A cybersecurity researcher in Canberra demonstrated that he could take remote control of a BYD Shark 6, one of Australia's best-selling plug-in hybrid utes, by exploiting an interface with no password. The test, conducted over two weeks by Dan Hreszczuk of Fortify Labs, showed that a malicious actor could disable headlights, activate wipers, blast audio through speakers, and record conversations inside the cabin, all without the driver's knowledge.
The attack surface
Hreszczuk's access point was not a sophisticated exploit. The interface he targeted had no password at all, giving him entry to the vehicle's internal communication bus. From there he could address individual software programs controlling different functions. Remote access let him toggle headlights, trigger windshield wipers at full speed, spray washer fluid, lock the doors with the driver inside, and display arbitrary images on the infotainment screen. The combination is designed to distract a driver at speed on a winding road.
Brakes and camera systems were protected and not reachable through the path Hreszczuk found. But the level of access he did achieve was enough for both sabotage and surveillance.
Surveillance through the cabin microphone
The surveillance demonstration was more alarming. Hreszczuk remotely accessed the vehicle's microphone while the reporter drove through Canberra. The reporter made a phone call discussing internet banking setup, including a temporary password built from personal details. Hreszczuk recorded the entire conversation from his lab.
He then extracted the "Hey Siri" wake phrase from the recording, stitched it with his own voice commands, and played the edited audio through the car's speakers into the reporter's unlocked iPhone while the car was parked at a service station. Siri responded to the fabricated commands without challenge, revealing the reporter's home address, date of birth, age, and a contact's phone number. Within minutes, Hreszczuk had the internet banking password and a list of contacts.
The attack chain is straightforward: the car provides the microphone access, the phone provides the voice assistant, and the two combine to extract data that neither system would release on its own.
Australia's regulatory gap
Australia has no minimum cybersecurity standards for vehicles. BYD is not required to keep its software updated or maintain a vulnerability management process for its cars. Home Affairs Minister Tony Burke defended the government's approach, saying connected household devices were regulated first for faster uplift and to target where attacks have principally occurred. New cybersecurity and software rules for cars are under consultation with industry but are years from taking effect.
The regulatory situation is inverted relative to the risk. Connected washing machines and vacuum cleaners face more cybersecurity requirements in Australia than connected cars. Alastair MacGibbon, the country's former national cyber security adviser, said a cabinet minister should not be able to own a Chinese EV, citing both surveillance and sabotage capabilities. ASIO has already warned ministers and public servants not to have sensitive conversations in their cars or connect work devices, though there is no ban on owning Chinese EVs.
Trade Minister Don Farrell owns a BYD Shark 6, the same model used in the demonstration.
BYD's response
BYD says the data it collects from its vehicles is stored in Australia and that it has not and would not hand over Australian customer data to Chinese authorities. The company has not addressed the specific vulnerability Hreszczuk demonstrated.
China's 2017 National Intelligence Law requires organizations and citizens to support, assist, and cooperate with national intelligence work, which is the core concern cited by security experts. The UK military has banned Chinese EVs, including those with Chinese components, from parking within three kilometres of sensitive sites. China itself has previously banned foreign EVs from military sites and political enclaves.
What this means for developers and security teams
The demonstration exposes a pattern common across connected vehicle platforms. The telematics and infotainment systems are built for convenience and over-the-air updates, not for adversarial conditions. Authentication is often absent or weak. The internal bus has no message authentication. A single compromised interface gives access to dozens of functions that were never designed to be exposed together.
For teams working on connected vehicle security, the lesson is that the attack surface is not just the external API. It is every path from a remote interface to the CAN bus, and every function that path can reach. The BYD Shark 6 had well-protected brake and camera systems, but the microphone, speakers, lights, wipers, and door locks were all reachable through an unauthenticated interface. The gap between what is protected and what is not is where the real risk lives.