The investigation, reported by Angus Grigg, Jonathan Miller and Maddy King, tasked Dan Hreszczuk, co-founder of Fortify Labs in Canberra, with remotely accessing the BYD Shark 6 to demonstrate what the manufacturer — or a malicious actor — could do from afar.
“It was easier than we were expecting,” Hreszczuk said. “The access we took advantage of didn’t even have a password.” That lack of authentication allowed him to enter the car’s digital systems and unpick the software controlling various functions.
After two weeks of preparation, Hreszczuk demonstrated his access by remotely turning off the headlights as the ute rounded a bend. “It’s a little bit scary how open … the BYD Shark is to a hacker,” he said.
Modern connected cars, especially electric and plug-in hybrid vehicles, are increasingly run by software, giving manufacturers the ability to change and update vehicles remotely. In BYD’s case, that software is controlled from China.
Electric vehicles and plug-in hybrids now account for almost a third of new car sales in Australia in 2026, with more than half of those from Chinese brands. Experts quoted in the report warn that data collected by such vehicles — through sensors, cameras and microphones — poses a greater risk in the hands of Chinese automakers because they can be compelled under Chinese national security laws to cooperate with authorities.
The investigation chose BYD as the test target because it is China’s top EV brand. BYD has not yet commented publicly on the findings.