BYD Hack Exposes Passwordless Car Wiring Flaws

A researcher hacked a moving BYD vehicle using an unprotected data port, allowing remote control and eavesdropping.
Key points
- A researcher hacked a moving BYD Shark 6 via an unprotected CAN bus port.
- The AADA urges the government to update 1988 privacy laws for connected vehicles.
- The OAIC is investigating Toyota and Hyundai for potential data privacy breaches.
Security expert Dan Hreszczuk hacked a moving BYD Shark 6 in Australia. He accessed the vehicle’s internal wiring without a password.
The attack allowed remote control of lights and audio. Dealers are now urging the government to update privacy laws.
Researchers access moving car systems
Hreszczuk spent two weeks testing the plug-in hybrid ute. He connected to the CAN bus, a network that links car parts.
This connection lacked any password protection. While the car drove on a country road, he activated wipers and locked doors.
He also turned off headlights and listened to cabin conversations. The source, Man of Many, reported these specific capabilities.
Dealers demand regulatory transparency
The AADA CEO James Voortman called for clearer rules. He stated buyers need to know what data their cars collect.
The association wants manufacturers to remain liable for security failures. They argue current laws do not address connected vehicles.
Industry-wide privacy concerns grow
Chinese brands now dominate the Australian new-car market. This shift increases scrutiny on how vehicle data is stored.
The OAIC is investigating Toyota and Hyundai for privacy breaches. This shows the issue extends beyond one specific brand.






