Washington | 17°C (clear sky)
The Unsettling Truth: Can Your Connected Car Be Controlled Remotely?

Cybersecurity Experts Remotely Access BYD Pickup, Unveiling Major Vulnerabilities

A shocking investigation by Fortify Labs and ABC Four Corners reveals how easily a BYD Shark 6 pickup could be remotely controlled and monitored, sparking urgent debates about vehicle cybersecurity and national security implications.

Imagine, for a moment, you're driving down a quiet country road, perhaps outside Canberra, minding your own business. Suddenly, your horn blares. Your windows slide down without you touching a thing. Then, the engine cuts out. Sound like a scene from a spy movie? Well, for owners of certain connected vehicles, this isn't just fiction – it's a very real, and frankly, unsettling possibility.

A recent, highly publicized investigation by Canberra-based cybersecurity firm Fortify Labs, working hand-in-hand with ABC's investigative program Four Corners, demonstrated just how vulnerable our increasingly 'smart' cars can be. Dan Hreszczuk, co-founder of Fortify Labs and a seasoned cybersecurity expert, managed to remotely access a popular BYD Shark 6 electric pickup truck, revealing a significant security loophole that raises some serious eyebrows.

Hreszczuk spent a mere two weeks probing the BYD Shark 6's systems, and what he found was alarming. During a live demonstration for ABC reporter Angus Grigg, Hreszczuk, from a completely separate location, was able to manipulate several functions of the moving vehicle. He could remotely lock and unlock doors, sound the horn, control the windows, and even, most disconcertingly, cut the engine. Critically, he stressed that he "didn't need to pick the lock as BYD left the front door open," implying that no physical access to the vehicle was required for this initial breach.

But the capabilities didn't stop at mere mischief. The researchers also demonstrated the ability to track the vehicle's exact location in real-time. Even more chillingly, they could remotely activate and listen through the car's built-in microphone, essentially turning the vehicle into a sophisticated eavesdropping device. While essential safety features like braking and steering remained inaccessible – thankfully! – the investigation warned that this is "not a guarantee that a more determined hacker couldn't bring that result" with further effort. It really makes you wonder, doesn't it?

BYD, the Chinese electric vehicle giant, has, predictably, pushed back against some of these claims. They assert that exploiting such a security vulnerability would actually require physical access to the vehicle. However, Hreszczuk's detailed account and the ABC Four Corners demonstration directly contradict this, suggesting the entry point was far less guarded than BYD suggests. This discrepancy is a significant point of contention and certainly warrants deeper scrutiny.

Beyond the immediate security risks, this investigation casts a long shadow over broader concerns, especially concerning data privacy and national security. Chinese EVs, like the BYD Shark 6, are rapidly gaining traction in Australia, now accounting for a staggering 40% of new car sales. While BYD claims that all Australian customer data is stored locally and never shared with the Chinese government, experts like former cybersecurity adviser Alastair MacGibbon point to China's national intelligence laws. These laws could, theoretically, compel any Chinese manufacturer to assist state authorities with data or access, regardless of where that data is stored. For high-profile individuals, or anyone, really, who values their privacy, this is a major red flag.

Trade Minister Don Farrell acknowledged these national security concerns, highlighting the government's ongoing engagement with intelligence agencies to assess the risks posed by foreign-made EVs. It seems we're in a strange position where, as the investigation noted, Australia currently has more stringent cybersecurity standards for smart home appliances than for our connected cars, with mandatory vehicle standards still years away. That's a pretty glaring oversight when you think about it.

Ultimately, the Fortify Labs and ABC Four Corners investigation serves as a stark reminder: as our cars become more integrated with technology, they also become potential targets. The ease with which the BYD Shark 6 was remotely accessed underscores the urgent need for robust, internationally recognized cybersecurity standards in the automotive industry. Our privacy, and perhaps even our safety, might just depend on it.

Comments 0
Please login to post a comment. Login
No approved comments yet.

Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.