# Cybersecurity vulnerabilities in BYD and Xpeng vehicles

> Live situation record from CLSTR: https://clstr.news/situations/byd-shark-6-cybersecurity-vulnerabilities
> Updated: 2026-09-25T06:00:00.000Z. Sources: 6. Developments: 3.

A cybersecurity test conducted by Fortify Labs in Canberra revealed remote access vulnerabilities in the BYD Shark 6. During a demonstration for ABC News’ program ‘Four Corners’, researcher Dan Hreszczuk successfully gained remote control of the vehicle without a password, allowing him to lock doors, control wipers, play music, and eavesdrop on conversations via the internal microphone. While critical safety systems like brakes remained inaccessible, the researcher noted that manipulating lights or wipers while in motion poses serious risks.

Following the report, BYD Australia launched an investigation into the allegations. Stephen Collins, Chief Operating Officer of BYD Australia, stated the company is taking immediate action to review claims involving unauthorized remote access to certain non-critical functions. 

The incident has triggered calls for new Australian legislation regarding connected vehicles. Shadow Minister for Defence James Paterson raised concerns regarding data sovereignty, noting that electric vehicles manufactured by Chinese companies may be subject to Chinese national security laws requiring assistance with data collection.

Subsequent investigations by ABC News expanded the scope of these vulnerabilities to include Xpeng vehicles. Demonstrations involving Xpeng showed that remote access could allow unauthorized parties to view sensitive data, including location, speed, steering angle, seat position, and the number of occupants. While Xpeng stated that their vehicles cannot be disabled or stopped remotely and denied providing Australian customer data to Chinese authorities, the findings have heightened concerns regarding data collection. The Australian Automobile Dealers Association (AADA) noted growing consumer anxiety regarding how vehicle data—ranging from driving habits to microphone recordings—is protected and whether it is transmitted to manufacturer cloud systems.

## Timeline

### 2026-09-25: Cybersecurity vulnerabilities exposed in connected BYD and Xpeng vehicles

Cybersecurity experts have demonstrated remote control and data access vulnerabilities in connected vehicles, including BYD and Xpeng models, raising significant privacy and safety concerns in Australia.

2 sources. https://clstr.news/cluster/cybersecurity-vulnerabilities-exposed-in-connected-byd-and-xpeng-vehicles

### 2026-09-23: BYD Australia investigates vehicle hacking allegations

BYD Australia is investigating claims of vehicle hacking after a report showed remote access vulnerabilities in a BYD Shark 6, prompting calls for stricter connected vehicle legislation.

2 sources. https://clstr.news/cluster/byd-australia-investigates-vehicle-hacking-allegations

### 2026-09-21: BYD Shark 6 cybersecurity test reveals remote hacking vulnerabilities

A cybersecurity test of the BYD Shark 6 revealed that hackers can remotely control various vehicle functions and eavesdrop on cabin conversations without a password, raising major safety and privacy concerns.

2 sources. https://clstr.news/cluster/byd-shark-6-cybersecurity-test-reveals-remote-hacking-vulnerabilities

---
Cite as: Cybersecurity vulnerabilities in BYD and Xpeng vehicles. CLSTR, https://clstr.news/situations/byd-shark-6-cybersecurity-vulnerabilities
