Connect with us

Technology

New bank scam laws could stop suspicious payments

Published

on

New bank scam laws could stop suspicious payments

NEWYou can now listen to Fox News articles!

Your phone rings, and the caller says your bank account is under attack. To protect your savings, you must move the money right now. The caller sounds calm. The instructions feel official. However, the “safe account” belongs to a scammer. That pressure can turn years of savings into an irreversible transfer. Georgia now gives some banks and credit unions another chance to interrupt the payment before the money leaves.

House Bill 945 took effect July 1, 2026. The law lets financial institutions pause certain transactions when they reasonably suspect financial exploitation. It protects adults age 65 or older. It also covers adults with qualifying physical or mental incapacities, Alzheimer’s disease or dementia. The idea sounds simple. Yet the details matter because your bank’s power may depend on your state, your account and the institution’s own policy.

YOUR FAMILY COULD BE ONE PHONE CALL FROM A BANK SCAM

Free live CyberGuy class: Sick of Spam? Join us July 22.

Advertisement

Join us Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

Georgia’s new bank scam law lets financial institutions pause certain suspicious transactions involving older or vulnerable adults. (Getty)

Georgia’s new bank scam law can pause a suspicious payment

Under Georgia’s law, a financial institution may place a hold on a transaction linked to suspected exploitation. The law can cover an eligible adult’s account or an account where that adult is a beneficiary. It can also reach an account belonging to someone suspected of carrying out the exploitation. That last provision gives the law extra reach. In practice, it could help when suspicious money arrives in another customer’s account. The institution may have room to stop the payment from moving farther when the facts support concern.

However, the law gives banks discretion. It says a financial institution may place the hold, but it does not require one. Therefore, a worried teller or fraud analyst still has to notice the warning signs and act. The law also focuses on the suspicious transaction. It does not automatically shut down every payment or withdrawal connected to the account.

Advertisement

A possible 30-day delay comes with limits

A Georgia hold initially expires after 15 business days. The bank may add up to 15 more business days if its review still supports the exploitation concern. A court may shorten or extend that period. The bank must notify authorized account parties and any trusted contact within three business days. It can skip someone it reasonably suspects of taking part in the exploitation. The institution must also begin reviewing the facts behind its decision.

Before using this power, the institution must train the employees involved. It also needs written procedures for reviewing suspected exploitation. The law gives institutions liability protection when they act in good faith and use reasonable care.

A trusted contact can help without controlling your money

Georgia’s law also allows an eligible adult to name a trusted contact for an account. That person could be a relative, friend or another adult the account owner trusts. The bank may contact that person when it suspects exploitation. It may also ask for help confirming contact information, health status or the identity of someone holding power of attorney. In some cases, the institution may share only that it suspects exploitation.

A trusted contact does not automatically gain access to your balance. The role also does not grant authority to move your money or make decisions for you. Federal regulators describe the contact as a backup person whom the institution can alert when something looks wrong.

Which states let banks pause suspected scam payments?

Georgia is part of a much larger shift. As of today, at least 33 states have enacted laws that let banks, credit unions or other covered financial institutions delay certain transactions when they suspect financial exploitation.

Advertisement

The FTC’s most recent nationwide chart identified 24 states with these laws.

However, the agency warned that its chart was only a snapshot and advised readers to check current state statutes.

However, the agency warned that its chart was only a snapshot and advised readers to check current state statutes. Since that report, nine additional states have enacted protections.

These 33 states have enacted transaction-hold protections

The states are:

  • Alabama, Arkansas, Colorado, Connecticut, Delaware, Florida, Georgia and Idaho
  • Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi and Montana
  • Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Oklahoma, Oregon and Rhode Island
  • South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington and Wyoming

The laws do not give every bank the same power. Some let an institution pause a payment on its own. Others require a report to law enforcement or adult protective services. The protected age can also vary, while several states include younger adults with qualifying disabilities. Hold periods differ even more. A delay may last only a few business days in one state. Elsewhere, an investigation or court order can keep the payment on hold much longer.

HOW FLORIDA RETIREE LOST $200K IN FAKE PAYPAL REFUND SCAM

Advertisement

Scammers often pressure victims to move money quickly, while transaction-hold laws aim to create time for review. (Photo by Nikolas Kokovlis/NurPhoto via Getty Images)

Nine states have joined the list since the FTC’s last review

Here is what the newer state laws do.

Colorado

Colorado’s HB 26-1110 created the Adults’ Security and Safeguards from Exploitation in Transactions Act, known as the ASSET Act. It lets a bank or credit union delay a disbursement when it reasonably believes a vulnerable adult faces financial exploitation. The institution must notify law enforcement or adult protective services. A decision generally must be made within 90 days. That period can reach 180 days when an agency investigation remains underway. The law takes effect August 12, 2026.

Georgia

Advertisement

Georgia’s HB 945 lets a financial institution place a hold on a suspicious transaction involving an eligible adult. The law also reaches accounts where the adult is a beneficiary. In some cases, it can cover an account belonging to the suspected perpetrator. The initial hold lasts up to 15 business days. A bank may extend it for another 15 business days when its review continues to support the concern. The law also includes trusted contacts, employee training and written notice requirements.

Idaho

Idaho enacted HB 182, known as the Report and Hold law, in 2025. It covers a broad range of financial businesses, including banks, credit unions, lenders, money transmitters and investment firms. Covered professionals may temporarily pause suspicious transactions and report suspected exploitation. The law also gives them liability protection when they act in good faith.

Maine

Maine’s 2025 law covers adults age 65 or older and people protected by the state’s Adult Protective Services Act. A bank or credit union may delay a disbursement when it reasonably believes the payment could result in exploitation. The institution must notify the Maine attorney general within two business days. The hold generally ends within 15 business days unless a court extends it. Customers may also be able to designate a trusted contact.

Advertisement

Maryland

Maryland’s Vulnerable Adult Banking Protection Act covers residents age 65 or older and vulnerable adults who cannot provide for their daily needs. A financial institution may delay or deny a suspicious disbursement. An initial delay can last 15 business days. The institution or an investigating agency can extend it for up to 25 business days from the original request date. The law takes effect October 1, 2026.

North Carolina

North Carolina’s SB 595 gives financial institutions broad authority to delay or refuse transactions involving suspected exploitation of older or disabled adults. The law covers withdrawals, transfers and some requested account changes. An initial delay can last up to 30 business days. The institution may extend it for another 30 business days if it continues to believe exploitation is occurring. Banks may also alert a trusted contact.

Oklahoma

Advertisement

Oklahoma’s SB 2067 requires financial institution employees to report suspicious activity internally and notify an appropriate agency. Banks and credit unions may place a temporary hold on a reported account. They can also contact someone previously designated by the account holder. The law takes effect November 1, 2026.

South Dakota

South Dakota’s HB 1238 lets a financial institution delay or refuse certain transactions when it reasonably believes exploitation may have occurred or is being attempted. The law protects senior and vulnerable adults. It also covers a consenting adult who asks the institution to take protective action.

Vermont

Vermont’s Act 106 lets covered financial institutions delay a transaction when they reasonably believe a customer faces financial exploitation. The initial delay can last 15 business days. The institution may add another 15 days when it believes the exploitation may continue. Vermont approved the law on May 20, 2026.

Advertisement

Why bank scam protections vary by state

The federal Senior Safe Act encourages financial professionals to report suspected exploitation. It also offers liability protection to covered institutions and trained employees who make qualifying reports. However, the law does not create one nationwide transaction-hold rule for checking and savings accounts. Investment accounts follow a different framework. FINRA Rule 2165 lets a brokerage firm temporarily hold certain disbursements or securities transactions when it reasonably believes an eligible adult faces financial exploitation.

The rule generally covers adults age 65 or older along with some younger adults who have qualifying impairments. As a result, a brokerage firm may have national regulatory authority to pause a suspicious request. A bank handling your checking account may depend more heavily on the law in your state.

A state law still cannot guarantee your payment will stop

Most state laws give a bank permission to act rather than requiring it to block every suspicious payment. The institution still needs to recognize the warning signs and have enough information to reasonably suspect exploitation. Your protection may depend on your age, the account involved and where you live. Your bank’s internal policies and employee training also play a role. Even in a state with a transaction-hold law, a payment may go through before anyone realizes a scam is underway.

Scammers know speed works in their favor

CyberGuy has reported on grandparent scams that use urgent calls, stolen details and AI-cloned voices. We have also covered crypto kiosk scamswhere frightened victims followed a caller’s instructions while the money moved beyond easy recovery. Georgia also used HB 945 to add safeguards for virtual currency kiosks, another payment method scammers use to move money quickly.

In both cases, the scammer wants to keep you isolated. They may warn you not to call your family or bank. They might claim that an employee is part of the investigation. A transaction hold attacks that pressure tactic. It adds time, which gives someone a chance to ask a basic question: Does this story make sense? Of course, no law will catch every scam. A payment can move through a different state, another financial service or a crypto wallet. Also, a bank may miss the warning signs or choose not to place a hold.

Advertisement

THE GIFT THAT PROTECTS YOUR DAD FROM SCAMMERS

House Bill 945 took effect July 1, 2026, giving Georgia banks more authority to delay payments tied to suspected exploitation. (Kurt “CyberGuy” Knutsson)

Do these bank scam transaction hold laws work?

An ABA Foundation survey commissioned from 158 banks offers an early view. Half of the responding banks in states with hold laws said they had used the authority to delay, refuse or hold transactions. Nearly 90% of respondents in states without such laws supported adopting them. The survey reflects the banking industry’s experience rather than a nationwide independent study. Even so, it shows that banks see value in having time to investigate.

That time can also create a difficult balance. Banks need enough authority to stop a devastating payment. Yet they must avoid blocking legitimate transactions based on age alone. Georgia tries to address that concern with a reasonable-cause standard. It also requires notice, employee training and an internal review. Whether the law succeeds will depend on how institutions use those tools.

How to protect your money from bank scams

You should not assume your bank can reverse a scam payment. You also cannot count on it pausing every suspicious transaction. The safest approach is to put protections in place before an urgent call, text or email catches you off guard.

Advertisement

1) Ask your bank about trusted contacts and transaction holds

Call your bank’s fraud department and ask whether you can add a trusted contact to your account. Then ask what the bank does when an employee suspects financial exploitation. You should also find out whether your state allows the bank to delay a suspicious transaction. The answer may differ between your checking account and your brokerage account.

2) Turn on instant alerts for account activity

Enable notifications for withdrawals, transfers and card purchases. Choose the lowest available dollar threshold so you hear about unusual activity quickly. Also review your bank’s daily transfer and wire limits. Lower limits can make it harder for a scammer to move a large amount of money in one transaction.

3) Make sure your trusted contact understands the role

Choose someone who will answer quickly and question an unusual request. Make sure that person knows your bank may call if something appears wrong. A trusted contact does not automatically gain access to your money. The role gives your bank another way to reach someone you trust during a possible emergency.

4) Create a family code word for emergencies

Choose a private word or phrase that family members can use to verify a real emergency. If someone calls claiming a loved one needs money, ask for the code word. Then hang up and contact your relative through a phone number you already have. Never call a number provided by the person demanding payment.

5) Never transfer money to a so-called safe account

A bank, government agency or law enforcement officer will not tell you to protect your savings by transferring them to another account. Scammers often use the phrase “safe account” to make a fraudulent transfer sound official. Do not send money through a wire transfer, cryptocurrency kiosk or payment app while someone is pressuring you to act immediately. End the conversation and call your bank using the number on the back of your card or its official website.

Advertisement

6) Use strong security software on your devices

Strong antivirus software can help detect malicious links, fake websites and downloads that scammers use to steal financial information. Keep the software updated on your phone and computer. Security software cannot stop every phone scam. However, it can block some of the digital tools criminals use before they reach your bank account. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

7) Reduce the personal information scammers can use

Scammers may pull your age, relatives’ names, phone number and address from data broker and people-search websites. They can use those details to make a fake emergency sound convincing. A data removal service can help reduce how much personal information appears on these sites. It cannot remove every record from the internet, but it can make it harder for criminals to build a detailed profile around you or your family. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.

8) Act quickly if money starts moving

Call your bank’s fraud department as soon as you suspect a scam. Ask the institution to stop, recall or flag the transaction. Change your online banking password from a trusted device and review recent account activity. If you shared login details, ask the bank whether it should lock online access or issue new account numbers. Next, report the incident to local law enforcement and the appropriate fraud agency. For suspected elder financial abuse, you can also contact Adult Protective Services in your state.

Kurt’s key takeaways

Georgia’s new law gives financial institutions explicit authority to pause certain transactions when they suspect financial exploitation. However, the hold remains optional, and the protection applies only in qualifying situations. The issue reaches far beyond Georgia. At least 33 states have enacted some form of transaction-hold authority for banks or credit unions, although several newer laws have later effective dates. The protections still vary, so your state and financial institution can shape what happens during the most urgent minutes of a scam. Add a trusted contact where available. Talk with your family about how to verify an emergency and learn how your bank handles suspicious payments. A five-minute conversation today could create the pause that saves someone’s life savings later.

Should a bank have the power to delay your payment when it believes a scammer is directing you, even if you insist the transfer is legitimate? Let us know by writing to us at CyberGuy.com.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

X replaces its revenue-sharing program with ‘Original Content Rewards’

Published

on

X replaces its revenue-sharing program with ‘Original Content Rewards’

X is ending its controversial revenue-sharing program for content creators, which has seen numerous revisions under Elon Musk’s reign. In its place, it’s launching a new Original Content Rewards program on September 8th. To be eligible, creators must have at least 500 verified followers and at least 500,000 Home Timeline impressions from verified users in the last 90 days, among other requirements.

Creators will then earn revenue based on “qualified impressions” on “original content.”Qualified impressions are unique impressions from Premium subscribers “on the Home Timeline feed, where at least 50% of the post is visible.” What qualifies as “original content” exactly? Well, that’s a little harder to define. Under the guidelines, original reporting or analysis, videos and photos taken by the user, as well as graphics or illustrations made by the creator, including memes. X also says that commentary or reactions still qualify, as long as they “add something meaningful.”

In the post announcing the program, the company says the goal is to shift the focus away from exploiting loopholes and clickbait. Simply repurposing content from others or replying to posts wouldn’t be a viable source of income under the new system, theoretically. Allegra Jacchia, Senior Product Manager, Creators at SpaceXAI, said on X that the program was designed to “reward the creators who bring original ideas, expertise, creativity, and unique perspectives to 𝕏 — not those who have become best at gaming the system.”

Participants in the revenue-sharing model will continue to earn revenue through September 7th.

Continue Reading

Technology

KARR Bluetooth flaw exposes 2.2M cars to theft risk

Published

on

KARR Bluetooth flaw exposes 2.2M cars to theft risk

NEWYou can now listen to Fox News articles!

Could a small device hidden beneath your dashboard make your car easier to break into? Nancy from Newtown, Pennsylvania, asked me where she should look for the KARR or SWDS “code” in her 2025 Cadillac XT5 and 2024 Hyundai Tucson Limited Hybrid.

Here is the first thing you need to know. There is no code to find in your vehicle’s settings. KARR and SWDS refer to aftermarket security hardware that a dealership may have installed before selling the car. SWDS stands for Southwest Dealer Services, the company associated with several KARR-branded vehicle protection products.

The device usually sits beneath the dashboard on the driver’s side. You may also find a KARR or SWDS sticker on the driver-side window.

So, before you start searching through menus or calling the automaker, here is how to find out whether your vehicle has one of these devices and what to do next.

Advertisement

15 SECURITY ESSENTIALS TO KEEP YOUR VALUABLES SAFE FOR SUMMER TRAVEL

A Bluetooth flaw in dealer-installed KARR and SWDS security devices could expose about 2.2 million vehicles to unauthorized access. (David Baillot/University of California San Diego/Jacobs School of Engineering)

CyberGuy Live: Missed “Sick of Spam?” Get the replay and checklist

Our free CyberGuy Live class “Sick of Spam?” has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt “CyberGuy” Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.

Get the free replay and checklist now at CyberGuyLive.com.

Advertisement

KARR Bluetooth car hack puts 2.2 million vehicles at risk

Computer security researchers at the University of California San Diego uncovered a Bluetooth vulnerability affecting at least 2.2 million vehicles. The flaw involves dealer-installed KARR and SWDS security devices. A person standing within about five yards of a vulnerable vehicle could connect to the device through Bluetooth.

From there, an attacker could lock or unlock the doors. The same flaw could silence the alarm, sound the horn or flash the headlights. An attacker could also prevent a parked vehicle from starting. However, the researchers did not report that the flaw could start the engine or shut down a vehicle that was already running. That distinction is important. The Bluetooth flaw alone does not let someone drive away. However, it could quietly unlock the doors. A thief could then use separate tools to create or program a key.

What are KARR and SWDS car security systems?

KARR systems are aftermarket vehicle security products sold through participating dealerships. They may include an alarm, GPS tracking, remote vehicle controls or an ignition-disabling feature. Southwest Dealer Services uses several product names, including KARR Security, KARR Fusion, KARR BT, KARR S.W.A.T. and S.W.A.T. Dealer. The features vary by product and vehicle.

These devices do not come from Cadillac, Hyundai, Ford or another automaker’s factory. A dealership or one of its vendors adds the hardware after the vehicle arrives. Dealers may use the system to protect inventory sitting on the lot. When someone buys the vehicle, the dealer may offer the system as an additional security package. The problem is that some dealers left the hardware connected even when buyers declined the service. As a result, a driver might have a vulnerable device without an active KARR account or any idea that the equipment is inside the car.

How the KARR Bluetooth vulnerability works

The KARR device communicates with a smartphone app through Bluetooth Low Energy. Researchers found that the affected devices relied on the same secret authentication key. Once they recovered that key, they could send commands that vulnerable KARR devices accepted.

Advertisement

Think of it as giving a huge group of devices the same unchangeable password. Once that password becomes known, each device becomes easier to approach. The researchers also found that the devices broadcast recognizable Bluetooth signals. Historical databases containing those signals could reveal where a particular device had appeared. That creates a privacy concern beyond car theft. Someone could potentially use the data to study where a vehicle regularly parks or travels.

Which cars may have a KARR or SWDS device?

UC San Diego researchers found the devices most often in vehicles sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California since 2017. However, that list does not mean other brands are safe.

KARR works with more than 3,000 dealerships nationwide. Vehicles also move around the country through used-car sales, auctions and dealership trades. Therefore, the vehicle’s make and model cannot confirm whether it has the equipment. The dealership that prepared the vehicle for sale matters more than the badge on the grille. A Cadillac, Hyundai or Chevrolet could have a KARR system if the selling dealer installed one. A Honda from another dealership might never have received it.

How to check your car for a hidden KARR device

Start with the easy clues before you remove any trim or crawl too far beneath the dashboard.

Check the driver-side window for a KARR sticker

Look at the lower corners and edges of the driver-side window.

Advertisement

The sticker may say:

  • KARR
  • KARR Security Systems
  • SWDS
  • S.W.A.T.

A sticker strongly suggests that the dealership installed a related device. However, the absence of a sticker cannot completely clear your vehicle. A dealer or previous owner may have removed the label while leaving the hardware connected. UC San Diego says many affected vehicles have the sticker, rather than every affected vehicle.

Look below the driver-side dashboard

Park the vehicle and shut off the engine. Move the driver’s seat back and use a flashlight to look beneath the lower dashboard. Researchers say the device is usually installed underneath the dashboard on the driver’s side.

You may see a small button or indicator light attached to the bottom edge of the dash. Wiring may run from the button behind the dashboard panels. The button shown by UC San Diego is small and easy to miss. It can look like a basic aftermarket alarm switch rather than a modern connected device. Do not pull on the wires or disconnect anything. The module may connect to the ignition system and other vehicle electronics.

Review your vehicle sales paperwork

Check the purchase agreement, dealer addendum, finance documents and service records.

Search for references to:

Advertisement
  • KARR Security
  • KARR BT
  • KARR Fusion
  • KARR S.W.A.T.
  • SWDS
  • Southwest Dealer Services
  • Dealer alarm
  • Vehicle recovery system
  • Inventory security system

The charge may appear as part of a larger dealer protection package. You may also find the product listed with no separate price if the dealer installed it for inventory control.

TESLA HELPED SAVE A DRIVER; IS YOUR CAR READY?

Some Jeep, Ram and Chrysler drivers previously saw promotional messages on infotainment screens through Stellantis’ Uconnect system. (Kurt “Cyberguy” Knutsson)

Ask the selling dealer to check your VIN

Call the dealership that originally sold the vehicle. This step can help even when you bought the car used from another business. Your VIN appears near the bottom of the windshield on the driver’s side. You can also find it on the registration, insurance card and driver-side door frame.

Ask the dealer: “Can you check this VIN and confirm whether your dealership or inventory vendor installed a KARR, SWDS, KARR BT, S.W.A.T. or other aftermarket security module?”

Then ask these follow-up questions: “Is the device still connected?” “Has it received the firmware update released on July 20, 2026?” “Can you provide the device model and firmware status in writing?”

Advertisement

A vague answer such as “Your factory alarm is fine” does not address the question. You are asking about dealer-installed aftermarket equipment.

Use the KARR app to check your VIN

KARR says people who never activated the security service can still use the official KARR Security app to check their VIN. Download the app only through the official Apple App Store, Google Play Store or KARR website. Do not use an app link from an unexpected text message, email or online advertisement.

After opening the app near the vehicle, tap the customer service link at the bottom of the screen. The app should guide you through the VIN check and available firmware update. KARR also lists customer support at 800-395-5277.

What Nancy should check on her Cadillac and Hyundai

Nancy’s 2025 Cadillac XT5 and 2024 Hyundai Tucson Limited Hybrid were not among the specific brands UC San Diego researchers said appeared most often. However, that does not rule them out. The device comes from the dealership rather than Cadillac or Hyundai.

Nancy should check each SUV separately. First, she should look for a KARR or SWDS sticker on the driver-side window. Next, she should use a flashlight to inspect the lower edge of the dashboard near the driver’s knees.

Advertisement

She should also review the paperwork from each dealership. If the vehicles came from different dealers, one could have the equipment while the other does not. Finally, Nancy should call both selling dealers with the VINs. She should ask whether either dealership installed a KARR, SWDS or S.W.A.T. module before delivery. If the dealers cannot provide a definite answer, she can use the official KARR app or call KARR support.

How to update a KARR security system

Acrisure released a firmware patch on July 20, 2026, one day before UC San Diego publicly announced the vulnerability. The vehicle owner must deliver the update to the KARR device through the official KARR Security app. Updating your phone or vehicle infotainment system will not patch the separate module.

Update an activated KARR system

An activated system means you purchased or activated KARR service through the dealership.

Follow these steps:

  • Go to the vehicle and sit in the driver’s seat.
  • Open the KARR Security app.
  • Log in and select the correct vehicle.
  • Tap the Settings button in the lower-right corner.
  • Scroll down and tap Check for Updates.
  • Follow the instructions shown in the app.
  • Wait for confirmation that the firmware is current.

KARR says no additional action is necessary after the app confirms that the latest firmware is installed.

Update a KARR system you never activated

You can still check and update a device that remained in the vehicle after you declined the service.

Advertisement

Follow these steps:

  • Download the official KARR Security app.
  • Sit in the driver’s seat near the device.
  • Open the app.
  • Tap the Customer Service: 800-395-5277 link.
  • Follow the app’s instructions to check the VIN.
  • Complete the firmware update when prompted.
  • Confirm that the app reports the latest firmware.

Call KARR support when the app cannot find the vehicle or complete the update.

WAYMO RECALLS ROBOTAXIS OVER CONSTRUCTION-ZONE RISK

Drivers can check for a KARR or SWDS device by inspecting the driver-side window, dashboard area and vehicle sales paperwork. (David Baillot/University of California San Diego/Jacobs School of Engineering)

Should you remove the KARR device?

You can ask to have the system deactivated or removed. However, I would not turn this into a weekend do-it-yourself project. Researchers warn that removal may require opening the dashboard, cutting wires and restoring connections involving the ignition system or vehicle computers. Disconnecting the wrong wire could stop the car from starting. It might also affect the factory alarm, remote start or another electrical feature. Southwest Dealer Services says an owner can request removal, transfer or deactivation by calling 800-395-5277 and confirming the account information.

Ask the original dealership or a qualified automotive electrical technician to handle the work. Before approving removal, ask the technician how the factory wiring will be restored. Afterward, request written confirmation that the module was removed and the vehicle’s original security functions still work.

Advertisement

We reached out to KARR Security, and a representative from the company provided CyberGuy with the following statement:

“KARR Security maintains rigorous standards to help protect customers’ vehicles. Researchers at UC San Diego identified a vulnerability affecting BLE-based auto theft devices, including a small percentage of KARR devices with certain Bluetooth-related components. The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue. We launched this app/firmware update on July 20, 2026. Active customers may apply the update directly from their phone after securely logging in to the KARR Security app. Vehicle owners of non-active systems can still update via the app using their VIN (last 8 digits) as a validation step. Consumers can find detailed instructions and tutorials for assistance with this firmware on the Customer FAQ section of our website at www.KARRSecurity.com.”

KARR Security added, “To our knowledge, we have not seen this vulnerability used in the real world to break into or steal a vehicle.”

What will not fix the KARR Bluetooth flaw

Turning off Bluetooth on your phone will not disable the Bluetooth radio inside the KARR module. Deleting the app will not remove the device. Removing the vehicle from your phone’s normal Bluetooth menu will not patch it either.

The KARR module communicates separately from the Cadillac, Hyundai or other factory infotainment system. A Faraday pouch also will not fix this particular problem. Faraday pouches can help block relay attacks involving a key fob. They cannot update or disable hardware installed beneath the dashboard. You need to update the KARR device itself or have a professional remove it.

Advertisement

Tips to protect your vehicle from being stolen

Car thieves use different methods, so protecting your vehicle requires more than one piece of technology.

1) Install the KARR firmware update first

When your vehicle has a KARR or SWDS device, install the firmware update as soon as possible. This directly addresses the Bluetooth flaw identified by the researchers. A steering wheel lock or tracker can add protection, but neither one repairs vulnerable software.

2) Confirm your doors actually locked

Signal jammers can sometimes block the command sent by a key fob. After pressing the lock button, listen for the normal confirmation sound. Look for the lights and pull a door handle before walking away. Also, close every window and take the keys with you. NHTSA recommends checking the doors whenever you leave a parked vehicle.

3) Add a visible steering wheel lock

A steering wheel lock creates an obvious barrier inside the car. It will not stop every determined thief. However, it adds time and makes the vehicle harder to steer. NHTSA includes steering wheel locks among visible devices that can discourage vehicle theft. You can find more ideas in my CyberGuy guide on how to help prevent your car from getting stolen.

4) Protect your key fob at home

Store key fobs away from exterior doors, windows and attached garages. A tested signal-blocking pouch can help reduce the risk of a relay attack. In that type of theft, criminals extend the signal from a key inside the house to a vehicle outside. Test the pouch regularly. Put the key inside, close the pouch and stand next to the car. The doors should remain locked when you touch the handle. Remember that a key-fob pouch protects against a different attack. It will not patch a KARR module.

Advertisement

5) Add a vehicle recovery tracker

A hidden GPS tracker or Bluetooth tracker may help locate a stolen vehicle. However, do not confront anyone or attempt to recover the car yourself. Give tracking information to law enforcement. An Apple AirTag can provide a backup location signal, although Apple’s anti-stalking alerts may eventually warn a thief that an unknown AirTag is traveling with the vehicle. Read my CyberGuy guide on using an AirTag in a vehicle and understanding its limits.

6) Choose a safer parking spot

Use a locked garage when one is available. Otherwise, park in a visible area with lighting, foot traffic or a security camera. Avoid isolated corners where someone can work around the vehicle without attracting attention. NHTSA also recommends parking in well-lit areas whenever possible.

7) Remove valuables from sight

A thief may break into a car without planning to steal the entire vehicle. Take phones, laptops, wallets and bags with you. Do not leave a spare key or garage remote inside the car. NHTSA warns that thieves commonly target electronics and other items they can quickly resell.

Kurt’s key takeaways

Nancy’s question highlights the biggest problem with this vulnerability. Many drivers have no idea that a KARR or SWDS device may be hiding in their vehicle. You will not find a KARR code inside your vehicle’s settings. Look for a sticker on the driver-side window and a small aftermarket button below the dashboard. Then check your paperwork and ask the selling dealer to search your VIN. The flaw can unlock a vulnerable vehicle and interfere with its security features from nearby. It cannot start the engine by itself or shut down a moving car. Still, unlocking the doors may give a thief the access needed to try another method. Fortunately, KARR has released a firmware update. Install it through the official KARR Security app. When you no longer want the system, arrange professional removal rather than pulling wires yourself.

Should dealerships have to tell you about every connected device installed in your car, even when you decline to purchase the service? Let us know by writing to us at CyberGuy.com.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading

Technology

An Amazon data center could have the worst polluting power plant in the country

Published

on

An Amazon data center could have the worst polluting power plant in the country

To power its new West Texas data center, Amazon is investing in the construction of a new power plant that could be one of the largest single producers of greenhouse gases in the US, according to the New York Times. The new gas-burning plant in Pecos County, Texas has received significant investment from Amazon and, at least initially, would not be connected to the state’s power grid. Instead, its 35 natural-gas turbines would primarily deliver its 7.65 gigawatts of electricity to the new data center.

According to Cleanview, which tracks data centers and their associated power projects, GW Ranch received a permit from Texas allowing for the emission of up to 33 million tons of CO2, more than even the largest coal plant in the country. Plants rarely emit as much greenhouse gas as their permits allow, but it’s still notable that the restrictions on its pollution levels are so lax. Amazon has confirmed that it purchased the site and plans to purchase power from GW Ranch.

Even if the GW Ranch site only emits a portion of the greenhouse gases it’s permitted to, it would still represent a significant setback for Amazon’s Climate Pledge. Jeff Bezos pledged to make his company carbon neutral by 2040. However, its emissions have climbed for several years in a row due to the demands of AI. Amazon spokeswoman Margaret Callahan told the New York Times that, “The world looks different now than when we co-founded the climate pledge,” but that, “our commitment hasn’t changed.”

Continue Reading
Advertisement

Trending