A cybersecurity test of a BYD Shark 6 in Australia found that the connected Chinese EV could expose sensitive information and allow certain vehicle functions to be controlled remotely. The test raises questions about privacy and cybersecurity in modern cars that increasingly operate as software platforms with microphones, cameras and always-on internet connections.
What the BYD Shark 6 Hackers Could Access
An Australian cybersecurity expert decided to test how vulnerable his own BYD Shark 6, one of Australia’s best-selling trucks, could be to a cyberattack. The team compromised the vehicle in under two weeks and found that some data was not protected behind passwords.
Once inside the BYD, the team was able to track the vehicle’s location live. They could also activate the in-car microphone and listen to phone conversations taking place inside the vehicle.
The researchers also used Siri through the vehicle’s speakers to obtain personal information from a smartphone left inside the car. The information included a home address and a birthday.
Other capabilities included triggering the windshield wipers and switching the vehicle’s lights on and off.
The hacker said he was unable to access critical vehicle controls such as the brakes or steering. However, the test did not establish that a more determined hacker could never reach those systems.
Connected Cars Can Reveal More Than Location
The test highlighted how a connected vehicle can potentially provide access to information about its occupants and their routines. In this case, the researchers were able to use the BYD as a source of location information and as a listening device.
The test also indicated that some Chinese EVs may be more susceptible to cyberattacks than other connected vehicles. The concern comes as BYD ships cars in volumes that rival Toyota.
Xpeng Test Shows Extent of Vehicle Data Access
A separate part of the ABC News In-Depth experiment involved an insider from another Chinese EV manufacturer, Xpeng. The agent was able to connect to an Xpeng G6 electric coupe SUV while a reporter drove around town.
The agent could see the vehicle’s GPS coordinates, speed and steering angle in real time. The system also provided access to seat settings and could indicate how many people were inside the vehicle.
Xpeng officially says it cannot remotely immobilize its vehicles and has never handed over Australian customer data to Chinese authorities.
What the Cybersecurity Test Did Not Prove
The experiment did not establish that Chinese EVs are sharing data with China. Instead, it demonstrated the amount of information that manufacturers can potentially access from connected vehicles.
The test also highlighted broader concerns about connected-car privacy and security, particularly because some companies are selling customer data without consent and rules governing connected-car security are not watertight in many parts of the world.
For connected vehicles, the experiment ultimately demonstrates how much information can be accessible through modern automotive systems, from location and vehicle data to information about people inside the car.








