BYD Shark 6 Hack Exposes Critical Security Flaws in Connected Cars
A recent cybersecurity test revealed alarming vulnerabilities in the BYD Shark 6, a connected electric vehicle (EV), demonstrating how easily hackers could remotely control critical functions and access sensitive data. Conducted by ABC’s Four Corners and cybersecurity researcher Dan Hreszczuk of Fortify Labs, the two-week investigation took place in Canberra, Australia, in September 2026, with a real-world demonstration on a rural road outside the city.
Hreszczuk, who specializes in car security, gained unrestricted remote access to the vehicle’s systems through an unprotected entry point no password or security measures were in place. During the test, he locked the doors, blasted music, displayed images on the infotainment screen, and manipulated the windshield wipers, headlights, and water spray while the car was in motion. Most critically, he disabled the headlights entirely, creating an immediate safety hazard for the driver.
While the brakes and cameras remained secure, the hack exposed the potential for catastrophic outcomes such as an attacker disabling lights or wipers at high speeds on a dark, winding road. However, the surveillance risks proved even more concerning. Hreszczuk tracked the vehicle’s real-time location and activated the cabin microphone, capturing private conversations. In one instance, he recorded a journalist’s voice saying "Hey Siri" and later replayed it to trick the phone into revealing personal details, including an internet banking password, home address, and contact information.
The test underscored regulatory gaps in Australia, where connected cars face no mandatory cybersecurity standards unlike appliances like washing machines. BYD, a Chinese manufacturer, is not required to patch software vulnerabilities or implement risk management systems for its vehicles. While BYD claims Australian customer data remains in Australia and denies sharing information with Chinese authorities, experts note that China’s national security laws could compel cooperation, raising concerns about state-backed surveillance.
The incident has sparked debate over government and military policies. The UK banned Chinese-made EVs from sensitive sites last year, while Australia’s ASIO has warned officials against discussing classified matters in such vehicles. Despite this, Trade Minister Don Farrell publicly drives the same BYD Shark model, calling it his "best ute ever" a statement that drew scrutiny given the hack’s timing.
Australia is now consulting on new cybersecurity rules for cars, but enforcement remains years away. Until then, the BYD Shark 6 hack serves as a stark reminder of the risks posed by unsecured connected vehicles, where remote access could enable sabotage, espionage, or data theft all with minimal effort.
Source: https://securityaffairs.com/199460/hacking/a-byd-shark-6-hack-shows-the-risks-of-connected-cars.html
BYD TPRM report: https://www.rankiteo.com/company/byd
"id": "byd1789993911",
"linkid": "byd",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': 'Owners of BYD Shark 6 vehicles '
'in Australia',
'industry': 'Automotive (Electric Vehicles)',
'location': 'China (with Australian operations)',
'name': 'BYD',
'type': 'Automobile Manufacturer'}],
'attack_vector': 'Unprotected entry point (no password or security measures)',
'data_breach': {'data_exfiltration': 'Yes (private conversations recorded and '
'replayed)',
'personally_identifiable_information': 'Yes (home address, '
'contact information, '
'banking details)',
'sensitivity_of_data': 'High (banking passwords, home '
'address, contact information)',
'type_of_data_compromised': ['Personal details',
'Private conversations',
'Location data']},
'date_detected': '2026-09',
'date_publicly_disclosed': '2026-09',
'description': 'A recent cybersecurity test revealed alarming vulnerabilities '
'in the BYD Shark 6, a connected electric vehicle (EV), '
'demonstrating how easily hackers could remotely control '
'critical functions and access sensitive data. The test, '
'conducted by ABC’s *Four Corners* and cybersecurity '
'researcher Dan Hreszczuk of Fortify Labs, exposed risks '
'including remote manipulation of vehicle systems, real-time '
'location tracking, and unauthorized audio surveillance.',
'impact': {'brand_reputation_impact': 'Negative publicity, concerns over data '
'privacy and vehicle safety',
'data_compromised': 'Personal details (internet banking password, '
'home address, contact information), private '
'conversations',
'identity_theft_risk': 'High (exposure of personal and banking '
'details)',
'legal_liabilities': 'Potential regulatory violations (no '
'mandatory cybersecurity standards in '
'Australia)',
'operational_impact': 'Remote manipulation of vehicle functions, '
'safety hazards (e.g., disabled headlights)',
'payment_information_risk': 'High (internet banking password '
'compromised)',
'systems_affected': 'Infotainment system, windshield wipers, '
'headlights, water spray, door locks, cabin '
'microphone, GPS tracking'},
'initial_access_broker': {'entry_point': 'Unprotected remote access point (no '
'password/security measures)',
'high_value_targets': 'Vehicle systems '
'(infotainment, lights, '
'wipers), cabin microphone, '
'GPS',
'reconnaissance_period': 'Two weeks (September '
'2026)'},
'investigation_status': 'Completed (demonstration)',
'lessons_learned': 'Connected vehicles lack mandatory cybersecurity '
'standards, exposing them to remote control, surveillance, '
'and data theft. Regulatory gaps in Australia and other '
'regions enable such vulnerabilities. State-backed '
"surveillance risks exist due to China's national security "
'laws.',
'motivation': 'Demonstration of security flaws and regulatory gaps',
'post_incident_analysis': {'corrective_actions': ['Government consultation on '
'new cybersecurity rules '
'for cars',
'Potential enforcement of '
'standards (long-term)',
'BYD’s denial of data '
'sharing with Chinese '
'authorities (no technical '
'remediation mentioned)'],
'root_causes': ['Lack of mandatory cybersecurity '
'standards for connected vehicles '
'in Australia',
'Unprotected remote access points '
'in BYD Shark 6',
'No software patching or '
'vulnerability management '
'requirements']},
'recommendations': ['Implement mandatory cybersecurity standards for '
'connected vehicles',
'Enforce regular software patching and vulnerability '
'management',
'Restrict sensitive discussions in unsecured vehicles '
'(e.g., government/military officials)',
'Enhance vehicle system segmentation to limit attack '
'surfaces',
'Conduct independent cybersecurity audits for connected '
'cars'],
'references': [{'date_accessed': '2026-09', 'source': 'ABC’s *Four Corners*'}],
'regulatory_compliance': {'regulations_violated': 'No mandatory cybersecurity '
'standards for connected '
'vehicles in Australia',
'regulatory_notifications': 'Australia consulting '
'on new cybersecurity '
'rules for cars '
'(enforcement years '
'away)'},
'response': {'communication_strategy': 'BYD claimed Australian customer data '
'remains in Australia and denied '
'sharing information with Chinese '
'authorities'},
'stakeholder_advisories': 'UK banned Chinese-made EVs from sensitive sites; '
'ASIO warned Australian officials against '
'discussing classified matters in such vehicles',
'threat_actor': 'Dan Hreszczuk (Fortify Labs) - Ethical Hacking',
'title': 'BYD Shark 6 Hack Exposes Critical Security Flaws in Connected Cars',
'type': 'Cybersecurity Vulnerability Exploitation',
'vulnerability_exploited': 'Lack of mandatory cybersecurity standards for '
'connected vehicles'}