How a Cybersecurity Expert Easily Hacked a BYD Electric Car

A cybersecurity expert gained unauthorized remote access to a BYD Shark 6 plug-in hybrid ute during a road test outside Canberra, cutting the vehicle’s headlights and controlling interior functions without a password, according to testing featured on the ABC program Four Corners. Dan Hreszczuk, co-founder of Canberra-based Fortify Labs, spent two weeks examining the Chinese-manufactured vehicle’s software and demonstrated how external access could manipulate headlights, wipers, door locks, and media systems while the vehicle was in motion.

How a BYD Shark 6 Was Remotely Accessed

Modern connected vehicles rely heavily on software systems that allow manufacturers to push updates and manage vehicle controls remotely. According to Hreszczuk, the BYD Shark 6 lacked basic password protection on the access points he targeted. “It was easier than we were expecting,” Hreszczuk said, describing the vehicle’s software architecture as wide open to external intervention.

During a controlled road test documented by Four Corners, Hreszczuk demonstrated the extent of that remote access from a nearby laptop. While a driver navigated a country road at low speed, the remote operator locked the doors, blasted music through the speakers, activated the windshield wipers at maximum speed, and repeatedly toggled the headlights on and off. The test culminated in the remote system cutting the vehicle’s headlights entirely while it was moving.

Did you know? Australia currently has tighter cybersecurity regulations for connected household devices like washing machines and vacuum cleaners than it does for connected motor vehicles, according to government acknowledgments.

Surveillance Risks and Intelligence Warnings

Beyond active sabotage, security agencies and defense experts have raised concerns regarding data collection through the cameras and microphones embedded in modern electric and hybrid vehicles. Because BYD and other Chinese manufacturers are subject to national security laws in China, authorities there can compel companies to cooperate with intelligence-gathering operations.

International responses to these risks have varied. The UK military banned Chinese-manufactured EVs from parking within three kilometers of sensitive defense locations. In Australia, ASIO has warned ministers and public servants against holding sensitive conversations inside connected cars or connecting work devices to them. However, no blanket ban currently prevents officials from purchasing or driving these vehicles. Trade Minister Don Farrell recently told a newspaper that his BYD Shark 6 is the “best ute I’ve ever owned.”

Extracting Personal Data via Vehicle Systems

To test the potential for data harvesting, Hreszczuk and the Four Corners reporting team conducted a live test in Canberra. As the vehicle was driven past the War Memorial, Hreszczuk activated the car’s internal microphone remotely. The driver placed a phone call to a family member to discuss setting up internet banking passwords, and the conversation was recorded through the vehicle’s audio system.

Using the recorded audio snippet of the driver saying “Hey Siri,” Hreszczuk edited a new voice command file. Playing that audio clip through the car’s built-in speakers, he prompted the digital assistant to reveal the driver’s home address, date of birth, and contacts list, including the phone number of Malcolm Turnbull. This demonstrated that low-level remote access could be leveraged to harvest sensitive personal data stored on connected smartphones.

Regulatory Gaps and Industry Response

Australia currently lacks minimum cybersecurity standards specifically tailored for the automotive sector. Former national cybersecurity adviser Alastair MacGibbon argued that current protections are inadequate for managing the volume of data collected by modern connected cars and transmitted overseas. Opposition Defence spokesman James Paterson described connected EVs from China as the “highest risk product in the marketplace.”

Powering up your Cybersecurity: Experts Share Tips on Implementing Electric Utility Regulations

Home Affairs and Cyber Security Minister Tony Burke defended the government’s phased regulatory approach, noting that officials prioritized household connected devices where cyberattacks had historically concentrated. The federal government has initiated consultations with the automotive industry to introduce software and cybersecurity rules for cars, though implementation is expected to take years.

In response to these findings, BYD stated that the data it collects from Australian customers is stored locally in Australia and maintained that the company has not handed over, and would not hand over, user data to Chinese authorities.

Frequently Asked Questions

Can hackers control the brakes and steering of a BYD Shark 6?

During testing, cybersecurity expert Dan Hreszczuk reported that he was unable to access critical safety functions like the brakes and cameras, stating those systems were more securely protected.

What vehicles are most vulnerable to remote hacking?

Modern connected vehicles, particularly electric vehicles (EVs) and plug-in hybrids that rely heavily on cloud-connected software and digital interfaces, present broader attack surfaces for remote access if foundational cybersecurity protocols are missing.

Are Chinese EVs banned in Australia?

No. While intelligence agencies like ASIO have issued warnings to public officials regarding sensitive conversations inside connected cars, Australia has no blanket ban preventing individuals or government ministers from owning Chinese-manufactured vehicles.

What are your thoughts on vehicle cybersecurity risks? Share your perspective in the comments below, or subscribe to our newsletter for more investigative reports and automotive updates.

Kevin Mandia – Cybersecurity Expert Hunting the World's Most Dangerous Hackers | SRS #328

Leave a Comment