ABC Test Finds BYD Shark 6 Remote-Access Weakness as Australia Lacks Minimum Car Cyber Standards

A controlled cybersecurity test on a BYD Shark 6 has demonstrated how a modern connected vehicle can expose drivers to risks that were barely relevant when Australia’s road rules were designed.

ABC Test Finds BYD Shark 6 Remote-Access Weakness as Australia Lacks Minimum Car Cyber Standards

ABC’s Four Corners reported that Canberra cybersecurity expert Dan Hreszczuk was able to obtain remote access to a Shark 6 and control several functions during a test conducted for the program.

The demonstration did not show that every BYD vehicle can be compromised in the same way, and it did not give the tester access to the vehicle’s brakes or cameras. Those systems were reported to be well protected.

What it did show was a broader regulatory problem: cars are becoming computers on wheels, while Australia is still developing national cybersecurity standards specifically for road vehicles.

What the test actually found

According to Four Corners, the test vehicle exposed a remote-access point that Hreszczuk said was not protected by a password.

From there, the tester was able to demonstrate control over functions including the vehicle’s locks, infotainment system, audio, lights, windscreen wipers and washers.

The ABC also reported that the test allowed access to location information and the vehicle’s microphone.

Those capabilities matter because they move the risk beyond ordinary data theft. A connected car may contain information about where a person travels, when the vehicle is used and what is said inside it. Some remote functions can also affect the driver’s immediate environment.

In the demonstration, headlights could be switched off. The testing was carried out under controlled conditions and at low speed, and it should not be portrayed as an uncontrolled road attack.

Just as importantly, Hreszczuk was not able to access the brakes or the vehicle’s cameras. That limits what can reasonably be concluded from the test.

The result is not “a hacker can take over every BYD”. It is that one tested Shark 6 exposed a set of remote capabilities that cybersecurity specialists and regulators will want to understand.

Why connected cars create a new security problem

Modern vehicles rely on software for navigation, entertainment, safety systems, driver assistance, charging, maintenance and communications with manufacturers or service providers.

Many models have embedded mobile connections and cloud-linked apps. Owners can use their phones to find the car, unlock it, check status information or activate functions remotely.

Those conveniences require trusted digital pathways into the vehicle. If authentication, software updates, access controls or cloud infrastructure are weak, the same pathway can become a target.

Cybersecurity specialists often describe the challenge as an expanding “attack surface”. Every internet-connected service, app, wireless interface and software component can create another potential entry point.

That does not mean connected vehicles are inherently unsafe. It means manufacturers need security controls that are designed for the life of the vehicle, including secure updates, strong authentication, vulnerability management and protection of sensitive data.

Australia does not yet have vehicle-specific minimum cyber standards

The Four Corners report highlighted that Australia currently lacks minimum national cybersecurity standards specifically applying to road vehicles.

The federal government has acknowledged that gap.

Under Horizon 2 of the 2023–2030 Australian Cyber Security Strategy, the Department of Home Affairs says it is working with the federal transport portfolio to introduce new national road vehicle cybersecurity standards consistent with Australia’s international vehicle-regulation obligations.

The work is scheduled within the 2026–2028 phase of the strategy.

Australia already has Australian Design Rules covering areas such as vehicle safety, anti-theft requirements and emissions. The emerging question is how software security should sit alongside those traditional engineering standards.

The issue is increasingly urgent because vehicle software can change after a car is sold. A hardware safety rule is relatively static; cybersecurity requires continuous attention as vulnerabilities are discovered and attackers develop new techniques.

Data is part of the risk

Connected vehicles can generate and transmit a large amount of information. Depending on the model and services enabled, that can include location, diagnostics, driving behaviour, app identifiers, contacts or audio-related functions.

For ordinary drivers, the privacy question is whether they know what is being collected, where it is stored, who can access it and how long it is retained.

For senior government officials, defence personnel and people handling sensitive commercial information, the concern is more acute.

Australian security agencies have previously warned ministers and public servants to be cautious about sensitive conversations in connected vehicles and about linking official devices to cars.

That advice is not limited to one manufacturer or one country. The underlying risk comes from any platform that combines microphones, connectivity, location data and remote administration.

BYD’s response matters

BYD has said data it collects from Australian customers is stored in Australia and that it has not provided, and would not provide, Australian customer data to Chinese authorities.

That response should be included because cybersecurity reporting can easily slide into broader geopolitical claims that are not established by a technical test.

The Four Corners exercise examined a vulnerability on a particular vehicle. It did not demonstrate that customer data had been transferred to a foreign government, nor did it establish a deliberate backdoor.

Technical weaknesses can arise from design mistakes, configuration errors, third-party components or poor security practices. Determining the cause requires evidence from the manufacturer and technical analysis.

Why one successful demonstration still matters

A single test cannot establish how common a vulnerability is across a fleet, but it can still be valuable.

Security researchers often discover systemic problems by examining individual devices. If a weakness is tied to a shared software version, cloud service or architecture, the manufacturer can then determine whether other vehicles need a patch.

The appropriate next step is coordinated investigation and remediation, not panic.

Manufacturers need a clear process for receiving vulnerability reports, validating them, developing fixes and delivering secure software updates. Regulators need enough authority and technical capability to ensure serious problems are addressed.

Owners also need reliable information about whether a vulnerability affects their model and whether action is required.

Cars are not covered in the same way as many smart-home devices

Australia has already introduced mandatory baseline cybersecurity requirements for many consumer smart devices manufactured from March 2026.

Those rules cover areas such as passwords and vulnerability reporting for many internet-connected products, but vehicles sit within a different regulatory environment.

That separation makes sense because cars have specialised safety systems and international vehicle standards. It also means the transition to dedicated road-vehicle cyber rules needs to happen deliberately.

A vehicle security regime has to consider not only privacy and hacking but also functional safety. A compromised light, steering, braking or driver-assistance system could have physical consequences that are different from a hacked household gadget.

What a useful national standard would need to achieve

Good regulation would not require government to dictate every line of vehicle software. It would set outcomes manufacturers must be able to demonstrate: secure access controls, protected communications, processes for reporting vulnerabilities, secure software updates and a response plan when serious flaws are found after sale.

Because vehicles remain on Australian roads for many years, regulators will also need to consider how long manufacturers must provide security support. A car can still be mechanically serviceable long after its original infotainment platform or mobile-network technology becomes outdated.

What drivers can reasonably do now

Individual owners cannot redesign a vehicle’s cybersecurity, but they can reduce avoidable risks.

Drivers should keep vehicle software and companion apps updated, use strong unique passwords where accounts support them, enable multi-factor authentication when available and be cautious about linking unnecessary devices or accounts.

People who handle sensitive information should follow employer or government security advice about conversations and device connections inside connected vehicles.

Owners should also pay attention to manufacturer notices or security updates rather than assuming a software issue can be solved only during mechanical servicing.

The regulatory question is bigger than BYD

The BYD Shark 6 makes a compelling case study because the remote functions were demonstrated clearly, but the policy issue covers the entire connected-vehicle market.

Australian consumers are buying cars from manufacturers based in China, Japan, Korea, Europe, the United States and elsewhere, and almost all major brands increasingly rely on cloud services and software.

A national standard should therefore be technology- and risk-based rather than designed around one brand.

The government’s planned road-vehicle cybersecurity standards will need to address how new vehicles are certified, how vulnerabilities are reported, how security updates are maintained over a vehicle’s lifespan and how Australia aligns with international regulations.

The Four Corners test should not be read as proof that every BYD is insecure. It is evidence that the risks of connected vehicles are no longer theoretical.

For Australian regulators, the challenge is to close the gap between rapidly evolving vehicle technology and rules that can keep drivers’ data and physical safety protected.

Related Posts

Editorial illustration of Anthony Albanese and Australia's climate policy debate

Albanese Calls for Climate Action as Advocates Challenge Australia’s Fossil-Fuel Record

Prime Minister Anthony Albanese has used a Climate Week appearance in New York to argue that governments can no longer avoid the economic and security costs of…

Editorial illustration of Brisbane app-only parking and accessibility concerns

Brisbane’s App-Only Parking Expansion Raises Accessibility Concerns

More than one in four paid parking spaces controlled by Brisbane City Council are now in app-only payment zones, prompting warnings that the shift away from physical…

Editorial illustration of Victoria's new data centre rules and community debate

Victoria Unveils Tighter Data-Centre Rules as Greens and Residents Push for Stronger Limits

Victoria has unveiled a new set of rules for data centres that will require future projects to source renewable energy, avoid drinking water and keep at least…

Editorial illustration of Australia and global AI guardrails policy debate

Albanese Joins Global Call for AI Guardrails as Trump Rejects Existential-Risk Framing

Australia has joined a group of 22 governments and institutions calling for stronger international guardrails around advanced artificial intelligence, placing Prime Minister Anthony Albanese on one side…

Editorial illustration of Victoria's IBAC reform and public interest immunity policy debate

Victorian Coalition Pushes PII Changes as Labor Moves to Expand IBAC Powers

Victoria’s fight over the powers of its anti-corruption watchdog has widened into a second argument about public interest immunity, as the Labor government moves to expand IBAC’s…

Editorial illustration of proposed NSW sexual assault evidence reforms

NSW Moves to Pre-Record Sexual Assault Evidence, but Advocates Say Reform Falls Short

New South Wales is preparing to change the way adult sexual assault complainants can give evidence, with the government proposing that recorded police interviews be used as…