Security

Connected V16 beacon: the vulnerability exposing thousands of drivers' data

A device that's been mandatory across all of Spain since 2026 just proved that 'connected' doesn't always mean 'secure'.

Since January 1, 2026, the connected V16 beacon has been the only legal way to signal a stopped vehicle on Spanish roads, replacing the traditional warning triangle. One of the best-selling models, also sold through Vodafone, was put to the test by an ethical hacker specializing in IoT — and the results are troubling for a device used on a mass, mandatory scale.

What the research found

The analysis uncovered several critical vulnerabilities: unencrypted communications, an insecure over-the-air (OTA) update system, and physically accessible debug ports. In practice, that means the beacon transmits the vehicle's exact location, the device identifier, and network data in plain text, with no encryption to stop a third party from intercepting it.

On top of that, the connection isn't authenticated: the receiver has no reliable way to verify that a message genuinely comes from the sender it claims to be. With more than 250,000 units of this model already in circulation, the potential impact isn't a technical footnote — it's a nationwide infrastructure problem.

Why it matters even if your business has nothing to do with cars

The V16 beacon case isn't an outlier: it's the usual pattern with IoT devices that hit the market prioritizing price and launch speed over security. Sensors, cameras, point-of-sale terminals, connected locks, or any equipment your company connects to the internet can carry the exact same flaws — unencrypted communication, unverified updates, unprotected physical access.

The gap between a reasonably secure IoT device and a vulnerable one usually goes unnoticed until someone puts it to the test — and by then it may have been in production, exposing data, for months or years.

The lesson for any SME with connected equipment

  • Don't assume "mandatory" or "sold by a major brand" means "secure".
  • Check what data your connected devices send, and whether it travels encrypted.
  • Verify whether firmware updates are authenticated or can be tampered with.
  • Restrict physical access to debug or maintenance ports on unattended equipment.

Security can't be improvised after the incident

The V16 beacon manufacturers have responded to the case, but the episode leaves a clear lesson: security needs to be assessed before a device goes live, not after a hacker (or someone with worse intentions) finds the flaw. If your business depends on connected equipment, networks, or critical systems, an security audit or an ongoing IT maintenance plan is how you catch these issues before they turn into a real data breach.

Does your business run IoT or connected devices?

We review your infrastructure's security before someone else finds the gaps first.

No spam. No sales calls. Just your personalised reply.