15 July 2026
Relay Attack Car Theft in the U.S.: What the Viral Video Shows—and What the Data Cannot Prove
Car Tech
A June 2026 video revived fears about a relay device described as Russian. The attack class is real; the device’s provenance and any nationwide U.S. surge are not established.
Relay attacks are technically real. A peer-reviewed paper presented at NDSS in February 2011 (Francillon, Danev, and Čapkun) showed that passive keyless entry and start can be defeated by relaying the radio exchange between a car and its key, and security researchers have treated relay as a live attack class ever since. In June 2026, Mark Rober published a video that depicts a relay-style attack and frames the hardware as an “old Russian” device bought on a hidden marketplace. Nothing in the public record establishes that the device was manufactured in Russia, who the seller was, or where it shipped from.
What the national numbers can and cannot do matters just as much. The FBI’s incident system counts vehicle thefts but carries no method-specific code for relay, so no public U.S. dataset can say how many thefts use it. NIBRS includes a broad computer-equipment indicator, but no public method-specific code for relay attacks, OBD key programming, CAN injection, or key emulation, and its Method of Entry field applies to burglary, not motor-vehicle theft. Total theft is not relay data.
The U.S. record does establish one thing. At least one police department — North Miami — has reported finding an item it called an “RFID Relay Attack Device.” That documents possession of a labeled device; it does not establish how often the method is used, and it is not evidence of a nationwide trend.
For anyone driving or shopping for a keyless premium car, the sensible response is to check the specific car rather than react to the clip. Verify the model-year’s access system and its security settings before you buy or keep it; cross-shop when passive entry can’t be disabled, when insurance exposure is materially worse, or when access credentials can’t be fully reset; and treat a certified-pre-owned badge as meaningful only if the program will document the car’s keys, accounts, and updates. Every model-specific conclusion here is a framework to run against a real VIN, not a verdict on any named car.
What the Mark Rober video shows — and what it can’t establish
The clip that reignited the conversation is a June 2026 entertainment video from Mark Rober. It depicts a keyless car being unlocked and started while the owner’s key sits inside a house, it recounts buying a relay device from a seller persona on a hidden marketplace, and it later shows the team building a cheaper rig from off-the-shelf parts to make the same point. It also shows shielding — putting the key in a metal container — stopping the rig.

As a source, the video is primary evidence of what Mark Rober says and what the edited footage depicts, and it is a strong signal of public attention. It is not a lab certification of the device’s performance, not law-enforcement evidence of how often the method is used, and not proof of where the hardware came from. The “old Russian” description and the Russian-coded seller persona are part of the video’s story. Independent evidence of Russian manufacture, of the seller’s identity or location, and of the package’s country of origin is not available in public sources. Treat “Russian device” as framing that has not been verified.
How a classic relay attack works
A passive keyless system lets you unlock and start a car without pressing a button, because the car and the key hold a short radio conversation whenever they are close. The car checks that its key is nearby; the key answers; the car opens.
A classic relay does not break that conversation — it stretches it. A classic relay requires the legitimate key to respond during the vehicle’s authentication exchange. One device sits near the car and another near the key, through a wall for example, and together they carry the signals far enough that the car behaves as if the key is beside it. Nothing is decrypted, and no new key is created. Because the attack depends on the real key answering, a shield that blocks the fob’s signal can defeat it, and a fob that stops transmitting after it has been still for a while narrows the window — though how well any of this holds depends on the enclosure, the habit of using it, and the vehicle’s own access design. The 2011 research established this class of attack more than a decade before the current video, so it is old news to security engineers even where it is new to owners.
“Electronic theft” is several different problems
Much of the online confusion comes from treating every high-tech theft as one thing. Relay is a single method, and the defenses that stop it do nothing against the others. In April 2026 the U.S. Attorney’s Office for D.C. unsealed an indictment alleging that a ring used On-Board Diagnostics (OBD-II) devices to reprogram stolen cars to accept blank key fobs and to disable tracking before shipping vehicles to Ghana; the defendants are presumed innocent. That is key programming, not a relay attack. The table separates the methods a buyer actually needs to tell apart.
| Method | Does the real key need to be nearby? | What it changes in the vehicle | Does key shielding (Faraday) help? |
|---|---|---|---|
| Classic relay | Yes — it forwards the key’s live signal | Nothing lasting; the car is fooled in the moment | Can help, if the enclosure actually blocks the fob’s signal |
| OBD key programming | No | Registers a new working key to the car | No |
| CAN injection | No | Sends commands on the car’s internal network | No |
| App / digital-key account compromise | No | Uses app or cloud credentials to unlock or start | No |
What current U.S. theft data shows
The headline numbers are real, and they point away from panic. NHTSA reports that more than 650,000 vehicles were stolen in the United States in 2025, about one every 48 seconds. NICB, analyzing reported thefts, puts 2025 at 659,880 — a 23% drop from 2024, which had itself fallen 17% — the lowest level in decades, with theft still concentrated in large metropolitan areas.
NICB also publishes a most-stolen-model list. That list describes which vehicles were reported stolen, not how they were stolen, and it cannot be used as a proxy for relay susceptibility. The totals and the rankings tell you the scale and the targets of theft overall; neither speaks to the share taken by any one electronic method.
Why national data can’t isolate relay theft
The reason no one can put a national number on relay is structural, and it sits in how the FBI collects crime data. NIBRS records an offender-tool field, Data Element 8, whose options include “Computer Equipment (Handheld Devices)” — one broad flag that cannot separate a relay box from an OBD programmer, a CAN tool, an emulator, or a phone. The field that records how entry was gained, Data Element 11 (Method of Entry), applies only to burglary, and Motor Vehicle Theft is a different offense entirely. So the public tables show how many cars were stolen, not how many were taken by relay, whether that share is climbing, or how it compares with other methods. A claim of widespread or increasing relay theft reads something into the data that the data does not hold.
The record does establish one U.S. data point. North Miami PD reported that a suspect possessed an item it described as an “RFID Relay Attack Device.” The public page does not establish the device’s exact function, its use in the cited theft, or the case’s final disposition. It is an official police account of a labeled device — not a forensic teardown, and not evidence of scale.
Before you buy or keep a keyless car
The useful questions are specific to the car in front of you, because access hardware and settings vary by model year, market, and trim. Ask the seller or dealer to show, in the car’s menus or service records: whether passive entry and start can be turned off; how many physical keys and fobs are registered; whether missing or extra keys have been deleted from the car’s list; whether the previous owner’s app account and digital keys have been transferred or revoked; and whether security and telematics software is current, with an active subscription. Get a VIN-specific insurance quote while you are at it, since exposure varies by car.
For theft history, no single database is complete. NICB’s free VINCheck screens a VIN against participating insurers’ theft and salvage records; by NICB’s own description it does not query law-enforcement records or non-participating insurers and is not a comprehensive vehicle-history report. A NMVTIS-approved report — the Justice Department’s national title system — adds a vehicle’s title, latest odometer reading, brand history, and in some cases theft data, though more than half of the states report into it, so gaps remain. Use VINCheck as one free screen, add an NMVTIS-approved report and an independent inspection, and treat any single source as partial.
On certified-pre-owned: do not assume a CPO label covers registered-key status, digital-key revocation, account transfer, or security software. Check the program’s actual inspection checklist and get written confirmation from the dealer. A CPO badge is worth having, but it does not, by itself, resolve electronic-theft exposure. If the paperwork shows key count, account transfer, digital-key revocation, security updates, and no disclosed theft or recovery record in the checks performed, that changes the picture; if it doesn’t, treat the gap as unpriced risk.
Countermeasures, and their limits
Defenses split into ones that reduce the chance of theft and ones that only help afterward, and each addresses a different layer. Shielding the key in a Faraday pouch targets classic relay by blocking the fob’s signal, and it works only when it actually blocks the signal and you use it every time. Disabling the relevant passive-entry or passive-start function can remove or reduce the classic relay path, depending on what the setting disables. Account security — multi-factor authentication and prompt digital-key revocation — is what addresses app and cloud compromise. Physical measures such as a start PIN, an OBD-port lock, or a wheel lock add time and visibility against the methods they fit. Trackers and telematics support recovery rather than preventing theft, and they can be found and disabled. None of these covers every route, and no single one makes a car theft-proof.
Ownership and insurance receipts
A stolen car is a financial event as much as a security one, and recovery does not erase the cost. Per NAIC, comprehensive coverage — which is optional — typically includes theft, subject to your deductible. A total-loss payout reflects the car’s actual cash value: what it was worth as a used car just before the loss, not Blue Book and not what you paid. Optional GAP coverage, where you carry it, can address a loan or lease balance above that payout, and rental reimbursement, if you bought it, is capped by a dollar limit in your policy. If the car is recovered with damage, comprehensive coverage may respond to covered recovery damage, subject to the policy, deductible, investigation, and state rules.
One point deserves care, because keyless thefts often leave no broken glass. The regulator and insurer guidance reviewed here did not identify a nationwide rule requiring visible forced-entry damage for a theft claim. That does not mean every claim is paid: policy language, evidence, exclusions, and state rules still control. Before you rely on any of this, read your own policy in your own state, and ask your insurer directly how they handle a theft with no forced-entry evidence.
The bounded buyer judgment
The evidence rewards a clear head over a universal verdict. Whether a given keyless car is a reasonable buy or keep depends on things you can check: the exact model-year access system, how completely its credentials can be reset, where it is parked overnight, and how its theft exposure prices out in an insurance quote. Treat an inability to disable passive access as one factor to weigh when cross-shopping, not an automatic disqualification. Cross-shop when credentials cannot be fully reset, when the seller cannot document the car’s keys and accounts, when insurance exposure is materially worse, or when the available security layers do not fit how and where you park. Prefer a CPO car only when the specific program and dealer will document the relevant checks in writing. Each of these is a framework to run against a real VIN — not a verdict on any model.
FAQ
If there’s no broken glass or damage, does that prove a relay attack?
No. Absence of forced entry fits several methods — a classic relay, key programming through the OBD port, a cloned or extra key, or app-account access — and it also fits an unlocked car or owner error. An individual theft can still be investigated and attributed by police, but the national public dataset does not expose a relay-specific method code, and a lack of broken glass on its own does not prove relay.
Does a Faraday pouch make my car safe from theft?
It can reduce classic relay exposure if it actually blocks the fob’s signal. It does not address OBD programming, CAN injection, account compromise, stolen keys, or tow-away theft, and it only helps when you use it every time. Shielding is a sensible habit, not a guarantee.
Was the device in the viral video actually made in Russia?
Not established. Mark Rober’s video uses Russian framing and a Russian-coded seller persona, but public evidence does not establish Russian manufacture, the seller’s location, or the shipment’s origin. The relay technique itself is real and documented in research since 2011; the provenance of that specific unit is unverified.
Sources Checked
- NHTSA, Vehicle Theft Prevention — 2025 U.S. theft total and rate. https://www.nhtsa.gov/vehicle-safety/vehicle-theft-prevention (accessed July 15, 2026)
- National Insurance Crime Bureau, U.S. Vehicle Thefts Experience Historic Decline (March 18, 2026) — 2025 reported-theft total and decline. https://www.nicb.org/news/news-releases/us-vehicle-thefts-experience-historic-decline (accessed July 15, 2026)
- FBI CJIS, 2025.0 NIBRS User Manual (document date June 23, 2025) — Data Element 8 (p.102) and Data Element 11 (p.114). https://le.fbi.gov/file-repository/nibrs-user-manual-2025-0-062625.pdf (accessed July 15, 2026)
- FBI CJIS, 2025.0 NIBRS Technical Specification (document date June 16, 2025) — Data Element 8 (Table 3-18) and Data Element 11 (Table 3-22). https://le.fbi.gov/file-repository/2025-0-nibrs-technical-specification-062625.pdf (accessed July 15, 2026)
- U.S. Attorney’s Office, District of Columbia, International Car Theft Ring Busted (April 22, 2026) — OBD-II key-programming allegation. https://www.justice.gov/usao-dc/pr/international-car-theft-ring-busted (accessed July 15, 2026)
- North Miami Police Department, November 2022 — police account referencing an “RFID Relay Attack Device.” https://www.northmiamifl.gov/1201/November-2022 (accessed July 15, 2026; department page text confirmed on its own domain)
- Francillon, Danev, Čapkun, Relay Attacks on Passive Keyless Entry and Start Systems in Modern Cars, NDSS Symposium, February 7, 2011 — technical feasibility of relay attacks. https://www.ndss-symposium.org/ndss2011/relay-attacks-on-passive-keyless-entry-and-start-systems-in-modern-cars/ (accessed July 15, 2026)
- NICB VINCheck — scope and stated limitations. https://www.nicb.org/vincheck (accessed July 15, 2026)
- U.S. Department of Justice (BJA), NMVTIS — For Consumers — data provided and state-reporting gaps. https://vehiclehistory.bja.ojp.gov/nmvtis_consumers (accessed July 15, 2026)
- NAIC, Auto Insurance — comprehensive coverage and theft, actual cash value, rental reimbursement. https://content.naic.org/consumer/auto-insurance.htm (accessed July 15, 2026)
- Mark Rober (YouTube), I Outsmarted Pro Car Thieves (June 2026) — the viral relay-style demonstration and “old Russian” framing. https://www.youtube.com/watch?v=h0EGCnBjTVk (existence, title, and channel confirmed; video content not independently verifiable frame by frame)
Limitations
- No hands-on testing. FSC has not driven, inspected, purchased, scanned, timed, or reproduced any relay or key-programming device. All findings come from public documents and media.
- The viral video was not independently verified frame by frame. Its exact runtime, precise timestamps, and which sequences are continuous versus edited or staged were not confirmed; the video is paraphrased rather than quoted from timings, and its “Russian” framing is treated as unverified.
- National prevalence is unmeasurable from public data. U.S. datasets count thefts but do not code method, so this article makes no claim about how common relay theft is, whether it is rising, or how it compares with other electronic methods.
- The North Miami case is a police label, not a forensic finding. It documents possession of a device the department called a relay tool; the device’s exact function, its use in a specific theft, and any disposition are not established here.
- The D.C. case is an allegation. The indictment describes an OBD-II method; guilt is not adjudicated.
- Insurance, VINCheck, NMVTIS, and CPO points are structural, not policy- or program-specific. Coverage, database scope, and CPO checks vary by insurer, provider, program, and state and must be confirmed directly.
- Deferred for separate verification: exact enacted federal and state statutes on relay/key-programming tools; ultra-wideband secure-ranging effectiveness and its published attacks; and model-year-specific access architectures. None are asserted as fact here.