An Australian cybersecurity expert exposed critical vulnerabilities in a Chinese electric vehicle during an ABC Four Corners investigation.
Dan Hreszczuk, co-founder of Canberra-based Fortify Labs, spent two weeks testing a BYD Shark 6 plug-in hybrid pickup. The results alarmed even a professional car security researcher.
Hreszczuk discovered an access point to the vehicle’s internal network that had no password protection whatsoever. Unlike physical locks requiring skilled manipulation, this digital entrance remained completely open. Once inside, he gained access to software controlling numerous vehicle functions. The Shark 6, popular with Australian tradespeople and federal politicians, suddenly became unexpectedly vulnerable to remote manipulation.
During a demonstration on a country road outside Canberra, the scope of the compromise became starkly evident. While ABC reporter Angus Grigg drove the Shark at approximately 30 kilometers per hour, Hreszczuk sat roadside with a laptop and demonstrated what remote access meant in practice. He remotely locked the doors while Grigg remained inside the vehicle. Subsequently, he activated the windscreen wipers at maximum speed, sprayed the windscreen with water, and turned the headlights on and off. Most alarmingly, he cut the lights completely while the car was moving, plunging the road ahead into darkness.
The privacy implications proved equally concerning. Hreszczuk gained access to the vehicle’s cabin microphone and demonstrated remote monitoring capability. While Grigg was talking to his mother on the phone about internet banking, discussing temporary passwords and personal information, Hreszczuk was listening from his lab. He then used the microphone and speakers to trigger voice assistant functions on Grigg’s smartphone through synthesized speech commands. This demonstrated how sensitive personal information could be captured during calls made inside the vehicle.
Importantly, certain critical systems remained protected. Hreszczuk could not access the braking system, vehicle cameras, or steering controls. These safety-critical functions proved significantly harder to compromise. However, the researcher’s findings raised fundamental questions about connected vehicle security and data collection practices.
The vulnerability stems partly from regulatory gaps rather than technical limitations. Australia currently lacks minimum cybersecurity standards for connected vehicles. This means manufacturers like BYD face no legal requirement to maintain patched software or implement formal cybersecurity risk management systems. Remarkably, Australia maintains stricter cybersecurity rules for connected washing machines than for automobiles.
Meanwhile, the data collection practices inherent to modern vehicles compound the risk. Connected cars routinely collect and transmit internal audio, external images, navigation entries, and phone logs. Experts warn that data poses particular risks when held by Chinese companies. China’s national security laws can compel businesses to cooperate with government authorities, creating potential surveillance and espionage concerns for Australian drivers.
Chinese electric vehicles now represent approximately 40% of Australia’s new car sales, meaning vulnerability affects a substantial portion of the country’s automotive fleet.
Hreszczuk emphasized one critical detail:
“I didn’t need to pick the lock as BYD left the front door open.”
BYD has disputed aspects of the investigation, saying the security vulnerability supposedly requires physical access to exploit. However, the investigation raised distinct concerns about data handling regardless of access methodology.
