CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Policy & Compliance

India’s AIS-156 update makes wireless BMS hacking tests compulsory

India's fifth AIS-156 amendment forces labs to probe Bluetooth-enabled battery packs on L-category EVs after remote e-rickshaw shutdowns.

CarThreat Staff
Last updated: September 9, 2026 8:31 pm
By
ctadmin
2 Min Read
SHARE

A low-speed electric vehicle battery that answers to Bluetooth is a switch an attacker can throw, and India is updating its L-category rulebook to test against exactly that risk. Amendment No. 5 to the AIS-156-2020 standard adds Clause 6.12 for BMS units carrying Bluetooth Classic, Bluetooth Low Energy or other wireless interfaces, with one pass/fail question: can an unapproved phone or device connect and reach safety-critical functions?

Labs must attempt to read live voltage, current, temperature and state of charge values, flip contactors and relays, switch charging and discharging on or off, run cell balancing, reset faults, rewrite configuration and protection thresholds, and push firmware over the wireless link. Test rigs pair Android and iOS handsets with BLE GATT browsers, Bluetooth Classic terminals and protocol analyzers, working on a full vehicle or a bench setup with the pack live. The battery is examined exactly as a customer receives it, with no pre-test security hardening, at a state of charge between 40 and 60 percent.

The mandate grew out of July incidents in which moving e-rickshaws lost power while strangers operated free BMS phone apps, reports that reached CERT-In and prompted action. Inspections blamed low-cost packs that carried default credentials or none at all. Officials removed the misused applications, and the Ministry of Heavy Industries briefed SIAM, ACMA and testing agencies on Bluetooth BMS weaknesses. Pack makers must now hand over the full wireless surface: chipset, Bluetooth profiles, exposed services and characteristics, intended pairing method and every command the interface accepts.

India already phases AIS-189 cyber rules aligned with UN R155 for connected vehicles by 2029. The AIS-156 amendment delivers the same assurance earlier to e-rickshaws and low-speed two- and three-wheelers, the segment where the July incidents proved a wireless BMS can be a remote safety risk.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Battery Management Systems (BMS)Bluetooth SecurityConnected VehiclesCybersecurityElectric Vehicles (EVs)RegulationsVulnerabilities
SOURCES:Autocar Professional
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Rollback bug lets attackers clone key fobs in rolling code systems

By
ctadmin
August 6, 2026
cel-shaded illustration of a small hatchback in an empty car-share bay with cyan data ribbons streaming away across the lot
Cybersecurity

Car-share service ties member record theft to one employee

By
ctadmin
September 16, 2026
Policy & Compliance

Gipuzkoa’s Automotive Sector Gears Up for Cyber Resilience Act Compliance

By
ctadmin
June 19, 2026
Cybersecurity

Used car head units leak keys that hijack their last owner’s phone

By
ctadmin
August 10, 2026
Cybersecurity

EV charger firmware compilers escape independent security testing

By
ctadmin
August 6, 2026
Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

By
ctadmin
September 21, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?