
Fresh cyber security concerns have emerged around the BYD Shark 6 after a televised investigation demonstrated how a specialist hacker could remotely access and manipulate several vehicle functions. The exercise, conducted by Canberra-based Fortify Labs for the ABC's Four Corners program, highlighted how connected vehicles may be vulnerable to both sabotage and surveillance, prompting renewed discussion around cyber security standards for cars sold in Australia.

The investigation centred on a BYD Shark 6 that spent two weeks with Fortify Labs co-founder Dan Hreszczuk, a cyber security specialist focused on connected vehicles.
According to the investigation, Hreszczuk gained access to parts of the Shark's software architecture through a system that allegedly lacked password protection. From there, he was able to remotely control a range of non-critical vehicle functions.
During an on-road demonstration near Canberra, the researcher activated the windscreen wipers, operated the headlights, locked the doors and broadcast audio through the ute's infotainment system while the vehicle was being driven.
Hreszczuk told Four Corners the process was simpler than expected.
"It was easier than we were expecting."
"The access we took advantage of didn't even have a password."

The researcher said critical safety systems such as braking and vehicle cameras remained protected and were not accessed during testing. However, the demonstration raised questions about how much disruption could be caused through remote access to other connected vehicle systems.
The investigation also explored potential privacy implications. Using access to the vehicle's microphone and speakers, Hreszczuk demonstrated how conversations could allegedly be monitored remotely, before using recorded audio to trigger voice assistant functions on a smartphone left inside the vehicle.
The findings come as connected vehicles become increasingly common.
Modern electric vehicles and plug-in hybrids rely heavily on software, over-the-air updates and constant internet connectivity, allowing manufacturers to remotely update functions and collect operational data.
Australia's security agencies have previously warned that connected devices can present surveillance risks.

Speaking separately on a podcast interview, ASIO director-general Mike Burgess said modern vehicles were effectively "computers on wheels" and noted that anything connected to a communications network could potentially be exploited.
BYD said it takes vehicle security seriously and is investigating the claims raised in the Four Corners report.
"The safety of our customers and all road users is paramount," a BYD spokesperson said.
The cyber security discussion arrives as BYD continues to gain momentum locally.
The Chinese brand has become one of Australia's strongest-performing automotive manufacturers, with the Shark 6 emerging as a significant player in the increasingly competitive dual-cab ute market.
The Federal Government has begun consulting with industry on future cyber security regulations for vehicles, although any new standards are unlikely to be implemented quickly.
As cars become more software-driven, scrutiny of cyber security protections is expected to intensify across the entire industry, not just among Chinese manufacturers.
