Cybersecurity expert remotely hacks BYD Shark 6 with ease, raising concerns about Chinese EV data risks

ABC investigation finds no password needed to access digital controls; headlights killed while driving

By LineZotpaper
Published
Read Time2 min
Sources2 outlets
An Australian cybersecurity expert was able to remotely access and control a BYD Shark 6 hybrid ute within two weeks, with no password required, according to an investigation by ABC News’ Four Corners. The test, conducted on a country road outside Canberra, saw the hacker kill the vehicle’s headlights while the driver was behind the wheel, highlighting what experts say are serious vulnerabilities in connected cars from Chinese manufacturers.

The investigation, reported by Angus Grigg, Jonathan Miller and Maddy King, tasked Dan Hreszczuk, co-founder of Fortify Labs in Canberra, with remotely accessing the BYD Shark 6 to demonstrate what the manufacturer — or a malicious actor — could do from afar.

“It was easier than we were expecting,” Hreszczuk said. “The access we took advantage of didn’t even have a password.” That lack of authentication allowed him to enter the car’s digital systems and unpick the software controlling various functions.

After two weeks of preparation, Hreszczuk demonstrated his access by remotely turning off the headlights as the ute rounded a bend. “It’s a little bit scary how open … the BYD Shark is to a hacker,” he said.

Modern connected cars, especially electric and plug-in hybrid vehicles, are increasingly run by software, giving manufacturers the ability to change and update vehicles remotely. In BYD’s case, that software is controlled from China.

Electric vehicles and plug-in hybrids now account for almost a third of new car sales in Australia in 2026, with more than half of those from Chinese brands. Experts quoted in the report warn that data collected by such vehicles — through sensors, cameras and microphones — poses a greater risk in the hands of Chinese automakers because they can be compelled under Chinese national security laws to cooperate with authorities.

The investigation chose BYD as the test target because it is China’s top EV brand. BYD has not yet commented publicly on the findings.

§

Analysis

Why This Matters

  • The hack demonstrates that a popular Chinese-branded ute sold in Australia can be remotely controlled with minimal effort, raising direct safety concerns for drivers and passengers.
  • As Chinese EVs and hybrids make up a growing share of Australian car sales, the potential for mass exploitation — or government-mandated access — becomes a systemic risk.
  • The test underscores the tension between the convenience of software-defined vehicles and the urgent need for robust cybersecurity standards, especially when manufacturers operate under foreign legal frameworks.

Background

Modern cars are increasingly software-defined, with over-the-air updates and remote connectivity becoming standard. The BYD Shark 6 is a plug-in hybrid ute popular in Australia among tradies and government buyers. Chinese brands now account for more than half of Australia’s EV and plug-in hybrid sales. Under China’s national security laws, companies can be compelled to assist authorities, which data security experts say creates a unique risk when those companies control sensitive in-vehicle data and vehicle functions. Australia does not currently have mandatory cybersecurity standards for connected cars.

Key Perspectives

Dan Hreszczuk (cybersecurity expert, Fortify Labs): Found the Shark 6’s lack of basic password protection “scary” and easy to exploit. He demonstrated that remote control of critical functions like lights is possible without authentication. BYD (manufacturer): Has not yet responded to the investigation. The company may argue that the hack required physical access to the vehicle’s systems or that its software is secure against real-world threats, though the investigation indicates remote access was achieved. Data security advocates and policymakers: Warn that Chinese automakers operating under China’s national security laws can be forced to hand over data or provide access to vehicle systems, a risk that grows as Chinese-branded EVs become more common on Australian roads.

What to Watch

  • Whether BYD issues a software patch or public statement addressing the vulnerabilities highlighted in the investigation.
  • Whether the Australian government introduces mandatory cybersecurity requirements for connected vehicles, or launches its own probe into Chinese EV data practices.
  • Further independent security audits of other popular Chinese EV models sold in Australia.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.