Skip to content
SUNDAY, SEPTEMBER 20, 2026

Independently reported.

Tech

A BYD Ute Had No Password on Its Remote Access Point. A Hacker Proved It.

A Canberra researcher took remote control of a BYD Shark 6's lights, locks and microphone in under two weeks, no credentials required. Australia has no minimum cybersecurity rules for connected cars, and the car industry says current standards are already enough.

By Mara Voss, Technology

· 4 min read · Updated

A pickup truck's dashboard glowing with digital display lights in a dim garage at night, no people, no visible text or logos.
Illustration: Trestlewire

Key Takeaways

  • Fortify Labs co-founder Dan Hreszczuk remotely controlled a BYD Shark 6's headlights, locks, wipers and cabin microphone during a Four Corners test, using an access point that required no password.
  • The hacked microphone recorded a driver reading a temporary banking password aloud, and a spliced 'Hey Siri' recording was used in an attempt to extract more data through the car's speakers.
  • Senator James Paterson and former national cyber security adviser Alastair MacGibbon both say Australia has no rules governing what data Chinese-made connected cars can collect or where it goes.
  • Four Chinese vehicle brands, including BYD, cracked Australia's top 10 sellers for the first time in August 2026, with more than 20,000 Chinese-made vehicles sold that month.
  • In Israel, operatives linked to the Palestinian Authority have used a separate, physical exploit on BYD's onboard diagnostics port to steal vehicles in seconds, prompting a software update to thousands of cars.

Dan Hreszczuk spent two weeks trying to break into a BYD Shark 6. He barely needed the two weeks. The digital access point controlling the plug-in hybrid ute's headlights, door locks and cabin microphone had no password on it at all.

Hreszczuk co-founded Fortify Labs, a Canberra cybersecurity firm, and ABC News commissioned him for its Four Corners program, which aired the results this month, to test what China's top-selling EV brand could see and do from outside the vehicle. "I didn't need to pick the lock as BYD left the front door open," Hreszczuk said.

The short answer

Fortify Labs co-founder Dan Hreszczuk remotely accessed a BYD Shark 6 for a Four Corners investigation, gaining control of its headlights, door locks, wipers, infotainment and cabin microphone without entering a password, while the vehicle was in motion. Australia has no mandatory cybersecurity standard for connected cars, so BYD faces no legal requirement to fix the flaw or tell owners about it.

Zero

passwords needed to reach the ute's controls

Fortify Labs used an access point with no credentials at all to reach the BYD Shark 6's lights, locks, wipers and microphone, per the Four Corners investigation.

What he could reach from outside the car

  • Killed the headlights and switched them back on
  • Locked and unlocked the doors
  • Ran the wipers and windscreen spray
  • Took over the infotainment screen and speakers
  • Turned on the cabin microphone and recorded audio
  • Tracked the vehicle's location in real time

A phone call to Mum became a demonstration

For the test, the driver called her mother from inside the moving ute to walk through setting up a new online banking password. She read it out loud: her initials, her house number, then her full date of birth. Hreszczuk's access to the cabin microphone caught the entire call.

He then spliced a recording of her saying "Hey Siri" together with follow-up questions of his own, playing the combination back through the car's speakers in an attempt to trigger her phone's voice assistant into handing over more personal information.

Officials do not agree on what happens next

Alastair MacGibbon, Australia's former national cyber security adviser, told the ABC that "China has always shown its strong desire to steal things, to surveil," and said he has no doubt Chinese-made connected vehicles get put to the same use. He has also argued that a federal cabinet minister should not be driving a Chinese EV, a pointed line given that Trade Minister Don Farrell owns a BYD Shark 6, the same model Hreszczuk hacked, and recently called it the "best ute I've ever owned."

A connected EV vehicle from China is the highest-risk product in the marketplace. And right now, there's nothing that says to that brand what data you can collect on Australians, how it can be stored, when it can be transmitted.

Senator James Paterson, the Coalition's defence spokesman

Australia has no minimum cybersecurity standard for connected cars at all right now, a gap MacGibbon and Paterson both point to. A rule covering internet-connected devices generally is still under government consultation, and neither official expects it to reach vehicles for years.

The industry says current rules are already enough

Region reported that the car industry maintains existing safety standards are sufficient, even as Chinese-made vehicles gain ground fast. Four Chinese brands, BYD, GWM, MG and Chery, cracked Australia's top 10 sellers for the first time last month, with more than 20,000 Chinese-made vehicles sold in August alone. Canberra is responding by pairing its new Cyber Security Centre of Excellence with the city's Electric Vehicle Centre of Excellence to study connected-car risk directly.

This is not BYD's first break-in

The flaw Hreszczuk found required no physical contact with the vehicle. BYD has already had a different kind of security problem elsewhere. Ynetnews reported that operatives linked to the Palestinian Authority obtained tools that plug directly into BYD's onboard diagnostics port, letting them start and drive off with a car in seconds. BYD's local distributor in Israel pushed a software update to thousands of vehicles after theft reports piled up.

That is a different vulnerability, physical rather than remote, in a different country. Both show the same design habit: functions built into the car for convenience, reachable by someone the owner never authorized.

Nothing in Australian law requires BYD to fix the access point Hreszczuk found, or to tell Shark 6 owners it exists. The government's promised minimum cybersecurity standard does not yet cover cars, and officials on both sides of politics say a fix is still years away. Until then, the password needed to reach a moving vehicle's lights, locks and microphone was the one BYD never set.

  • BYD
  • cybersecurity
  • connected cars
  • Fortify Labs
  • Australia
  • data privacy

Sources

  1. 01We got a cybersecurity expert to hack this BYD. It was too easy, ABC News Australiaabc.net.au
  2. 02Report on BYD onboard diagnostics port theft in Israel, Ynetnewsynetnews.com
  3. 03Coverage of Canberra's Cyber Security Centre of Excellence and connected-vehicle risk, Regionregion.com.au

Corrections

No corrections have been made to this article.

About the reporter

Mara Voss

Technology Reporter, Trestlewire

I spent seven years as a product manager at a mid-size SaaS company before I ever wrote a sentence for pay, which means I have sat through more roadmap reviews than most people would tolerate in a lifetime. I watched a scheduling feature get rebranded three times before it shipped, and I watched a launch date slide past four straight quarters while the slide deck stayed exactly the same. That is where the question I still ask every day came from: does this actually ship, or is it a demo.

Read full bio and all stories →