CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

A passwordless port let a researcher command a moving BYD ute

An Australian television investigation found a BYD ute's systems reachable through an access point that asked for no password.

CarThreat Staff
Last updated: September 21, 2026 1:18 am
By
ctadmin
2 Min Read
SHARE

A cybersecurity researcher needed no password to reach the systems of a BYD Shark 6, the plug-in hybrid ute that Australia's trade minister owns. Dan Hreszczuk, co-founder of Canberra firm Fortify Labs, spent two weeks with the vehicle for an ABC Four Corners investigation.

What he found was an exposed access point his team called easier than expected. Hreszczuk locked a journalist inside, pushed audio through the speakers, threw images onto the infotainment display, ran the wipers at full speed and killed the headlights mid-corner. Brakes and cameras held. Almost everything else did not.

The sharper demonstration used the cabin microphone. Hreszczuk recorded a conversation from the moving car, then replayed the driver saying "Hey Siri" to feed a voice assistant commands. It surrendered a home address, a date of birth and enough detail to assemble a banking password.

BYD said the data it collects stays in Australia and that it has not handed Australian data to Chinese authorities.

Australia has no minimum cybersecurity standard for cars. Consultations with industry started recently and rules are years away. Home Affairs and Cyber Security Minister Tony Burke defended the sequencing, saying household connected devices were regulated first. Former national cyber security adviser Alastair MacGibbon wants stronger protections for connected car data, and opposition defence spokesman James Paterson called a Chinese connected EV the highest-risk product on the market.

"I didn't need to pick the lock as BYD left the front door open," Hreszczuk said.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityData PrivacyElectric Vehicles (EVs)Vehicle HackingVehicle SurveillanceVulnerabilities
SOURCES:ABC News (Australia)
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

AI Race

AI tool chains low-severity bugs into critical automotive attack paths

By
ctadmin
July 27, 2026
Cybersecurity

License plate camera firm locks down vehicle data after abuse reports

By
ctadmin
August 17, 2026
Cybersecurity

Tesla FSD Safety Data Under Fire for Misleading European Regulators

By
ctadmin
June 17, 2026
CybersecurityResearch & Innovation

EvilValet attack uses AOSP test keys to compromise Honda infotainment

By
ctadmin
July 21, 2026
Cybersecurity

Analog fingerprints catch counterfeit ECUs that pass crypto checks

By
ctadmin
August 12, 2026
Cybersecurity

Hardcoded keys in a truck logging app expose fleet telemetry

By
ctadmin
September 18, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?