CYBER WELFARE

Protect your Digital Privacy

Bluetooth attacks: what is realistic

Descriptions of this family of threats circulate that are far more dramatic than reality, and it is worth putting things in proportion from the start.

The constraint governing everything is distance. Every technique in this family requires whoever acts to be within a few tens of metres. That rules out scale: you do not reach thousands of people from another continent. You reach whoever is in the same room.

The result is a category of threats that is real but little practised, because the effort is high and the result limited.

It expands on the recommendation turning off Bluetooth and location.

1. Unrequested content being sent

How it works. Some systems allow files or contacts to be sent to nearby devices that accept requests. Whoever is in range sends content to strangers.

What they get. Nothing technical: it is a form of harassment, not a compromise. The content still has to be accepted.

Where it happens. Trains, planes, crowded places.

The specific defence. Set receiving to “contacts only” or turn it off. It is a setting present on every recent system, and on many it is already configured that way.

An important note: it is by far the most frequent case in this family, and it is also the least serious. It should be said, because it often gets described as if it were an attack on the device.

2. Exploiting vulnerabilities

How it works. The Bluetooth component processes data coming from outside, and like any component of that kind it can contain defects. Some allow a nearby device to provoke unusual behaviour or — in the worst documented cases — to run code.

How realistic it is. It deserves an honest assessment:

ElementReality
The vulnerabilities existYes, documented over time
They require proximityYes, a few metres
They require high skillYes
They get fixed by updatesYes, generally quickly
They are used at scaleNo
They concern the average updated deviceRarely

The specific defence. Updates. They are the main countermeasure, and on their own they close the known vulnerabilities. Switching Bluetooth off when it is not needed shortens the window further, but it is the second measure, not the first.

3. The pairing that stays

How it works. A paired device keeps a key and gets recognised automatically. A pairing made long ago — a rental car, an acquaintance’s speaker, headphones you sold — stays valid.

What it means. The risk is less technical than one of data left behind: a rental car you synced your contacts with keeps those contacts, and whoever rents that car after you can see them.

The specific defence. Remove the pairing from both sides: from the phone and, where possible, from the other device. Rental cars always have a function to delete the connected phones, and it is the most useful action in this paragraph.

4. Following through the signal

How it works. A device always emitting the same identifier can be recognised in different places, allowing movements to be reconstructed.

Why it works less today. Modern devices periodically change the identifier they advertise, precisely to prevent it. It is a protection on by default.

What remains. Some characteristics of the signal can stay recognisable, and not every device — especially cheap accessories — implements the rotation.

The specific defence. Keep the devices updated, and switch Bluetooth off when it is not needed.

5. The tag placed secretly

It is the most relevant technique in this family in real life, and it is not a technical attack.

How it works. A small Bluetooth tag gets placed in a bag, a car, among personal effects. It uses the global detection network to report the position to whoever placed it.

Why it is the most relevant. It requires no skill, it requires no continuing proximity, it costs very little. And the target is not the device: it is the person.

Who does it. In the great majority of documented cases, somebody who knows the victim — not a stranger.

The specific defence. The alert systems introduced by manufacturers: the phone warns you when a tag that is not yours moves with you. It is the case covered in detail in the unit on signals.

What to do if it happens. Do not ignore the notification, look for the object using the function the system offers, and — if the situation is worrying — keep it and consider going to the competent authorities.

The overall picture

TechniqueFrequencySeverityMain defence
Unrequested content being sentHighLowReceiving set to “contacts only”
Exploiting vulnerabilitiesLowHighUpdates
A pairing that staysMediumMediumRemoving the pairings
Following through the signalLowLowUpdated devices
A tag placed secretlyMediumHighNot ignoring the alert

The two rows that count are the second and the last, for opposite reasons: the second is rare but serious, and it closes with updates; the last is more frequent than people think and serious, and it is not even a digital threat in the strict sense.

Why the risk is lower than it gets described

It is worth closing the subject with an explicit assessment, because the common perception is out of proportion.

The distance constraint is decisive. Anybody wanting to compromise devices at scale does not do it from three metres away: they send a message to a million people. Phishing has a marginal cost near zero; a Bluetooth attack requires being physically present.

The defences have improved greatly. Rotating identifiers, explicit authorisation for pairing, receiving limited to contacts, frequent updates.

The vulnerabilities get fixed. The documented ones received quick corrections, and today they mainly concern devices that are not updated.

That does not mean the recommendation is useless: it means its main justification is not the risk of attack, but the risk of observability and tracking — which are different and more concrete subjects.

What does not belong to this family

Drawing boundaries is useful, because things get attributed to Bluetooth that do not belong to it.

Data being taken from the phone. If an app collects information, it does so because it has a permission, not through Bluetooth. It is a question of authorisations.

Listening in on conversations. The microphone is governed by a system permission with a visible indicator. It does not go through Bluetooth.

Cloning a phone. It is not something done at a distance with a radio signal. Serious compromises require something to be installed on the device.

Contactless payment. It uses a different technology, over a range of a few centimetres, with protections of its own and authorisation required at every transaction.

Cars’ digital keys. Some use Bluetooth and have had documented vulnerabilities. It is a real subject but specific to vehicles, and it is addressed with the manufacturer’s updates.

The useful distinction: this family includes only what exploits the short-range radio signal. Everything else has other vectors and other defences — and attributing it to Bluetooth leads to switching off a function without solving anything.

What to do, in order of usefulness

  1. Keep the devices updated. It closes the known vulnerabilities, which are the most serious technique.
  2. Do not ignore tag alerts. It is the most concrete threat in the family.
  3. Set content receiving to “contacts only”. It closes the most frequent nuisance.
  4. Clear out the paired devices, and delete your phone from rental cars.
  5. Switch Bluetooth off when you are not using it. Useful, but it comes after the others.

The order matters: the fifth point is the one everybody mentions first, and it is the least effective of the five.

The devices that deserve more attention

Not every Bluetooth device has the same level of protection, and it is worth knowing where the residual risk concentrates.

CategoryAttentionWhy
Updated phones and computersLowThey receive regular fixes
Watches and bands from known brandsLow-mediumUpdated, but on longer cycles
Cheap unbranded accessoriesHighOften not updatable
Connected home devicesHighRarely updated after purchase
CarsMediumUpdates available but seldom installed
Connected medical devicesMediumRegulated, but on long cycles

The two highlighted rows describe the same problem: equipment that receives no updates keeps the vulnerabilities it had on the day it was made.

It is not a reason not to use them, and it is a reason for two practical points of care:

Prefer manufacturers who state an update policy. It is information available before purchase, and it separates a product designed to last from one designed to be sold.

Remove the pairing with devices you no longer use. An accessory abandoned in a drawer but still paired is a pointless entry in the list, and every entry is a stored key.

The comparison with the other families of threat

To place this unit correctly against the rest of the series.

FamilyDoes it need proximity?Possible scaleReal frequency
PhishingNoMillionsVery high
Providers’ breachesNoMillionsHigh
Access with reused credentialsNoThousandsHigh
Physical proximity attacksYesOne personMedium
Bluetooth attacksYesOne personLow
Traffic interceptionYesA few peopleLow

The scale column tells the whole story: the threats that really affect people are the ones that can be carried out remotely and in bulk.

A Bluetooth attack requires being physically present to reach one person at a time. It is an investment that makes sense only when the target is that specific person — that is, in targeted cases, not in volume crime.

That has a practical consequence worth stating explicitly: if you have no reason to be a specific target, this family of threats concerns you very little. And if you do, the defence is not switching Bluetooth off: it is the whole set of measures in this series, starting with updates.

The only exception is the fifth technique — the tag placed secretly — which escapes that logic because it costs very little and requires no skill. That is why, across the whole family, it is the one deserving the most attention.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessPlacing the Bluetooth risk in its real proportion
SkillsKnowing that updates count more than switching off
Secure BehaviourRemoving the pairings and responding to alerts

Reference level: FL3 — Autonomous.

Summary

  • Every technique in this family requires physical proximity: it is the constraint limiting its spread.
  • The main defence against the vulnerabilities is updates, not switching off.
  • The most concrete threat is not technical: it is a tag placed secretly.
  • Switching Bluetooth off is useful, but it is the least effective of the five measures.

One thing to do today. If you have driven a rental car in recent months, check on your phone whether the pairing is still saved. And remember your synced contacts stayed in that car.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.