Fortify Labs, a Canberra cybersecurity firm, switched off a BYD Shark 6’s headlights and started its windscreen wipers by tapping the pickup’s CAN bus, the internal network that links its electronic control units. Co-founder Dan Hreszczuk demonstrated the takeover on a road near Canberra, in a test that Australia’s ABC Four Corners program covered and that BYD later confirmed in its own investigation.
The demonstration came with a condition that headlines tend to drop. Getting the first foothold on the truck took hands-on access, and BYD’s own findings say the lights-and-wipers control required direct physical access to the CAN bus.
The CAN bus tap on the Shark 6
Fortify Labs’ September 28 post explains the step in the team’s own words: they tapped the CAN bus line “to demonstrate what could happen if an ECU on that network was compromised,” and that is “how the lights were switched off and the windscreen wipers activated.” The firm describes the work as starting on July 17, 2026, the day after the vehicle had reported itself fully patched. The post gives no overall duration for the research.
According to carsales, the pickup spent two weeks with Hreszczuk, a figure that describes how long the vehicle was in his hands for the program. During the on-road demonstration he operated the wipers and headlights, locked the doors and played audio through the infotainment system. He told the outlet that it was easier than expected and that the access used did not even have a password.
Physical access first, remote control after
Both Fortify Labs and BYD are explicit that the attack did not begin over the air. Fortify’s post says physical access to the vehicle was required to install software on the head unit, the infotainment computer, and that from then on connectivity and control of the software worked remotely. BYD’s investigation, reported by CarExpert, concluded that initial access required physical access and could not be performed remotely.
The technique rested on the Android Debug Bridge, a developer tool for Android devices. BYD said the researcher exploited a software defect to enable it and then installed an untrusted third-party application. Fortify Labs said the access it used was implied by its setup, given the firm was simulating a manufacturer’s access to a connected vehicle, and it withheld the initial-access method from the broadcast, citing the risk to victims of stalking and domestic abuse.
Some coverage went further than the sources do. SC Media’s brief described the pickup as remotely hacked without saying how the first foothold was obtained, and the carsales follow-up reported that non-critical functions such as the wipers could be hijacked while critical systems like the brakes stayed secure.
The two accounts differ in emphasis rather than substance. Fortify Labs frames the CAN bus tap as a demonstration of what a compromised control unit on that network could do, while BYD stresses that the demonstration needed someone physically inside the vehicle. Neither source says the lights and wipers were commandeered from outside the car with no prior contact, so what both agree happened is the tap and the physical access that preceded it.
BYD’s confirmed defect and the promised fix
The scale of the brand adds weight to the episode. The carsales follow-up notes that BYD now ranks second only to Toyota in Australian new-vehicle sales and that the security episode followed recent recalls, including one for spare wheels that could detach. The company told carsales that Australian customer data is stored on Australian servers, and that it would conduct an internal investigation with its Chinese headquarters and publish the findings.
That investigation is the document that produced the physical-access finding. It gives the episode two records that agree on the central mechanics: the researchers’ own account of a tap on the CAN bus, and the manufacturer’s account of a defect that let ADB be switched on through the infotainment system.
BYD’s own investigation confirmed a software defect, according to CarExpert, and the company said its corrective action would address the ADB-related issue and remove the unintended pathway. Autoblog reports that the fix removes the pathway that allowed ADB to be enabled through the infotainment user interface, and that an over-the-air update for the Shark 6 will be issued only after the updated software passes rigorous validation. No release date has been published in those reports.
Autoblog also notes that the backdoor exposed vehicle functions including the headlights and windscreen wipers, and that location data and phone calls made in the car were reachable. BYD Australia chief operating officer Stephen Collins said the company takes vehicle security very seriously and called for purpose-built connected vehicle legislation applying equally to every brand. Fortify Labs asked for something different: a cybersecurity star rating so consumers can judge how secure a connected car is.
The unresolved piece is timing. BYD has described the fix and its validation step, but the reports on the fix carry no date for when Shark 6 owners will receive it.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The FBI warns a new phishing trick can hijack your account without your password
- The NSA says three phone features should be off whenever you aren’t using them
- Hawaii’s magnitude 6.0 Kona earthquake is now a federal major disaster
- Comcast is shutting down its email service, and Xfinity customers must act to keep it