the capability to initiate an exploit in the following manner:

  • Once connected to the vehicle’s CAN bus communication wires, the third-party ‘emergency start‘ device can send a prioritised series of CAN signals to bypass the vehicle’s security and immobiliser systems, which could allow a thief to unlock the doors and turn the vehicle’s ignition ON.
  • The third-party ‘emergency start’ device is then disconnected.
  • At this point a thief can enter the vehicle and start the car without the key.

What is Toyota doing to prevent these types of attacks?

Toyota and Lexus take the issue of car theft very seriously.  We are continuously developing technical solutions to make our vehicles more secure to help reduce the risk of theft.

In fact, in the UK market, an enhanced security hardware was introduced in October 2021 on the latest versions of the models that had previously been targeted by criminals. Since then, we have seen a significant drop-off in terms of successful thefts of those models.

For older models we endeavour to create solutions that can offer enhanced protection to our customers. 

We cannot divulge the precise nature of the imminent security enhancement; should we do so we risk offering information into the public domain that could be of interest to criminal parties.

The intention is to make the security enhancement available to vehicles affected by CAN bus theft.

What models are known to be targeted by this issue and are newer models affected?

The models primarily targeted are fourth-generation Lexus RX and the Toyota RAV4. 

For older models we endeavour to create solutions that can offer enhanced protection to our customers.

Since October 2022, Toyota models are subject to a platform change that negates CAN Bus theft. This excludes Hilux, which is not subject to CAN bus attacks.

When did Toyota first become aware of the vulnerability in the security systems?

It is not so much vulnerability of the security systems but more so the growing rise in criminal gangs targeting vehicles for ‘cannibalisation’ and/or complete theft.  

Instances appear to have been rising significantly from 2019-2020.

There are many factors involved and at a global level. This includes parts of the world experiencing parts shortage which results in targeted thefts to supply vehicles and/or parts sent to countries experiencing trade restrictions.

Which models can be fitted with the enhanced security feature?

It can be fitted to Land Cruiser 150, RAV4 and first-generation Toyota C-HR.

When is the enhanced security upgrade going to be available and will it be free of charge?

Exact timings are still to be confirmed. We anticipate being able to advise the Toyota Centre network with full details soon. The security enhancement needs to be carried out at a Toyota Centre. Costs are under review; customers may incur a nominal charge.

Are any new models targeted by thieves?

While no car can be considered 100% immune to criminal intent, more recent models are equipped with enhanced security systems aimed at deterring CAN bus type thefts.

Given that the rise in this type or car theft has been known for several years in other countries and is growing in the UK why wasn’t I told about this?

Toyota takes the issue of car crime very seriously. To protect customers’ vehicles our approach is not to disclose our vehicle theft analysis data. The sharing of information could enable thieves to find ways to circumvent anti–theft technologies or make some models particularly attractive to some thieves and unnecessarily vulnerable to attack.

Is a Vehicle Protection Plate (VPP) available for any Toyota models?

Yes, for RAV4, excluding the Plug-In Hybrid model (which is not susceptible to CAN bus attack). The fitment is chargeable.

What is the countermeasure and what’s the plan moving forwards?

We are continuously developing technical solutions to make our vehicles more secure and reduce the risk of theft. An enhanced security hardware was introduced in October 2022 on the latest versions of the models that had previously been targeted by criminals. Since then, we have seen a significant drop-off in terms of successful thefts of those models.

Why is there no recall for vehicles susceptible to the CAN bus attack?

Recall announcements in the UK are guided by very specific guidelines as drawn up by the Driver and Vehicle Standards Agency (DVSA). To qualify as a recall, the issue must relate to a safety or thermal type issue where there is potential for injury as a result of vehicle manufacture or component failure. Only in these such circumstances can a recall be announced. In recall circumstances, the DVSA will provide manufacturers access to ownership records for purpose of communication. Instances of theft do not trigger a recall.

Will Toyota pay for damage caused by an attempted theft?

No. This will need to be addressed by the customer and the vehicle insurers. While we understand theft or attempted theft can be highly upsetting and, in some cases, a costly experience, in such instances customers are first and foremost victims of crime. Toyota does not cover costs associated with criminal activity either under the terms of the warranty or as goodwill.

What is the position with insuring affected models?

As a manufacturer, we stay close to Toyota Insurance colleagues and indeed all motor insurers. We are aware that in many cases, insurance premiums might have increased as a direct result of vehicle crime. We need to refer you to your insurer for further comment.

1,035 comments

  1. Hello, could you please provide an assessment of the risk level of my vehicle (registration: PY72***, mild hybrid)? Additionally, would you recommend contacting my local dealer to enhance its security? Thank you.

  2. I have just purchased a Toyota C-HR GR sport 22 plate and was not informed or aware of this. Is it at risk of CANBUS theft, will I need an immobiliser for additional protection?
    They should be honest and make us aware of this prior

  3. Toyota UK
    says:
    14 March 2024 at 12:47 pm
    Hi Mark,
    Thank you for confirming.
    Unfortunately, as per our latest statement, your RAV4 is a targeted model.
    However, following significant investments, newly developed official Toyota security hardware components will be available very soon to fit to these targeted models.
    The exact timings of the security enhancement are still to be confirmed. We anticipate being able to advise Centres with full details before the end of April.
    However, a Vehicle Protection Plate is available for your RAV4, please contact your nearest Toyota Centre if you would like to have this fitted.
    Thank you.

    April has come, and April has gone, It’s been more than 6 months beyond “April” and yet there is no fix for the security vunlerability yet…
    Do you have any updates on when this will be available?

    1. Hi Linda, thanks for your comment.

      Please get in touch with your local Toyota Centre to book in for a Tracker fitting. We have no further information at the moment.

      Thanks,

      Toyota UK

  4. Hi, I have a late 2020 mk4 Yaris hybrid. Do you think it has the enhanced security hardware system you mentioned in the article to prevent hackers? Thanks

  5. I have just purchased a Toyota RAV4 Estate 2.5 VVT-I Hybrid, registration number:PL18*** and was not informed or aware of this. Is it at risk of CANBUS theft, will I need an immobiliser for additional protection?

    1. Hi there, thanks for your comment.

      Your vehicle is at risk of CANbus theft, please get in touch with your local Toyota Centre for further advice.

      Thanks,

  6. Two missed calls, second one from Mercedez Benz, which I dn’t hve. If curiosity hadn’t got the better of me I would have ignored this. I called back. Outstanding recall to have a teacker fitted in my car, due to high level of thiefts.

    First I had of this. No email, or letter sent to me prior to the missed two calls, (odd). To which I called back after the second call. Now having the nitty gritty details through the info needed for me to read, I’m glad Iv’e booked my car in to have this fitted. But to firstly get your customers well informed from the off, send the neccessary details via email or post please. Customer’s need to know in advance what the issue may be, instead of telling them once they have called you back, or you do get hold of them.

    1. Hi Ken, thanks for your comment.

      Your Toyota C-HR is deemed as at risk of CANbus theft. We’d recommend getting in touch with your local Toyota Centre for further assistance on this.

      Thanks,

  7. My RAV4 was stolen from our driveway just this weekend, on November 9th. We were not aware of this CANBUS security flaw until now. As a longtime Toyota customer, I am very upset not to have been better informed of such issue.

    1. Hi Tim, we’re so sorry to hear this.

      Sadly vehicle crime is something that always has and likely always will be rife, especially with the higher ticket value vehicles. We hope your RAV4 can be recovered swiftly.

      Thanks,

Leave a Reply

Your email address will not be published. Required fields are marked *

To be the first to hear about all of our latest news, offers and events, check the box below, we’ll send these communications by email, phone, SMS or post. Be assured that Toyota will only share your personal information with companies that are an integral part of fulfilling the services we deliver. If you would like to find out more about how we process your data please visit our privacy policy for details.

I understand that I can unsubscribe at any time.