Cybersecurity Expert Hacks BYD Shark 6 Remotely in Two Weeks
An Australian cybersecurity expert has revealed critical security vulnerabilities in the BYD Shark 6, a Chinese plug-in hybrid pickup, by remotely hacking the vehicle within two weeks. Dan Hreszczuk, co-founder of Fortify Labs based in Canberra, conducted the investigation as part of an ABC Four Corners report, highlighting significant risks in connected vehicle security.
Hreszczuk discovered an entry point into the Shark 6’s internal network that was completely unprotected, requiring no password. This open digital access enabled him to control various functions of the vehicle remotely. During a demonstration near Canberra, Hreszczuk remotely locked the doors while the reporter was inside, activated the windscreen wipers at full speed, sprayed water on the windshield, and repeatedly turned the headlights on and off. In a particularly concerning act, he shut off the headlights entirely while the vehicle was moving, leaving the road in darkness.
In addition to manipulating vehicle systems, Hreszczuk accessed the cabin microphone to eavesdrop on conversations. He was able to listen to a phone call made inside the car, capturing sensitive personal details such as temporary passwords. Furthermore, he used synthesized voice commands to trigger the phone’s voice assistant remotely, underscoring privacy threats posed by these vulnerabilities.
Despite these alarming findings, Hreszczuk could not access safety-critical systems such as brakes, steering, or vehicle cameras, which remained difficult to compromise. Still, the investigation raised broader concerns about cybersecurity standards for connected vehicles in Australia. Currently, Australia lacks mandatory regulations requiring manufacturers to implement cybersecurity risk management or consistently patch vehicle software.
Notably, Australian cybersecurity rules are reportedly more stringent for connected household appliances like washing machines than for automobiles, leaving a major gap in automotive security oversight. The issue is compounded by data collection practices within modern vehicles. Connected cars routinely gather and transmit audio, images, navigation data, and phone activity, raising concerns about data privacy and potential surveillance.
BYD holds an estimated 40% share of Australia’s new car market, making this vulnerability particularly significant for a large portion of Australian drivers. The company has contested some of the report’s conclusions, stating that physical access is necessary to exploit certain vulnerabilities. However, the remote access demonstrated in the investigation challenges that assertion.
Hreszczuk emphasized the ease with which the intrusion was achieved, stating, “I didn’t need to pick the lock as BYD left the front door open.” His findings underline the urgent need for enhanced cybersecurity standards in the automotive industry to protect driver safety and privacy in an increasingly connected world.
