My clients all claimed they broke/lost their keys to their car - most of the time they were believable (car stuck in front of their driveway, etc). Sometimes less so, but I’d do it anyway because I needed the money and I had no proof of the contrary (innocent until proven guilty right?), although given the sad conditions of the cars I really doubt anyone would bother stealing them.
Car security is based on obscurity. There is very little cryptography involved (if any), and where there is, the car’s “computers” would happily install new, untrusted firmware through the diagnostics (OBD) port, which means you can do pretty much anything - program new keys, disable the immobiliser or alarm completely (by installing patched firmware) or even rewind the odometer.
I’m frankly surprised it took this long for “high tech” car theft to appear, unless it’s been going on for a while but executed perfectly so nobody would find a trace.
Happy to answer any questions if anyone’s curious.