> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> A BYD Shark 6 Hack Shows the Risks of Connected Cars

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 21/09/2026 10:32] [LANGUAGE: EN]
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights with a keystroke. That’s not a hypothetical. It’s what happened during a two week test by Four Corners and a cybersecurity researcher named Dan Hreszczuk. Hreszczuk runs Fortify Labs in Canberra and specialises in car security. His job was simple: find out what BYD, or anyone with access to BYD’s systems in China, could see and do to the vehicle remotely. He didn’t expect it to be quick. “It was easier than we were expecting.” Hreszczuk says. That wasn’t just an offhand comment. Hreszczuk makes a living finding ways to break into cars, so the fact that he was surprised by how easy it was is significant. Even he didn’t expect to get access so quickly or find so little standing in his way. The entry point had no password at all. There was nothing protecting it. That one weakness gave Hreszczuk a way into the software that controls many of the car’s functions. After spending two weeks exploring the system and testing what he could do, he was ready to show the results in a real-world demonstration. “Sitting by the side of the country road, he demonstrates what can be done with remote access to a vehicle. First, he locks the doors while I’m inside, blasts music over the speakers and plays images on the BYD’s giant infotainment screen.” reads the report published by ABC News. “Then, as I drive, he remotely switches the wipers on at top speed, sprays the windscreen with water and turns the lights on and off.” While Four Corners reporter Angus Grigg was driving the BYD at about 30 km/h along a straight country road, Hreszczuk controlled parts of the vehicle from his laptop. He locked the doors remotely, turned up the music through the speakers and displayed random images on the infotainment screen. He then switched the windscreen wipers to their highest setting, sprayed the windscreen and repeatedly turned the headlights on and off. At the same time, a recorded voice played through the speakers, warning the driver to use low beam. Then things became more serious. Hreszczuk switched the headlights off completely while Grigg was still driving the car in the dark. He was not able to control everything. The brakes and cameras were protected by stronger security measures, so he could not access them. But the test still showed what could happen if someone gained remote access to a connected vehicle. Imagine the same attack taking place at 100 km/h, on a winding road at night, with the driver suddenly losing control of the lights and having the wipers running at full speed. The potential danger is obvious. Sabotage got the dramatic demo, but surveillance is the bigger worry security experts keep raising. Modern EVs are covered in cameras and microphones, and with a Chinese manufacturer, there’s a legal wrinkle: China’s national security laws can compel companies to cooperate with the state on data requests. The UK military took that risk seriously enough last year to ban Chinese made EVs from parking within 3 kilometres of its most sensitive sites. China does the same thing in reverse, keeping foreign EVs away from its own military and political areas. Australia has not taken such a strict approach. ASIO has warned ministers and public servants not to discuss sensitive information inside these cars or connect work devices to them. But there is still nothing stopping ordinary people from buying and using one. Even Trade Minister Don Farrell drives the same BYD Shark model that was hacked during the test. He has publicly described it as the best ute he has ever owned. The timing is certainly awkward. But the surveillance part of the test was arguably more worrying than the ability to control the headlights. Once Hreszczuk gained basic access to the vehicle, he was able to track its location in real time as it moved through central Canberra. He then remotely activated the microphone inside the cabin. At the time, Grigg was talking to his mother on the phone and helping her set up internet banking. He also said “Hey Siri” to unlock his phone and then read out a temporary password. The password was based on his initials, house number and full date of birth. The car’s microphone picked up all of it. The test showed that an attacker with access to the vehicle could potentially listen to conversations happening inside the cabin and collect sensitive information without the people inside knowing it was happening. Hreszczuk had a recording of Grigg’s own voice saying “Hey Siri.” Later, when the phone was sitting unlocked in the car, he stitched that recording together with new questions and played the audio back through the car’s speakers. The phone answered “Hey Siri, what is my home address?” without questioning why its owner didn’t seem to know where he lived. Same trick pulled his date of birth, his age, and, because why stop there, a phone number for former Prime Minister Malcolm Turnbull straight out of his contacts. Within minutes, that internet banking password was fully exposed. All from a car microphone and a voice assistant doing exactly what it’s designed to do: trust whoever’s voice it hears. Part of why this was so easy comes down to regulation, or the lack of it. Australia currently has stricter cybersecurity rules for connected washing machines than it does for cars, which is a genuinely strange sentence to have to write. “Hreszczuk’s hacking challenge was made easier because Australia has no minimum cybersecurity standards for cars.” continues ABC News. “That means BYD is not compelled to keep its software up to date or have a system for managing cybersecurity risks to its vehicles.” BYD isn’t required to keep software patched or maintain any formal system for managing vehicle cybersecurity risk, because no such requirement exists yet. “I didn’t need to pick the lock as BYD left the front door open.” said Hreszczuk. The government has started consulting industry on new cybersecurity rules for cars, but those protections are years away from taking effect. Meanwhile, Alastair MacGibbon, Australia’s former national cyber security adviser, argues a sitting cabinet minister shouldn’t be driving a Chinese made EV at all, given the country’s track record on data collection and surveillance. He’s careful to separate capability from intent, admitting he doesn’t actually know whether that intent exists, but the capability, he says, is undeniably there. BYD’s response is that all Australian customer data stays in Australia and that it has never handed anything over to Chinese authorities. Maybe true. But “we haven’t done it yet” isn’t the same as “we structurally can’t,” and a car with no password protecting its own control systems doesn’t inspire much confidence either way. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, BYD Shark)
[messages.read_original_source] →