BYD Shark 6 Cybersecurity Hack Raises Key Security Concerns

The BYD Shark 6 cybersecurity hack has exposed potential access to sensitive vehicle data and certain vehicle functions, after Australian security researchers at Fortify Labs hacked a BYD Shark 6 over a two-week period. The research showed access to location data, phone calls made in the vehicle and functions including the headlights and windscreen wipers.…

The BYD Shark 6 cybersecurity hack has exposed potential access to sensitive vehicle data and certain vehicle functions, after Australian security researchers at Fortify Labs hacked a BYD Shark 6 over a two-week period. The research showed access to location data, phone calls made in the vehicle and functions including the headlights and windscreen wipers.

BYD Investigates the Cybersecurity Issue

Fortify Labs conducted the research in Australia, with Four Corners reporting its findings on September 21, 2026. Following the report, BYD Australia launched a formal internal investigation into the matter.

BYD China described the issue as a “software defect” that was exploited through an “Android Debug Bridge” (ADB), a tool that enables access to Android devices.

The Shark 6 uses the Android-based “DiLink” infotainment system, which is also used in other BYD and Denza models. The system is heavily customized by BYD, but the incident has raised concerns about Android-based infotainment systems used by other vehicle manufacturers.

BYD Says the Issue Has Been Resolved

According to a report from Car Expert, BYD determined that the application involved in the experiment required physical touch to confirm its installation into the infotainment system.

BYD subsequently issued a corrective action that “removes the unintended pathway that allows ADB to be enabled through the infotainment system user interface, thereby eliminating the access path identified during the investigation.”

The company said an over-the-air update for the Shark 6 will be issued “only once the updated software has undergone rigorous validation.” BYD also said it would examine whether its other products require the same security patch.

Fortify Labs Clarifies How the Research Was Conducted

Fortify Labs published its own account of the research, explaining that the Four Corners episode did not show everything that was done to the vehicle.

The company’s initial goal was to “simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused.” Fortify Labs said the Four Corners report brought attention to the issue but clarified several details about its work.

The vehicle used during the research and filming was a 2025 BYD Shark 6 Premium owned by Fortify Labs. The company said the vehicle was fully patched, with all software updates applied, as of 16 July 2026, while research began on 17 July 2026.

The head unit’s software version was reported as 56.1.2.2507080.1. Fortify Labs said it used a publicly known technique to gain unprivileged access to the head unit and then installed software that achieved most of what was demonstrated.

Physical access to the vehicle was required to install the software on the head unit. From that point, the connectivity and control of the software functioned remotely.

How the Vehicle Functions Were Accessed

Fortify Labs also tapped the CAN bus line to demonstrate what could happen if an ECU on that network were compromised. This was used to switch off the lights and activate the windscreen wipers.

The company said this was achieved in-line, with a Raspberry Pi simulating a compromised ECU and sending CAN bus messages.

No firmware was modified anywhere on the system, and Fortify Labs said it did not attempt to escalate privileges because doing so was not required for the demonstration.

The Vehicle Was Isolated From BYD’s Infrastructure

Before beginning its research, Fortify Labs removed the SIM card from the telematics box inside the vehicle. The company said this isolated the vehicle from the internet and prevented it from interacting with any part of BYD’s back-end infrastructure.

Fortify Labs said the measure was taken as a safety precaution to ensure that its research did not interact with or affect BYD’s online services or infrastructure.

Internet connectivity outside that system was established by connecting the vehicle to a cellular hotspot inside the car. Fortify Labs said the vehicle used its own infrastructure and cellular connection, and that the BYD-provisioned SIM card and BYD-provided internet access were not used to remotely interact with the vehicle during the research or demonstration.

Physical Access Remains a Requirement

For the demonstrated method, physical access was required to install software and tap into the CAN bus line before access to the vehicle’s functions could be obtained.

Although the BYD Shark 6 was the vehicle featured in the Four Corners report, Fortify Labs said “this same [hacking] technique can be used against other Android-based head units in vehicles from other manufacturers if they are not adequately locked down.”

Fortify Labs also stressed that the issue is not limited to Chinese automakers. The company said vehicle manufacturers in the U.S., Europe and the rest of Asia face the same broader concern.

“It’s also worth highlighting that these risks are not faced by Australia alone. This is a global issue, and other countries should be concerned,” Fortify Labs continued.

Calls for a Cybersecurity Star Rating

One recommendation stemming from the incident was a “Cyber Security Star Rating” conducted alongside the Australian NCAP star rating.

However, establishing such a system would present significant challenges. Unlike physical crashes, cybersecurity threats and effective protections can change over time.

There is also currently no established process and rubric for the industry to determine how cyber-secure a vehicle is. As a result, there is no guarantee that a 5-star car purchased today will not become vulnerable tomorrow.

Looking for a rental car near you? Whether you need a vehicle for a weekend trip, business travel, a family vacation, or everyday transportation, you can easily explore available rental car options in your area.

Ready to find a rental car near you? Rental Cars Near Me and check the latest available offers.

Follow the latest updates through Latest Automotive News.

About the Author

Jason Cooper Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *