Australian automotive news & analysis

Saturday, 26 September 2026
Industry ↗

BYD Australia investigates Shark 6 security allegations, calls for connected-car rules

The company is reviewing allegations raised by an ABC security demonstration, while industry groups press for clearer rules on vehicle data and software security.

Automatically researched, written and checked using AI. Verify details against the sources.

Share
AI editorial illustration of a BYD Shark 6
AI-generated illustration of the BYD Shark 6, based on the manufacturer reference. It does not depict the reported incident. DriveAgent · AI illustration · AI-generated editorial illustrationBYD Shark 6 — manufacturer reference

BYD responds to Shark 6 security report

BYD Australia says it is investigating allegations that a cybersecurity researcher gained unauthorised remote access to functions of a BYD Shark 6 plug-in hybrid ute. The response follows an ABC Four Corners investigation into connected-vehicle security. The ABC also identified cyber safety flaws found by the investigation in its AM program. 14

In a statement to CarExpert, BYD Australia chief operating officer Stephen Collins said the company was reviewing the program’s allegations concerning what he described as certain non-critical vehicle control functions. He said BYD would respond in detail after its investigation and would make no further comment until then. That description is BYD’s characterisation of the alleged access, not a published finding from its investigation. 1

What the demonstration involved

CarExpert reported that a researcher demonstrated remote access to the Shark 6 while it was being driven, including the ability to listen to phone calls, track its location and switch off its headlights. The report said the researcher had spent two weeks working on the ute before the demonstration; he did not gain access spontaneously. AutoTalk, citing the ABC, identified the researcher as Dan Hreszczuk of Canberra-based Fortify Labs and reported that he found an access point without a password. 13

AutoTalk described further functions demonstrated while a reporter drove: locking the doors, displaying music and images through the infotainment system, operating the wipers and washers at speed, and accessing the cabin microphone. Those accounts describe a demonstration involving a vehicle the researcher had worked on. They do not establish that another Shark 6 could be accessed remotely without comparable preparation. 3

Vehicle data and BYD’s privacy policy

Collins told CarExpert that personal data generated by BYD vehicles in Australia is stored on Australian servers. In an earlier account of comments from BYD representatives, CarExpert reported the company’s statement that its data was stored in Australia on Telstra servers. These are company statements about data storage, distinct from the researcher’s demonstration of access to the ute’s functions. 12

CarExpert reported that BYD replaced privacy-policy wording that had referred to surveillance activities with a more limited policy covering customer data transmitted through its website, rather than through vehicles. AutoTalk reported the ABC’s account that the revised Australian policy removed references to China and surveillance. AutoTalk also reported that BYD told Four Corners it had not handed, and would not hand, Australians’ data to Chinese authorities, and had responded to preliminary inquiries from the Office of the Australian Information Commissioner. 13

Calls for rules covering connected vehicles

BYD Australia says it wants purpose-built, enforceable connected-vehicle legislation applying equally to every brand in the Australian market, and would comply with such a framework. CarExpert separately reported that the Australian Government had released draft legislation to update the Privacy Act and was seeking feedback on proposed measures addressing privacy issues arising from connected vehicles. BYD’s call is for a regulatory standard, not an announcement that such a standard has been enacted. 12

The Australian Automotive Aftermarket Association is seeking different, more specific protections in the privacy reforms. According to AutoTalk, its submission calls for affirmative consent before vehicle-generated personal information is collected, better protection for passengers and secondary drivers, and fuller rights to delete vehicle data. It also wants manufacturers responsible for secure software updates and timely vulnerability fixes throughout a vehicle’s working life, regardless of a vehicle’s origin or powertrain. 3

The aftermarket association also wants owners to be able to authorise an independent repairer or data intermediary to access diagnostic information for a limited purpose and withdraw that access. It has proposed resets to clear previous owners’ accounts and data when vehicles change hands. These are the association’s proposals, rather than requirements already imposed on manufacturers or repairers. 3

Wider scrutiny of connected-car data

The Australian Automotive Dealer Association has separately called for car companies and the government to work together on clearer information about connected vehicles. Its chief executive, James Voortman, said dealers were receiving questions about what vehicles collect, what can be accessed remotely and what safeguards are in place. CarExpert reported his comments before BYD’s announcement that it was investigating the Shark 6 allegations. 2

The privacy questions extend beyond BYD. CarExpert and AutoTalk have reported investigations concerning Toyota and Hyundai and their handling of connected-vehicle personal data. Those inquiries concern data practices; they should not be conflated with the Shark 6 security demonstration or treated as findings of wrongdoing. 23

Share

AI evidence finder

Ask about this article

Ask a question to find relevant published passages and source links. AI selects evidence; the passages remain exactly as published.

Your question is processed by AI. Please leave out personal details.

0/400

Behind this report

Sources & context

How these labels work ↗

Cited source mix

4 cited pages across 4 websites

  • News publisher 1
  • Role not assessed 3
Website breakdown

3 cited pages with an undocumented publisher role. Websites may share ownership or repeat the same reporting.

Saved research extracts

4 / 4 cited pages with saved extracts

0 shortened at our text limit · 0 without a saved-extract record

Extracts retrieved 26 Sep 2026.

Extracts can omit page content. These counts do not verify claims or measure independent reporting. Political leaning and reliability are not rated.

  1. BYD investigating hacking concerns as it calls for new connected vehicle legislation in Australia

    carexpert.com.au · 25 Sep 2026 · accessed 26 Sep 2026

    News publisherSource extract saved
    Why these labels?BYD investigating hacking concerns as it calls for new connected vehicle legislation in Australia

    Who produced it

    Publishes automotive news and reviews and operates a car-buying service connecting buyers with dealers. Identity reference ↗Identity checked 22 Sep 2026.

    How this report uses it

    Cited in 6 paragraphs: BYD responds to Shark 6 security report; What the demonstration involved; Vehicle data and BYD’s privacy policy; Calls for rules covering connected vehicles.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 26 Sep 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  2. 'Urgent' calls for greater transparency on data collection following report on Chinese car hacking

    perthnow.com.au · 23 Sep 2026 · accessed 26 Sep 2026

    Role not assessedSource extract saved
    Why these labels?'Urgent' calls for greater transparency on data collection following report on Chinese car hacking

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 4 paragraphs: Vehicle data and BYD’s privacy policy; Calls for rules covering connected vehicles; Wider scrutiny of connected-car data.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 26 Sep 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  3. AAAA pushes connected vehicle privacy rules after Four ...

    autotalk.com.au · 22 Sep 2026 · accessed 26 Sep 2026

    Role not assessedSource extract saved
    Why these labels?AAAA pushes connected vehicle privacy rules after Four ...

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 6 paragraphs: What the demonstration involved; Vehicle data and BYD’s privacy policy; Calls for rules covering connected vehicles; Wider scrutiny of connected-car data.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 26 Sep 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  4. Chinese-made EV vulnerable to hacking - ABC listen

    abc.net.au · 20 Sep 2026 · accessed 26 Sep 2026

    Role not assessedSource extract saved
    Why these labels?Chinese-made EV vulnerable to hacking - ABC listen

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 1 paragraph: BYD responds to Shark 6 security report.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 26 Sep 2026. The retained extract did not reach our text limit. Extraction can still omit page content.