BYD Shark 6 Hack Exposes Password-Free Access to Ute’s Systems

A cybersecurity researcher gained remote control of a BYD Shark 6’s lights, wipers, doors and speakers after finding the vehicle’s access point had no password at all.

In an Australian Broadcasting Corporation’s (ABC) Four Corners program, a cybersecurity researcher has demonstrated how easily a BYD Shark 6 hybrid ute can be remotely accessed and manipulated, raising fresh questions about connected-car security in Australia.

Dan Hreszczuk, co-founder of Canberra-based Fortify Labs, spent two weeks testing a Shark 6 supplied for the investigation. He found the access point he used had no password protecting it at all, allowing him to explore the vehicle’s onboard software with little resistance.

What the hacker could control

While an ABC reporter drove the 2.6-tonne ute, Hreszczuk remotely locked the doors, played music and images through the infotainment system, and switched the wipers and windscreen washers on at speed. He also killed the headlights while the vehicle was moving, and triggered a recorded safety message urging the driver to use low beam.

But don’t be overly worried, Hreszczuk said he could not access more critical systems such as brakes or cameras, which he described as well protected. He called the ease of the access he did obtain surprising, given how little effort it took to get past BYD’s defences.

A voice-assistant workaround

In a separate test, Hreszczuk used the car’s remote microphone access to record the reporter saying “Hey Siri” during a phone call. He then edited that clip with follow-up questions and played it back through the car’s speakers, prompting the phone’s assistant to reveal a home address, date of birth and a stored contact number, all without the phone being unlocked by anyone in the vehicle.

Regulation still years away

Australia currently has no minimum cybersecurity standards for cars, meaning manufacturers like BYD are not required to keep software updated or maintain formal risk-management systems. The federal government has begun industry consultations on new cybersecurity and software rules for vehicles, but any resulting regulation is not expected to take effect for years.

Experts interviewed for the investigation raised broader concerns about data collected by Chinese-made EVs, given Beijing’s national security laws can compel companies to cooperate with authorities. The UK has previously barred Chinese-made EVs from parking near sensitive military sites, and China itself restricts foreign EVs from similar locations. BYD has said the data it collects from Australian customers is stored in Australia and has not been, and would not be, handed to Chinese authorities.

Why it matters

The findings highlight a gap between how quickly connected vehicles have adopted remote software control and how slowly regulation has kept pace. With EVs and plug-in hybrids now making up close to a third of new car sales in Australia, and Chinese brands accounting for more than half of that share, the security of these systems is becoming a mainstream concern rather than a niche one.

For BYD, the episode is a reminder that software convenience carries its own risks, and that a missing password can undo an otherwise VERY well-regarded product.

Before you go

Liked that? There’s a weekly email.

The best of Tarmac Life — reviews, news and what’s on the show — once a week, straight to your inbox.

Free. No spam. Unsubscribe in one click.

Share your love
Facebook
Twitter

Newsletter

The Tarmac Life Email

Get Tarmac Life in your inbox

One email a week: what’s on the show, the week’s best reads, and the odd bit of automotive nonsense.

Free. No spam. Unsubscribe in one click.

Support our advertisers


Paying bills

Ads from the Googles

Support our advertisers

Leave a Reply

Your email address will not be published. Required fields are marked *

Secret Link

Get the weekly Tarmac Life email