A researcher sat on the shoulder of a road outside Canberra with a laptop and switched off the headlights of a moving BYD Shark 6. There was a reporter at the wheel.
The stunt was staged for Australia’s ABC and its investigative program Four Corners, which handed the plug-in hybrid ute to Dan Hreszczuk, co-founder of Canberra firm Fortify Labs. He had two weeks to find out what could be seen and done to the truck from a distance. His verdict, as published in the ABC’s own account, was blunt: “The access we took advantage of didn’t even have a password.”
The Demo: Annoying, Distracting, Then Dark
The sequence escalated nicely for television. With reporter Angus Grigg inside, Hreszczuk locked the doors, pumped music through the speakers and threw images onto the infotainment screen. Once the ute was moving, he ran the wipers at full speed, fired the washer jets and flicked the headlights on and off before shutting them down completely.
Related Articles
- Car Payments Just Hit a September Record of $821. Prices Barely Moved. Here’s Where the Money Went.
- Buyer Alert: Washington Just Cut the 2031 Fuel Economy Target to 34.9 MPG. Here’s What It Means for Your Next Car
Relax about the cliff scenario: the 2.6-tonne ute was only doing about 30 km/h on a reasonably straight road. Hreszczuk also said he couldn’t get into the brakes or cameras, which he described as well protected.
That’s the good news, and why it happened is worth a minute.
Why He Got the Lights But Not the Brakes
Modern cars run on internal networks, most commonly the CAN bus, which dates back to an era when nobody expected a stranger to be plugged into it. Classic CAN has no built-in way to verify who sent a message. If a module on the network says “headlights off,” the headlight controller generally believes it.
Hreszczuk explained the point in the broadcast episode, where he described the CAN bus as the internal network that the car’s components use to talk to one another. The footage also shows him hunting through the ute for places to tap into it.
Well-engineered cars put gateways between the comfort-and-convenience side of the network (lights, locks, wipers, audio) and the chassis side (brakes, steering, powertrain). The fact that Hreszczuk could play DJ but couldn’t touch the brakes suggests BYD did segment the safety-critical systems. The failure was leaving an unauthenticated door open into the “soft” side of the car, and it turns out the soft side can be dangerous too. Killing the headlights at night on a twisty road is not a cosmetic problem.
The Asterisk: This Started With the Keys
Before this turns into “BYDs can be hacked from the roadside”: this was not a drive-by attack on a random stranger’s truck. Hreszczuk had the Shark in his workshop for two weeks, with time to pull trim, probe connectors and study the car’s software. The “remote” portion of the demonstration came after that period of unrestricted physical access.
That doesn’t make the result meaningless. Plenty of people get unsupervised time with your car: valets, detailers, independent shops, a buyer on a test drive, or whoever owned it before you. An interface that accepts commands with no password is sloppy engineering regardless of how an attacker reaches it. But it’s a very different threat from a mass wireless exploit that could hit every Shark on the road at once. Until BYD or an independent researcher shows whether the open door exists on stock, untouched vehicles, owners should treat this as a serious warning, not proof of a fleet-wide emergency.
The Nastiest Trick Had Nothing to Do With Driving
The sabotage footage got the headlines, but the surveillance demo is what should make owners wince. While Grigg drove around Canberra, Hreszczuk tracked the car’s location in real time and switched on the cabin microphone. Grigg made a phone call and, as a planned part of the test, recited the details of a temporary banking password.
Then came the clever bit. Hreszczuk recorded Grigg saying “Hey Siri,” spliced it with his own questions, and played the audio through the car’s speakers while Grigg’s unlocked iPhone sat in the cabin. Siri obediently gave up the home address, date of birth and a contact’s phone number.
Note what actually happened there. The car didn’t leak that data. The car became a microphone and a loudspeaker, and those were used to attack the phone. That’s a threat model most drivers have never considered: your car’s audio hardware can be a bridge to every voice-activated device inside it.
BYD’s Position
BYD told the ABC that the data it collects is stored in Australia, and that it has never handed Australians’ data to Chinese authorities and would not do so. Meanwhile, the ABC separately documented a change to BYD’s Australian privacy policy, reporting that references to “China” and “surveillance” disappeared just days after the program sent the company questions. Changing the wording of a privacy policy does nothing to the software in the truck.
Australia’s Regulatory Blind Spot
The episode also exposed a legal gap. Australia currently has no minimum cybersecurity standards for cars, so BYD has no legal obligation to keep its software updated or to run a formal cyber-risk management system. Cyber Security Minister Tony Burke defended focusing first on household connected devices, while the government has only just begun consultations with industry on vehicle rules that likely won’t take effect for years. Since March, a Wi-Fi washing machine sold in Australia has had to meet mandatory cyber rules, including a ban on universal default passwords. Road vehicles are specifically exempt, so a ute that can tow 3.5 tonnes doesn’t.
Why Americans Shouldn’t Feel Smug
The Shark 6 isn’t sold in the U.S., and Washington has already tackled the China question from a supply-chain angle. The Commerce Department’s connected vehicle rule bans connected passenger vehicles from manufacturers tied to China or Russia starting with the 2027 model year, and connectivity hardware from those countries starting with the 2030 model year.
But the flag on the grille doesn’t determine whether a car can be hacked. Engineering does. The industry’s defining cyber recall came from Detroit, not Shenzhen. In July 2015, Fiat Chrysler filed a safety recall covering roughly 1.4 million 2013–2015 vehicles with Uconnect radios, after researchers showed software flaws could allow outsiders to manipulate networked vehicle controls. NHTSA opened its own recall query to scrutinize that fix. More than ten years later, an unauthenticated entry point on a best-selling ute shows how uneven the progress has been.
What Owners and Buyers Should Actually Do
Keep your phone locked in the car, and consider disabling voice-assistant access on the lock screen. The Siri trick only worked because the phone was unlocked and listening.
Related Articles
- Arizona Driver Going the Wrong Way on I-40 Tells Troopers He Was ‘Supervisor’ of a Game Called ‘Lunatic,’ Then Gets Arrested for Endangerment
- Subaru Cut the Impreza’s Price by $2,000. Its Own Sales Numbers Explain Why.
Install every over-the-air and dealer software update. If an automaker patches this, the fix will almost certainly arrive as software, and it’s worth nothing if you ignore the notification.
Treat physical access as a security event. If your car has spent unsupervised time with someone you don’t trust, or you bought it used, ask the dealer to check for aftermarket devices plugged into diagnostic ports or wiring. Remove the previous owner from any connected-car app and perform a factory reset of the infotainment system.
Don’t hold sensitive conversations in any connected car if you have real reason to worry about being targeted. That applies regardless of what country built it.
Check your insurance policy. Coverage for losses caused by cyber intrusion, such as theft via a hacked lock or a crash caused by manipulated systems, isn’t guaranteed. Ask your insurer directly, and get the answer in writing.
A few years ago, hacking a car required months of work from elite researchers. This time it took one specialist two weeks and a password field that was never filled in.
Images Via: BYD
Does a hack that needed two weeks in a workshop worry you, or is the missing password the real scandal? Which connected feature would you switch off first if you could? Tell us in the comments.

