BYD Shark 6 Hacked Remotely: Security Expert Takes Control in Just Two Weeks
Generated by pixel @ 2026-09-23T02:33:57.857386
The BYD Shark 6 hacked in a controlled test has become one of the biggest car cybersecurity stories of the year. An Australian researcher remotely accessed the popular plug-in hybrid pickup in just two weeks, controlling its doors, headlights and cabin microphone. The test was carried out for ABC’s Four Corners investigation and has renewed global concern about how secure connected cars really are.
Key Takeaways
- Dan Hreszczuk, co-founder of Canberra-based Fortify Labs, hacked a BYD Shark 6 within two weeks.
- He found an entry point into the vehicle’s internal network with no password protection.
- He remotely locked the doors, controlled the wipers and switched off the headlights while the car was being driven.
- He accessed the cabin microphone and listened to a private phone call.
- Brakes, steering and cameras could not be accessed.
- BYD disputes the findings, saying the flaw requires physical access to the vehicle.
How Was the BYD Shark 6 Hacked?
Hreszczuk was asked to examine the Shark 6 for security weaknesses. Instead of a long, complex attack, he found an unprotected access point to the vehicle’s internal network. Once inside, he could reach software that controls many of the vehicle’s everyday functions.
He admitted the job turned out simpler than his team had anticipated. Summing up the flaw, he said: “I didn’t need to pick the lock as BYD left the front door open.”
What Could the Hacker Control in the BYD Shark 6?
During a live demonstration on a rural road near Canberra, ABC reporter Angus Grigg drove the Shark 6 at around 30 km/h while Hreszczuk worked from a laptop at the roadside. He was able to:
- Lock the doors with the driver still inside
- Run the windscreen wipers at full speed
- Spray washer fluid across the windscreen
- Flash the headlights on and off
- Switch the headlights off completely while the vehicle was moving
Losing headlights while driving at night could leave a driver unable to see the road ahead, which is why experts describe this as a serious safety risk even though braking was not affected.
Could the Hacker Listen to Conversations Inside the Car?
Yes. This was one of the most worrying parts of the test. Hreszczuk gained access to the cabin microphone and listened in from his lab while Grigg was on a phone call with his mother about online banking, including passwords and personal details.
He then used the car’s microphone and speakers to play synthetic voice commands that activated the voice assistant on Grigg’s smartphone. In simple terms, a compromised car could be used to both overhear and trigger actions on devices inside it.
Were the Brakes and Steering Safe?
Yes. The researcher could not access the braking system, steering controls or the vehicle’s cameras. These safety-critical systems appeared to be far better protected than comfort and convenience features.
What Has BYD Said About the BYD Shark 6 Hacked Claims?
BYD Australia told EV Central that it takes the allegations seriously and is running its own investigation, adding that the vulnerability appears to require unrestricted access to the vehicle first. The company also told CarsGuide it is questioning some of the claims. However, the concerns about how the car collects and handles personal data remain regardless of how the system is accessed.
Why Connected Car Cybersecurity Matters
Modern vehicles are essentially computers on wheels. Connected cars regularly gather and transmit:
- Audio from inside the cabin
- Images from external cameras
- Navigation and location history
- Phone contacts and call logs
The report highlighted that Australia currently has no minimum cybersecurity standards for connected vehicles. That means carmakers are not legally required to patch software or run formal cyber risk management programmes. Strikingly, connected washing machines in Australia face tougher cybersecurity rules than cars do.
Experts also raised concerns about data held by Chinese companies, since China’s national security laws can require firms to cooperate with state authorities. With Chinese EVs now making up roughly 40% of new car sales in Australia, the issue affects a large share of the country’s vehicles.
What the BYD Shark 6 Hack Means for Pakistan
Chinese automakers, including BYD, are expanding quickly in Pakistan’s auto market, and connected features such as app control, voice assistants and over-the-air updates are becoming standard selling points. As more of these vehicles reach Pakistani roads, questions about data protection, software security and local regulation will become just as important as price and range.
This story also fits a wider pattern of technology raising fresh privacy concerns, such as the recent case where a Meta AI agent shared a user’s address on Facebook Marketplace. For more on road safety and vehicles, visit our Auto section, and follow the latest on surveillance and digital systems in stories like Islamabad Safe City cameras getting legal protection.
How Can Car Owners Protect Themselves?
- Install software updates from the manufacturer as soon as they are available
- Avoid discussing passwords, OTPs or banking details on calls inside a connected car
- Review and limit data sharing permissions in the car’s companion app
- Disconnect or unpair phones you no longer use from the infotainment system
- Ask dealers what cybersecurity protections and update policies come with the vehicle
The BYD Shark 6 hacked test is a clear reminder that car security now matters as much as crash safety. Stay updated with the latest in tech, AI and cybersecurity on our Technology page and explore local innovation in Digital Pakistan.
