Morning Overview

Hyundai and Kia became America’s most-stolen cars almost overnight

Few brands have watched their reputation flip as fast as two Korean automakers did when a hardware shortcut collided with social media. Vehicles that had sold for years on value and warranties suddenly became the easiest targets on the street, hauled away with little more than a screwdriver and a common charging cable. What turned a quiet engineering gap into a nationwide theft wave was not a new criminal technique but the speed at which the method spread once it was filmed and shared.

The result was a surge in stolen cars concentrated on specific model years, a scramble by cities and insurers to respond, and a lasting lesson about how a single omitted part can cascade into a public-safety problem. The story is less about clever thieves than about a vulnerability that sat unnoticed until it was handed a megaphone.

The missing part that opened the door

At the center of the crisis was the absence of an engine immobilizer, a standard anti-theft component that prevents a car from starting unless it detects the correct key. Roughly 8.3 million Hyundai and Kia vehicles built between 2011 and 2022 lacked that industry-standard part, as documented in the history of the theft phenomenon. Without an immobilizer, the ignition could be defeated mechanically, allowing a thief to start and drive off using ordinary hand tools.

The scale of the omission was stark when measured against the rest of the industry. In the mid-2010s, only about a quarter of the two brands’ cars included immobilizers, while roughly 96 percent of other manufacturers’ vehicles came with them. That gap meant a large slice of the affected fleet could be started with a USB cable and a screwdriver, a method simple enough for anyone to replicate once shown how.

How social media turned a flaw into a wave

The vulnerability had existed for years, but it became a crisis only when it was demonstrated at scale. The trend traces to Milwaukee around 2021, where local youths who called themselves by a nickname began filming break-ins and joyrides. Those clips migrated to major platforms, where hashtags tied to the challenge accumulated hundreds of millions of views and step-by-step tutorials spread the technique nationwide.

From there the copycat thefts jumped city to city, reaching Chicago, Los Angeles, Philadelphia, Seattle, Atlanta, and dozens of others. The videos did more than glorify the act; they functioned as instructions, collapsing the learning curve for would-be thieves to the length of a short clip. In some cities the theft rate for the affected models spiked by more than 1,000 percent, and the wave was linked to deaths and crashes as inexperienced drivers fled in stolen cars.

Topping the most-stolen lists

The consequence showed up plainly in national crime data. By the 2023 tally, the two brands’ models were by far the most stolen vehicles in the country, according to figures from the insurance industry’s crime bureau reported by analysts tracking the data. Cars that had never featured prominently on theft rankings suddenly dominated them, displacing the pickups and sedans that traditionally led the list.

The fallout reached beyond raw theft counts. Some insurers grew reluctant to write or renew coverage on the affected models in high-theft areas, leaving owners caught between a car that was easy to steal and a policy that was hard to obtain. The financial and practical burden landed on drivers who had simply bought an affordable vehicle without knowing it lacked a part most competitors treated as standard.

The recall pressure and the response

As thefts mounted, officials pushed for a formal response. A coalition of state attorneys general urged federal regulators to order a recall of the vulnerable vehicles, a step reported when 17 states pressed the case. Cities that had absorbed the theft surge filed lawsuits against the automakers, arguing that the missing immobilizers had created a foreseeable public-safety problem.

The manufacturers responded with a free software update rather than a hardware recall in most cases. The patch requires the key to be present before the engine will start and extends the vehicle’s alarm duration, closing the specific loophole the challenge exploited. The companies also began installing immobilizers as standard equipment on new cars, distributed steering-wheel locks in hard-hit areas, and reached settlements tied to the thefts. The fixes reduced the vulnerability going forward, though the millions of older cars already on the road still depend on owners actually installing the update.

The episode stands as a case study in how a small cost-saving decision can carry an outsized bill. Leaving out a component that most of the industry considered baseline saved money at the factory but exposed millions of owners to theft, insurers to losses, and cities to a wave of stolen vehicles once the method went viral. The lasting takeaway is that a vulnerability is only as contained as its obscurity, and social media has a way of erasing obscurity overnight, turning a quiet engineering gap into one of the most visible theft stories of the decade.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview