ConnectedChinese EV's Lax Security Puts Australian Drivers at Risk, Cybersecurity Test Reveals

Chinese EV’s Lax Security Puts Australian Drivers at Risk, Cybersecurity Test Reveals

A hacker remotely disabled headlights, accessed microphones, and extracted banking passwords from a popular BYD vehicle, exposing critical gaps in Australia’s car cybersecurity standards.


ABC News Australia has reported a cybersecurity expert easily compromised a BYD Shark 6 hybrid ute, demonstrating vulnerabilities that could allow remote surveillance and sabotage of increasingly common Chinese electric vehicles on Australian roads.

Dan Hreszczuk, a cybersecurity specialist, spent two weeks analyzing the Shark’s defenses and was startled by what he found. The vehicle’s critical systems lacked even basic password protection, granting him straightforward access to its software controls.

During a test drive outside Canberra, Hreszczuk remotely toggled the vehicle’s headlights, wipers, doors, and infotainment system while the car was in motionโ€”a combination he described as “unsettling and highly distracting.” Though he could not access safety-critical functions like brakes, the demonstration underscored the potential for dangerous interference at highway speeds.

More alarming was the surveillance capability. Using the vehicle’s microphone and speaker system, Hreszczuk recorded a private phone conversation about internet banking, then crafted a deepfake audio prompt using Siri voice commands extracted from the earlier recording. When played through the car’s speakers, the fabricated command tricked Siri into revealing the driver’s home address, date of birth, and even contact information for a former prime ministerโ€”credentials sufficient to access the banking account discussed in the overheard call.

“I didn’t need to pick the lock as BYD left the front door open,” Hreszczuk said of the vulnerability.

Growing Market, Growing Concerns

The findings come as Chinese EV and plug-in hybrid sales surge in Australia. These vehicles now account for nearly one-third of new car sales, with over half from Chinese manufacturers. Modern connected vehicles collect vast amounts of data through cameras, microphones, and sensorsโ€”information that security experts warn poses heightened risks when controlled by companies subject to China’s national security laws, which can compel cooperation with state authorities.

Australia currently lacks minimum cybersecurity standards for vehicles, a gap that stands in stark contrast to regulations governing household appliances. The government has only recently begun consultations on introducing car cybersecurity rules, with implementation likely years away.

The security lapse carries particular sensitivity given that Trade Minister Don Farrell drives a BYD Shark 6, the same model tested. Australia’s domestic spy agency, ASIO, has previously warned government officials against conducting sensitive conversations in Chinese-made vehicles or connecting work devices to themโ€”yet no formal ban exists.

The UK military took a more restrictive approach, prohibiting Chinese EVs from parking within 3 kilometres of sensitive defense sites. China itself bars foreign EVs from military and political compounds, acknowledging their surveillance potential.

Government Response Lags Behind Experts

Alastair MacGibbon, Australia’s former national cyber security adviser, argued that cabinet ministers should be prohibited from owning Chinese EVs entirely, warning that the capability for data theft and surveillance is demonstrably present.

Home Affairs Minister Tony Burke defended the government’s measured approach, noting that regulations began with household devices where cybersecurity breaches have been most prevalent. However, opposition defense spokesman James Paterson emphasized that connected Chinese EVs represent “the highest-risk product in the marketplace” with no current restrictions on data collection, storage, or transmission.

BYD stated that it stores Australian customer data locally and has neither handed over nor would hand over such information to Chinese authorities. The company did not address the specific cybersecurity vulnerabilities demonstrated in the test.

The investigation highlights a critical blind spot in Australia’s regulatory framework: as connected vehicles become mainstream, oversight remains virtually absent, leaving millions of drivers potentially exposed to remote interference and extensive surveillance.

Press Roomhttps://autotech.news/
AutoTech News features articles from the intersection of the automotive and the technology industry focusing on the four decisive mega-trends: automated/self-driving, electrification, connectivity and sharing.