Descriptions of this family of threats circulate that are far more dramatic than reality, and it is worth putting things in proportion from the start.
The constraint governing everything is distance. Every technique in this family requires whoever acts to be within a few tens of metres. That rules out scale: you do not reach thousands of people from another continent. You reach whoever is in the same room.
The result is a category of threats that is real but little practised, because the effort is high and the result limited.
It expands on the recommendation turning off Bluetooth and location.
1. Unrequested content being sent
How it works. Some systems allow files or contacts to be sent to nearby devices that accept requests. Whoever is in range sends content to strangers.
What they get. Nothing technical: it is a form of harassment, not a compromise. The content still has to be accepted.
Where it happens. Trains, planes, crowded places.
The specific defence. Set receiving to “contacts only” or turn it off. It is a setting present on every recent system, and on many it is already configured that way.
An important note: it is by far the most frequent case in this family, and it is also the least serious. It should be said, because it often gets described as if it were an attack on the device.
2. Exploiting vulnerabilities
How it works. The Bluetooth component processes data coming from outside, and like any component of that kind it can contain defects. Some allow a nearby device to provoke unusual behaviour or — in the worst documented cases — to run code.
How realistic it is. It deserves an honest assessment:
| Element | Reality |
|---|---|
| The vulnerabilities exist | Yes, documented over time |
| They require proximity | Yes, a few metres |
| They require high skill | Yes |
| They get fixed by updates | Yes, generally quickly |
| They are used at scale | No |
| They concern the average updated device | Rarely |
The specific defence. Updates. They are the main countermeasure, and on their own they close the known vulnerabilities. Switching Bluetooth off when it is not needed shortens the window further, but it is the second measure, not the first.
3. The pairing that stays
How it works. A paired device keeps a key and gets recognised automatically. A pairing made long ago — a rental car, an acquaintance’s speaker, headphones you sold — stays valid.
What it means. The risk is less technical than one of data left behind: a rental car you synced your contacts with keeps those contacts, and whoever rents that car after you can see them.
The specific defence. Remove the pairing from both sides: from the phone and, where possible, from the other device. Rental cars always have a function to delete the connected phones, and it is the most useful action in this paragraph.
4. Following through the signal
How it works. A device always emitting the same identifier can be recognised in different places, allowing movements to be reconstructed.
Why it works less today. Modern devices periodically change the identifier they advertise, precisely to prevent it. It is a protection on by default.
What remains. Some characteristics of the signal can stay recognisable, and not every device — especially cheap accessories — implements the rotation.
The specific defence. Keep the devices updated, and switch Bluetooth off when it is not needed.
5. The tag placed secretly
It is the most relevant technique in this family in real life, and it is not a technical attack.
How it works. A small Bluetooth tag gets placed in a bag, a car, among personal effects. It uses the global detection network to report the position to whoever placed it.
Why it is the most relevant. It requires no skill, it requires no continuing proximity, it costs very little. And the target is not the device: it is the person.
Who does it. In the great majority of documented cases, somebody who knows the victim — not a stranger.
The specific defence. The alert systems introduced by manufacturers: the phone warns you when a tag that is not yours moves with you. It is the case covered in detail in the unit on signals.
What to do if it happens. Do not ignore the notification, look for the object using the function the system offers, and — if the situation is worrying — keep it and consider going to the competent authorities.
The overall picture
| Technique | Frequency | Severity | Main defence |
|---|---|---|---|
| Unrequested content being sent | High | Low | Receiving set to “contacts only” |
| Exploiting vulnerabilities | Low | High | Updates |
| A pairing that stays | Medium | Medium | Removing the pairings |
| Following through the signal | Low | Low | Updated devices |
| A tag placed secretly | Medium | High | Not ignoring the alert |
The two rows that count are the second and the last, for opposite reasons: the second is rare but serious, and it closes with updates; the last is more frequent than people think and serious, and it is not even a digital threat in the strict sense.
Why the risk is lower than it gets described
It is worth closing the subject with an explicit assessment, because the common perception is out of proportion.
The distance constraint is decisive. Anybody wanting to compromise devices at scale does not do it from three metres away: they send a message to a million people. Phishing has a marginal cost near zero; a Bluetooth attack requires being physically present.
The defences have improved greatly. Rotating identifiers, explicit authorisation for pairing, receiving limited to contacts, frequent updates.
The vulnerabilities get fixed. The documented ones received quick corrections, and today they mainly concern devices that are not updated.
That does not mean the recommendation is useless: it means its main justification is not the risk of attack, but the risk of observability and tracking — which are different and more concrete subjects.
What does not belong to this family
Drawing boundaries is useful, because things get attributed to Bluetooth that do not belong to it.
Data being taken from the phone. If an app collects information, it does so because it has a permission, not through Bluetooth. It is a question of authorisations.
Listening in on conversations. The microphone is governed by a system permission with a visible indicator. It does not go through Bluetooth.
Cloning a phone. It is not something done at a distance with a radio signal. Serious compromises require something to be installed on the device.
Contactless payment. It uses a different technology, over a range of a few centimetres, with protections of its own and authorisation required at every transaction.
Cars’ digital keys. Some use Bluetooth and have had documented vulnerabilities. It is a real subject but specific to vehicles, and it is addressed with the manufacturer’s updates.
The useful distinction: this family includes only what exploits the short-range radio signal. Everything else has other vectors and other defences — and attributing it to Bluetooth leads to switching off a function without solving anything.
What to do, in order of usefulness
- Keep the devices updated. It closes the known vulnerabilities, which are the most serious technique.
- Do not ignore tag alerts. It is the most concrete threat in the family.
- Set content receiving to “contacts only”. It closes the most frequent nuisance.
- Clear out the paired devices, and delete your phone from rental cars.
- Switch Bluetooth off when you are not using it. Useful, but it comes after the others.
The order matters: the fifth point is the one everybody mentions first, and it is the least effective of the five.
The devices that deserve more attention
Not every Bluetooth device has the same level of protection, and it is worth knowing where the residual risk concentrates.
| Category | Attention | Why |
|---|---|---|
| Updated phones and computers | Low | They receive regular fixes |
| Watches and bands from known brands | Low-medium | Updated, but on longer cycles |
| Cheap unbranded accessories | High | Often not updatable |
| Connected home devices | High | Rarely updated after purchase |
| Cars | Medium | Updates available but seldom installed |
| Connected medical devices | Medium | Regulated, but on long cycles |
The two highlighted rows describe the same problem: equipment that receives no updates keeps the vulnerabilities it had on the day it was made.
It is not a reason not to use them, and it is a reason for two practical points of care:
Prefer manufacturers who state an update policy. It is information available before purchase, and it separates a product designed to last from one designed to be sold.
Remove the pairing with devices you no longer use. An accessory abandoned in a drawer but still paired is a pointless entry in the list, and every entry is a stored key.
The comparison with the other families of threat
To place this unit correctly against the rest of the series.
| Family | Does it need proximity? | Possible scale | Real frequency |
|---|---|---|---|
| Phishing | No | Millions | Very high |
| Providers’ breaches | No | Millions | High |
| Access with reused credentials | No | Thousands | High |
| Physical proximity attacks | Yes | One person | Medium |
| Bluetooth attacks | Yes | One person | Low |
| Traffic interception | Yes | A few people | Low |
The scale column tells the whole story: the threats that really affect people are the ones that can be carried out remotely and in bulk.
A Bluetooth attack requires being physically present to reach one person at a time. It is an investment that makes sense only when the target is that specific person — that is, in targeted cases, not in volume crime.
That has a practical consequence worth stating explicitly: if you have no reason to be a specific target, this family of threats concerns you very little. And if you do, the defence is not switching Bluetooth off: it is the whole set of measures in this series, starting with updates.
The only exception is the fifth technique — the tag placed secretly — which escapes that logic because it costs very little and requires no skill. That is why, across the whole family, it is the one deserving the most attention.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Placing the Bluetooth risk in its real proportion |
| Skills | Knowing that updates count more than switching off |
| Secure Behaviour | Removing the pairings and responding to alerts |
Reference level: FL3 — Autonomous.
Summary
- Every technique in this family requires physical proximity: it is the constraint limiting its spread.
- The main defence against the vulnerabilities is updates, not switching off.
- The most concrete threat is not technical: it is a tag placed secretly.
- Switching Bluetooth off is useful, but it is the least effective of the five measures.
One thing to do today. If you have driven a rental car in recent months, check on your phone whether the pairing is still saved. And remember your synced contacts stayed in that car.
Related content
- Turning off Bluetooth and location — the recommendation this expands on
- Signs of unwanted tracking — how to recognise a nearby tag
- How Bluetooth and location work — the mechanisms these techniques exploit
- Proximity attacks — the wider family of close-range threats
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



