Daddies - promo banner 3540 x 270
BYD Shark 6 in silver driving on a highway with blurred trees in the background.

Passwordless Chinese Car Hack Triggers Urgent Privacy Warning from Dealers

Ben McKimm
By Ben McKimm - News

Updated:

Readtime: 7 min

Every product is carefully selected by our editors and experts. If you buy from a link, we may earn a commission. Learn more. For more information on how we test products, click here.

  • Cybersecurity expert successfully hacked a moving BYD Shark 6.
  • The attack allowed remote control over headlights and cabin eavesdropping.
  • Xpeng insiders confirmed remote access to vehicle speed and steering angle.
  • Toyota and Hyundai are also under investigation for data privacy breaches.
  • The AADA is demanding urgent government intervention and industry transparency.

The biggest news in automotive this week was an ABC Four Corners investigation that exposed some of the concerning vulnerabilities in modern connected vehicles. In the video, below, a cybersecurity expert Dan Hreszczuk from Fortify Labs tapped directly into the CAN bus of a BYD Shark 6. Surprisingly, the entry point completely lacked password protection, allowing him to exploit the vehicle easily.

He spent two weeks hacking the plug-in hybrid ute, and demonstrated how he could remotely access the vehicle while it was being driven. While a reporter drove the ute at slow speeds on a country road, Hreszczuk was able to eavesdrop on cabin conversations, track the vehicle’s exact location, activate the wipers at maximum speed, lock the doors, blast the stereo, and even turn off its headlights on a country road.

“The access we took advantage of didn’t even have a password,” Hreszczuk stated.

Now, the peak body for new-car dealers wants action. While framing their public concerns around consumer transparency, the AADA is doing what it can to highlight vulnerabilities in Australian Consumer Law to ensure manufacturers, rather than dealers, remain solely liable for cybersecurity and product failures.

James Voortman, CEO of the Australian Automotive Dealer Association (AADA), stated that buyers are increasingly concerned about what information their vehicles collect and what safeguards exist: “Australian car buyers are asking legitimate questions about connected vehicle technologies and deserve clear answers,” said Mr Voortman, calling for greater collaboration between automakers, regulators, security agencies, and other stakeholders.

This is not an isolated incident. With Chinese cars now dominating the market, becoming the primary source of new vehicles in Australia, the rising popularity of Chinese cars and connected concepts like the GAC GOVE eVTOL brings intense scrutiny on data storage.

The Office of the Australian Information Commissioner (OAIC) is also investigating established automakers like Toyota and Hyundai over potential privacy breaches, proving this is an industry-wide vulnerability. Voortman noted the widespread nature of the issue. “Those questions are not limited to privacy and data collection. Customers also want to understand how these technologies operate, what protections are in place and how manufacturers and regulators are managing potential cybersecurity and safety risks,” he explained.

Byd cars loading off ship
All-electric BYD SEALION 7s being unloaded from the BYD ZHENGZHOU | Image: BYD

What the Industry is Saying About the Chinese Car Hack

The current Australian Privacy Act dates back to 1988, long before connected vehicles were envisioned. The AADA is pressing for immediate updates to these regulations to protect drivers.

“We need an urgent debate on this issue informed by the facts, so that as an industry we can provide car buyers with confidence. We also need a thorough understanding of what the future regulatory landscape looks like,” said Voortman. He stressed that both brands and lawmakers must step up. “Manufacturers are responsible for the technologies they introduce to the Australian market, while government agencies and regulators play a critical role in ensuring appropriate oversight and public confidence.”

Voortman concluded with a clear warning for the sector. “If Australians are expected to embrace increasingly connected vehicles, there must also be a coordinated effort to ensure clear and accessible information is available to both industry and the public.”

Byd dethrones toyota 0004 shark 6 dual cab 98
BYD Shark 6 | Image: BYD

Connectivity and Established Rivals

The debate around connected vehicles is heavily politicised. Shadow Minister for Defence James Paterson told Four Corners, “An electric vehicle made by a company headquartered in China is subject to the laws of China, and particularly the national security laws, which oblige them to assist China’s intelligence agencies.” He added, “So, a connected EV vehicle from China is the highest-risk product in the marketplace, and right now there’s nothing that says to that brand what data you can collect on Australians, how it can be stored, when it can be transmitted.”

However, this connectivity is not exclusive to newer market entrants. When questioned about Xpeng having access to his vehicle’s data in the program, Federal Energy Minister Chris Bowen noted, “Car manufacturers do have access to those sorts of information increasingly because every car now is basically connected.” He added, “Every new car, whether it’s an electric car, it’s made in China, Korea, the United States, they’re connected to the grid.”

This connectivity allows vehicles to receive over-the-air software updates that can affect battery management systems, steering, and lights.

Leapmotor b05
Leapmotor B05 is priced from $35,990 before on-roads | Image: Leapmotor

Meanwhile, Leapmotor uses Zhejiang Dahua cameras, which are banned from federal government buildings due to spyware fears, “It’s extraordinary to me that we’ve ripped out Dahua cameras from defence bases… but we’ve allowed that same technology in a connected vehicle to drive around those bases with all their cameras, all their sensors, all their data collection,” Senator Paterson, the former chair of the parliamentary committee on security and intelligence, told the ABC.

Xpeng insiders demonstrated they can remotely access speed, steering wheel angle, and passenger occupancy. Despite this, Xpeng confirmed it cannot remotely immobilise a customer’s vehicle in Australia.

“As a global EV company we, first of all, respect all the policies and rules in every country,” BYD Asia Pacific managing director Liu Xueliang told Australian media, including CarExpert, at the Melbourne motor show in April. “Before we entered the Australian market, we’ve been constantly communicating with different government divisions and to discuss about the compliance and the rules. In the car, you know, improve car approval, and all these things. So, to make sure that we respect the rules and compliance requirements here.”

Byd dethrones toyota 0000 byd denza zhengzhou 0084
BYD ZHENGZHOU | Image: BYD

BYD Asia Pacific managing director Liu Xueliang also confirmed the brand stores all local data on Telstra servers.

Until a recent update to its privacy policy, BYD’s fine print stated: “We may collect, hold, use and disclose your information for the following purposes: through surveillance activities undertaken to assist in the protection of people, property and company assets and resources (including ICT assets), information which may also be used to gather operational data, in connection with suspected illegal or improper activities and as part of disciplinary investigations.”

Responding to the current legislative gap, BYD told Four Corners, “At the moment the industry is applying elements of the Australian Privacy Act from 1988, together with other regulations that almost certainly did not foresee a scenario with connected vehicles almost 40 years on.”

Connected vehicles aren’t new. However, as they transform into sophisticated, internet-connected software platforms for the mainstream, the regulatory landscape is struggling to keep pace. The AADA’s push for transparency and manufacturer liability, alongside the glaring cybersecurity flaws exposed in popular models, underscores a critical turning point for the automotive industry.

It’s becoming clear that outdated legislation must be overhauled to protect drivers from the modern realities of remote surveillance and digital exploits.

If you want to read more about how the Australian Government is planning to update the Privacy Act to address connected vehicle issues, check out the latest statement from the office of the AADA below.

Ben McKimm

Journalist - Automotive & Tech

Ben McKimm

Ben lives in Sydney, Australia. He has a Bachelor's Degree (Media, Technology and the Law) from Macquarie University (2020). Outside of his studies, he has spent the last decade heavily involved in the automotive, technology and fashion world. Turning his ...

Comments

We love hearing from you. or to leave a comment.

No comments yet. Be the first to give your opinion!

Trending Stories