Skip to main content

Morning Overview

A security researcher tapped a BYD pickup’s microphone and live location in two weeks

Dan Hreszczuk needed two weeks to get inside a BYD Shark 6, and when he did, the plug-in hybrid ute let him follow its location live and switch on its cabin microphone from outside the vehicle. The Canberra security researcher was working with the ABC’s Four Corners program, and the entry point he used, in his words, “didn’t even have a password”.

The Four Corners report ran on September 21, and BYD Australia confirmed a week later that it had opened its own investigation with teams from its Chinese headquarters. The episode has become a test case in a country that, according to the ABC, has no minimum cybersecurity standard for imported cars.

Two weeks of picking apart a ute’s software

Hreszczuk is a co-founder and director of Fortify Labs, an Australian firm that works on the security of vehicles, connected devices and operational technology. His AUSCERT conference biography lists more than two decades in the field, including 15 years in the Australian Government sector and a stint as Technical Director of Computer Network Operations at the Australian Signals Directorate.

According to the ABC investigation by Angus Grigg, Jonathan Miller and Maddy King, he spent fourteen days unpicking the software programs that run the Shark 6’s different functions. The break-in point required no credentials at all. Hreszczuk told the program that he had no lock to pick because BYD had left the front door open, and that the job was easier than he had expected.

What he could reach, and what stayed locked

The demonstrations began with nuisance and sabotage functions. While a Four Corners journalist drove at about 30 kilometers an hour, Hreszczuk switched the headlights off, ran the wipers at top speed, sprayed the windscreen, locked the doors, blasted music through the speakers and put images on the infotainment screen. The car also repeated the warning “For safety, use low beam.” He described the vehicle as “a little bit scary” in how open it was to a hacker.

The surveillance tests were more personal. On a drive through Canberra past the War Memorial and along Anzac Parade, Hreszczuk remotely activated the microphone and recorded the journalist phoning his mother to talk through setting up internet banking, including parts of a password. Real-time location tracking was part of the same access. Autoblog’s summary of the investigation and Security Affairs both put it plainly: the researcher could track the car live and listen in on phone conversations inside it.

He also stitched together an audio clip of the journalist’s own “Hey Siri” command with questions of his own and played it through the car’s speakers while the phone sat unlocked in the cabin. Siri answered with a home address, a date of birth and contact details, and a banking password followed within minutes, according to the ABC.

Some systems held. Hreszczuk said he “wasn’t able to access more critical functions like brakes and cameras as these were well protected.” Autoblog adds a caution that the absence of a brake or steering compromise is not a guarantee that a more determined attacker could not reach one.

BYD’s answer and Australia’s missing rulebook

BYD’s public position, as the ABC reported it, is that the data it collects is stored in Australia and that the company has not and would not hand Australians’ data to Chinese authorities. After the broadcast, BYD Australia’s Chief Operating Officer Stephen Collins said the company takes vehicle security “very seriously for its customers and all road users,” according to carsales.com.au. The company said the joint investigation with headquarters teams would be disclosed publicly when it finishes, and that it has advocated for dedicated connected-vehicle legislation in Australia.

The regulatory backdrop is thin. The ABC reported that Australia currently imposes more cybersecurity requirements on connected household appliances than on cars, that consultations on automotive rules have begun, and that implementation remains years away. Home Affairs and Cyber Security Minister Tony Burke said the government prioritizes regulation where it will get “the fastest uplift.” Former National Cyber Security Adviser Alastair MacGibbon countered that “a cabinet minister should not be able to own a Chinese EV,” while Opposition defence spokesman James Paterson called a connected Chinese EV “the highest-risk product in the marketplace.” Those are political judgments layered on a technical demonstration, and the demonstration itself does not show any data actually going to China. Autoblog noted the same limit: the investigation did not prove data sharing with Beijing, but it did show that manufacturers hold “a startling amount of information” about the people who drive their cars.

The same pattern in a second car

The BYD was not the only vehicle in the investigation. According to Autoblog, an insider from Chinese maker Xpeng demonstrated real-time access to a G6’s GPS coordinates, speed, steering angle, seat settings and the number of people in the car. Xpeng told the program it cannot remotely immobilize vehicles and has never handed Australian customer data to Chinese authorities. Neither the Autoblog nor the ABC account confirms that either model faces a fix or recall.

The open question is what BYD’s investigation finds about the unprotected access point, and whether the company publishes those findings as promised. Until it does, the only public measurement of the flaw is Hreszczuk’s own: fourteen days of work, no password, and a microphone that answered to a stranger.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview