started · updated
BYD Shark 6 cybersecurity test reveals remote hacking vulnerabilities
A cybersecurity test conducted by Fortify Labs in Canberra has revealed significant remote access vulnerabilities in the BYD Shark 6. During a demonstration for ABC News’ program ‘Four Corners’, researcher Dan Hreszczuk successfully gained remote control of the vehicle without requiring a password.
Hreszczuk demonstrated the ability to remotely lock doors, control windshield wipers, play music, and manipulate the infotainment screen. Most critically, he was able to activate the vehicle’s internal microphone to eavesdrop on conversations. In one instance, the researcher used recorded audio to trigger voice commands via the car’s system, allowing him to access personal information such as the driver’s birth date and contact details.
While the researcher could not control critical safety systems like brakes or cameras, he noted that interfering with lights or wipers while a vehicle is in motion poses serious safety risks. The findings have renewed concerns regarding the data security of Chinese-made electric vehicles in Australia, particularly as software is controlled by entities in China. BYD has stated that it stores data in Australia and does not provide user information to Chinese authorities.