< Back to situation

[REVISION HISTORY]

Cybersecurity vulnerabilities in BYD and Xpeng vehicles

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-25 03:33 UTC → 2026-09-25 10:30 UTC · added removed

BYD Shark 6 cybersecurity Cybersecurity vulnerabilities in BYD and Xpeng vehicles

A cybersecurity test conducted by Fortify Labs in Canberra revealed remote access vulnerabilities in the BYD Shark 6. During a demonstration for ABC News’ program ‘Four Corners’, researcher Dan Hreszczuk successfully gained remote control of the vehicle without a password, allowing him to lock doors, control wipers, play music, and eavesdrop on conversations via the internal microphone. While critical safety systems like brakes remained inaccessible, the researcher noted that manipulating lights or wipers while in motion poses serious risks. Following the report, BYD Australia launched an investigation into the allegations. Stephen Collins, Chief Operating Officer of BYD Australia, stated the company is taking immediate action to review claims involving unauthorized remote access to certain non-critical functions. The incident has triggered calls for new Australian legislation regarding connected vehicles. Shadow Minister for Defence James Paterson raised concerns regarding data sovereignty, noting that electric vehicles manufactured by Chinese companies may be subject to Chinese national security laws requiring assistance with data collection. Subsequent investigations by ABC News expanded the scope of these vulnerabilities to include Xpeng vehicles. Demonstrations involving Xpeng showed that remote access could allow unauthorized parties to view sensitive data, including location, speed, steering angle, seat position, and the number of occupants. While Xpeng stated that their vehicles cannot be disabled or stopped remotely and denied providing Australian customer data to Chinese authorities, the findings have heightened concerns regarding data collection. The Australian Automobile Dealers Association (AADA) noted growing consumer anxiety regarding how vehicle data—ranging from driving habits to microphone recordings—is protected and whether it is transmitted to manufacturer cloud systems.

Versions

  1. 2026-09-25 10:30 UTC Cybersecurity vulnerabilities in BYD and Xpeng vehicles
  2. 2026-09-25 03:33 UTC BYD Shark 6 cybersecurity vulnerabilities

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.