ABC Test Finds BYD Shark 6 Remote-Access Weakness as Australia Lacks Minimum Car Cyber Standards

A controlled cybersecurity test on a BYD Shark 6 has demonstrated how a modern connected vehicle can expose drivers to risks that were barely relevant when Australia’s road rules were designed.

ABC Test Finds BYD Shark 6 Remote-Access Weakness as Australia Lacks Minimum Car Cyber Standards

ABC’s Four Corners reported that Canberra cybersecurity expert Dan Hreszczuk was able to obtain remote access to a Shark 6 and control several functions during a test conducted for the program.

The demonstration did not show that every BYD vehicle can be compromised in the same way, and it did not give the tester access to the vehicle’s brakes or cameras. Those systems were reported to be well protected.

What it did show was a broader regulatory problem: cars are becoming computers on wheels, while Australia is still developing national cybersecurity standards specifically for road vehicles.

What the test actually found

According to Four Corners, the test vehicle exposed a remote-access point that Hreszczuk said was not protected by a password.

From there, the tester was able to demonstrate control over functions including the vehicle’s locks, infotainment system, audio, lights, windscreen wipers and washers.

The ABC also reported that the test allowed access to location information and the vehicle’s microphone.

Those capabilities matter because they move the risk beyond ordinary data theft. A connected car may contain information about where a person travels, when the vehicle is used and what is said inside it. Some remote functions can also affect the driver’s immediate environment.

In the demonstration, headlights could be switched off. The testing was carried out under controlled conditions and at low speed, and it should not be portrayed as an uncontrolled road attack.

Just as importantly, Hreszczuk was not able to access the brakes or the vehicle’s cameras. That limits what can reasonably be concluded from the test.

The result is not “a hacker can take over every BYD”. It is that one tested Shark 6 exposed a set of remote capabilities that cybersecurity specialists and regulators will want to understand.

Why connected cars create a new security problem

Modern vehicles rely on software for navigation, entertainment, safety systems, driver assistance, charging, maintenance and communications with manufacturers or service providers.

Many models have embedded mobile connections and cloud-linked apps. Owners can use their phones to find the car, unlock it, check status information or activate functions remotely.

Those conveniences require trusted digital pathways into the vehicle. If authentication, software updates, access controls or cloud infrastructure are weak, the same pathway can become a target.

Cybersecurity specialists often describe the challenge as an expanding “attack surface”. Every internet-connected service, app, wireless interface and software component can create another potential entry point.

That does not mean connected vehicles are inherently unsafe. It means manufacturers need security controls that are designed for the life of the vehicle, including secure updates, strong authentication, vulnerability management and protection of sensitive data.

Australia does not yet have vehicle-specific minimum cyber standards

The Four Corners report highlighted that Australia currently lacks minimum national cybersecurity standards specifically applying to road vehicles.

The federal government has acknowledged that gap.

Under Horizon 2 of the 2023–2030 Australian Cyber Security Strategy, the Department of Home Affairs says it is working with the federal transport portfolio to introduce new national road vehicle cybersecurity standards consistent with Australia’s international vehicle-regulation obligations.

The work is scheduled within the 2026–2028 phase of the strategy.

Australia already has Australian Design Rules covering areas such as vehicle safety, anti-theft requirements and emissions. The emerging question is how software security should sit alongside those traditional engineering standards.

The issue is increasingly urgent because vehicle software can change after a car is sold. A hardware safety rule is relatively static; cybersecurity requires continuous attention as vulnerabilities are discovered and attackers develop new techniques.

Data is part of the risk

Connected vehicles can generate and transmit a large amount of information. Depending on the model and services enabled, that can include location, diagnostics, driving behaviour, app identifiers, contacts or audio-related functions.

For ordinary drivers, the privacy question is whether they know what is being collected, where it is stored, who can access it and how long it is retained.

For senior government officials, defence personnel and people handling sensitive commercial information, the concern is more acute.

Australian security agencies have previously warned ministers and public servants to be cautious about sensitive conversations in connected vehicles and about linking official devices to cars.

That advice is not limited to one manufacturer or one country. The underlying risk comes from any platform that combines microphones, connectivity, location data and remote administration.

BYD’s response matters

BYD has said data it collects from Australian customers is stored in Australia and that it has not provided, and would not provide, Australian customer data to Chinese authorities.

That response should be included because cybersecurity reporting can easily slide into broader geopolitical claims that are not established by a technical test.

The Four Corners exercise examined a vulnerability on a particular vehicle. It did not demonstrate that customer data had been transferred to a foreign government, nor did it establish a deliberate backdoor.

Technical weaknesses can arise from design mistakes, configuration errors, third-party components or poor security practices. Determining the cause requires evidence from the manufacturer and technical analysis.

Why one successful demonstration still matters

A single test cannot establish how common a vulnerability is across a fleet, but it can still be valuable.

Security researchers often discover systemic problems by examining individual devices. If a weakness is tied to a shared software version, cloud service or architecture, the manufacturer can then determine whether other vehicles need a patch.

The appropriate next step is coordinated investigation and remediation, not panic.

Manufacturers need a clear process for receiving vulnerability reports, validating them, developing fixes and delivering secure software updates. Regulators need enough authority and technical capability to ensure serious problems are addressed.

Owners also need reliable information about whether a vulnerability affects their model and whether action is required.

Cars are not covered in the same way as many smart-home devices

Australia has already introduced mandatory baseline cybersecurity requirements for many consumer smart devices manufactured from March 2026.

Those rules cover areas such as passwords and vulnerability reporting for many internet-connected products, but vehicles sit within a different regulatory environment.

That separation makes sense because cars have specialised safety systems and international vehicle standards. It also means the transition to dedicated road-vehicle cyber rules needs to happen deliberately.

A vehicle security regime has to consider not only privacy and hacking but also functional safety. A compromised light, steering, braking or driver-assistance system could have physical consequences that are different from a hacked household gadget.

What a useful national standard would need to achieve

Good regulation would not require government to dictate every line of vehicle software. It would set outcomes manufacturers must be able to demonstrate: secure access controls, protected communications, processes for reporting vulnerabilities, secure software updates and a response plan when serious flaws are found after sale.

Because vehicles remain on Australian roads for many years, regulators will also need to consider how long manufacturers must provide security support. A car can still be mechanically serviceable long after its original infotainment platform or mobile-network technology becomes outdated.

What drivers can reasonably do now

Individual owners cannot redesign a vehicle’s cybersecurity, but they can reduce avoidable risks.

Drivers should keep vehicle software and companion apps updated, use strong unique passwords where accounts support them, enable multi-factor authentication when available and be cautious about linking unnecessary devices or accounts.

People who handle sensitive information should follow employer or government security advice about conversations and device connections inside connected vehicles.

Owners should also pay attention to manufacturer notices or security updates rather than assuming a software issue can be solved only during mechanical servicing.

The regulatory question is bigger than BYD

The BYD Shark 6 makes a compelling case study because the remote functions were demonstrated clearly, but the policy issue covers the entire connected-vehicle market.

Australian consumers are buying cars from manufacturers based in China, Japan, Korea, Europe, the United States and elsewhere, and almost all major brands increasingly rely on cloud services and software.

A national standard should therefore be technology- and risk-based rather than designed around one brand.

The government’s planned road-vehicle cybersecurity standards will need to address how new vehicles are certified, how vulnerabilities are reported, how security updates are maintained over a vehicle’s lifespan and how Australia aligns with international regulations.

The Four Corners test should not be read as proof that every BYD is insecure. It is evidence that the risks of connected vehicles are no longer theoretical.

For Australian regulators, the challenge is to close the gap between rapidly evolving vehicle technology and rules that can keep drivers’ data and physical safety protected.

Related Posts

Former teacher pictured in a portrait

Brisbane teacher accepts $1.27 million compensation payout after Marist College playground incident

A former teacher at Marist College Ashgrove has accepted a $1.27 million compensation payout after an incident in which she says hundreds of students surrounded her and…

Emergency responders near an ambulance

Mother charged with murder and attempted killing offences after Blue Mountains car stabbing

A 42-year-old mother has been charged with murder and two serious attempted-killing offences after her three children were found with stab wounds in a car at Valley…

Two people standing outside a public building

Barnaby Joyce says senior Liberals have discussed confidence-and-supply deal with One Nation

One Nation MP Barnaby Joyce says he has held discussions with “very, very senior” Liberals about a possible confidence-and-supply arrangement after the next federal election, highlighting the…

Pauline Hanson at a public appearance

Pauline Hanson condemns Channel Nine KKK segment and rejects link between One Nation and white supremacy

One Nation leader Pauline Hanson has condemned Channel Nine after the network broadcast an interview with Ku Klux Klan figure Thomas Robb, rejecting any suggestion that her…

Vehicle at the gates of a synagogue at night

Brisbane synagogue driver sentenced after hate-crime aggravation dropped from property-damage case

A Brisbane man who drove his vehicle through the gates of the Brisbane Hebrew Congregation has been sentenced for wilful damage and drug offences after prosecutors withdrew…

Person taking a mirror selfie indoors

South Australian child-sex offender released after serving full sentence, with no parole conditions imposed

A South Australian child-sex offender has been released from prison after serving a full sentence of four years and 10 months, with authorities confirming the release was…