BYD Shark 6 Hacked in Security Test as Researcher gains Access to Car Systems

Byd Shark 6 Hacked In Security Test As Researcher Gains Access To Car Systems

What started as controlled cybersecurity test quickly turned into startling demonstration as researcher investigating BYD Shark 6 found he could access the connected vehicle’s systems and remotely trigger lights, wipers, audio and other functions, while also tracking its location and activating the cabin microphone. The test has now raised fresh questions about how secure today’s connected cars really are.

The demonstration was conducted as part of ABC’s Four Corners investigation ‘Asleep at the Wheel’. It was an authorised security test, not evidence of a widespread criminal attack targeting BYD customers. Canberra-based automotive cybersecurity researcher Dan Hreszczuk, co-founder of Fortify Labs, spent around two weeks examining a Shark 6 provided for the investigation.

What researchers found raised immediate questions about authentication and security in increasingly connected vehicles.

Hreszczuk said gaining access proved “easier than we were expecting.” Researchers identified an interface or access point that reportedly had no password or equivalent authentication. They then investigated the vehicle’s software and internal systems, including areas linked to its CAN-bus network.

The precise technical method used to gain entry has not been publicly revealed. That limitation is important because the demonstration does not establish that an attacker sitting anywhere in the world could simply take over an unsuspecting Shark 6 without first obtaining physical access.

The demonstration nevertheless showed just how much could potentially be done once researchers reached the relevant systems. While Four Corners reporter Angus Grigg drove the vehicle, researchers remotely activated a series of functions. They were able to lock the doors while Grigg remained inside, activate the windscreen wipers and washer jets, switch the headlights on and off and even turn the headlights completely off while the vehicle was moving.

The researchers also took control of the vehicle’s audio system, blasting music through the speakers and displaying images on the large infotainment screen. A repeated safety message was also played through the vehicle. The tests were conducted while the Shark 6 was being driven at low speed on a road near Canberra and later in the city.

Car Could Also Be Tracked?

The demonstration went beyond physical vehicle functions. Researchers were able to monitor the Shark 6’s location in real time, highlighting another potential privacy concern surrounding internet-connected vehicles.

A connected car can generate and transmit significant amounts of information about its users and movements, making the security of its communication systems increasingly important.

Perhaps one of the most concerning demonstrations involved the vehicle’s microphone. Researchers showed that they could activate the cabin microphone and listen to conversations taking place inside the vehicle. In a staged test, the microphone captured a conversation involving Grigg and his mother during which temporary internet-banking information was discussed.

The finding raised questions about what could happen if an attacker gained similar access to a connected vehicle without the occupants knowing.

Researchers also demonstrated how the vehicle’s audio system could potentially be used alongside a smartphone inside the cabin. They recorded Grigg saying “Hey Siri,” modified the recording with additional instructions and then played it through the vehicle’s speakers. With an unlocked iPhone inside the vehicle, Siri responded and disclosed personal information, including details such as an address, age or date of birth and contact numbers.

The demonstration reportedly included a contact number belonging to a high-profile individual. The test showed how compromising one connected system could potentially create opportunities to interact with other devices inside the vehicle.

Despite the dramatic findings, the demonstration did not show researchers taking control of the vehicle’s brakes or other critical driving systems. The cameras were also reportedly protected. That means the test did not demonstrate complete remote control of the Shark 6.

Pakistani News Channel’s Website Hacked by India’s ‘HIND CYBER GHOST’ group

Instead, the researchers accessed a range of peripheral and privacy-sensitive functions, including lights, wipers, audio, location tracking and the cabin microphone.

BYD has said it takes cybersecurity seriously and is investigating the findings. The auto manufacturer also questioned whether the demonstration proves that a completely remote attacker could reproduce the same access without first obtaining unrestricted physical access to the vehicle.

According to the company’s response, once someone has physical access to the vehicle, some authentication protections may no longer provide the same barrier. The exact technical pathway used during the investigation has also not been fully disclosed publicly.

The company has said Australian customer data is stored locally, including through infrastructure involving Telstra servers. BYD has rejected suggestions that it would hand Australian customer information to Chinese authorities and has called for dedicated legislation governing connected vehicles.

A privacy-policy change around the time of the media inquiry also attracted attention after references relating to surveillance and China were reportedly removed.

The controversy comes as cars increasingly resemble connected computers on wheels. Modern EVs and hybrids rely heavily on software, mobile applications, cloud services, telematics, Bluetooth, Wi-Fi, remote diagnostics and over-the-air updates. Every additional connection can potentially create another security challenge.

Several countries lack mandatory nationwide cybersecurity baseline specifically covering passenger vehicles, although consultations over stronger rules are underway. Privacy regulators are also examining broader questions about how connected vehicles collect, store and process information.

BYD case has also intensified Australia’s wider debate over Chinese-connected vehicles. Concerns have centred on data sovereignty, cross-border information flows and Chinese laws that can require companies to cooperate with authorities in certain circumstances. BYD has rejected suggestions that Australian customer information would automatically be accessible to Chinese authorities.

The debate, however, is not limited to Chinese manufacturers. Cybersecurity researchers have identified vulnerabilities involving connected systems across the global automotive industry, including remote interfaces, mobile applications and internal vehicle networks.

BYD demonstration could trigger further research into other connected vehicles. Researchers may examine additional Shark 6 vehicles as well as models from other manufacturers to determine whether comparable weaknesses exist. Potential targets for investigation include telematics systems, manufacturer APIs, Bluetooth and Wi-Fi connections, CAN-bus networks and over-the-air update mechanisms.

The industry has faced major cybersecurity incidents before. 2015 Jeep Cherokee case became one of the most prominent examples after researchers demonstrated remote manipulation of vehicle functions, eventually contributing to a major recall.

BYD’s investigation will determine whether the weaknesses identified during the demonstration can be reproduced and whether software changes can close the relevant access points. The episode could also increase pressure on Australian authorities to introduce mandatory cybersecurity requirements for connected vehicles.

Future regulations could address authentication, network isolation, software updates, vulnerability reporting and the collection and transfer of vehicle data. For drivers, the demonstration offers a broader warning about treating connected cars as computers rather than conventional vehicles.

Keeping software updated, reviewing connected-app permissions, checking privacy settings and avoiding sensitive conversations or confidential devices inside connected vehicles are among the basic precautions owners can take.

Let it be clear that BYD Shark 6 investigation does not show that thousands of BYD vehicles have been hacked or that criminals are currently exploiting the demonstrated weakness across Australia’s roads. It was a controlled, authorised cybersecurity test involving extended physical access to one vehicle. But the findings demonstrate why connected-car security is becoming an increasingly important issue.

Get Alerts