Australian automotive news & analysis

Friday, 2 October 2026
EVs & hybrids ↗

BYD confirms Shark 6 software defect and prepares over-the-air fix after Four Corners hacking demonstration

BYD Australia says its forensic investigation reproduced the vulnerability used by a cybersecurity researcher in an ABC Four Corners demonstration, and plans an OTA software update to close the unintended access path.

Automatically researched, written and checked using AI. Verify details against the sources.

Share
AI editorial illustration of the BYD Shark 6
AI-generated illustration of the BYD Shark 6, based on the manufacturer reference for the vehicle's appearance. It does not depict the reported incident. DriveAgent · AI illustration · AI-generated editorial illustrationBYD Shark 6 — manufacturer reference

The demonstration that started the investigation

The ABC's Four Corners program, aired on 21 September 2026, featured Canberra-based cybersecurity researcher Dan Hreszczuk of Fortify Labs demonstrating access to a range of functions on a BYD Shark 6 plug-in hybrid ute, including locking the doors, operating the wipers and washers, playing content through the infotainment system and accessing the cabin microphone. AutoTalk Australia reported the demonstration also covered the vehicle's location and microphone. Hreszczuk had spent roughly two weeks with the vehicle before the demonstration, and the ABC reported he found a digital access point that was not password protected, although he was unable to reach more safety-critical functions such as the brakes. 13

CarExpert's reporting, republished by 7NEWS, noted the demonstration was carried out after the researcher had spent two weeks working on the plug-in hybrid ute, rather than being achieved spontaneously from the roadside. Fortify Labs issued its own statement saying its objective was to simulate the remote access a car manufacturer has to a connected vehicle, that the investigation was never about gaining initial access, and that manufacturers can reach into vehicles remotely to run commands and deliver over-the-air updates. 4

BYD Australia's chief operating officer Stephen Collins told NRMA's Open Road the company saw the report at the same time as the public and would look at it holistically before stating its position. At that stage, Collins said it was probably premature to say whether the issues could be fixed with a software update, and BYD's director of public relations Paul Ellis said the company was asking the ABC whether additional hardware had been connected to the vehicle during the remote demonstration. 3

BYD's forensic findings on the infotainment access path

BYD Australia subsequently confirmed the key software finding. The company said its forensic investigation, involving technical teams in Australia and China, focused on two areas: access to the infotainment system through Android Debug Bridge (ADB), and physical access to the Controller Area Network (CAN) bus. AutoTalk Australia reported that BYD's engineers were able to reproduce the software defect the researcher used to enable ADB, which is disabled by default, and to then install an untrusted third-party application. 7NEWS, which credited CarExpert's reporting, quoted BYD's statement saying the researcher exploited a software defect to enable ADB and subsequently install the untrusted application. 14

However, BYD said access to sensitive information or functions such as the vehicle's location or microphone still required permission to be manually approved through the infotainment interface. "The requested permissions could only be granted after the user manually approved the request through the infotainment interface," the company stated, as quoted by AutoTalk Australia. Fortify Labs separately commended BYD for well-implemented security in parts of the vehicle, according to the 7NEWS article. 14

CAN bus access and the regulatory context

On the second area of its investigation, BYD's technical analysis confirmed the demonstrated control of the Shark 6's headlights and windscreen wipers required direct physical access to the vehicle's internal CAN bus by tapping into the vehicle wiring. "This method requires physical intervention on the target vehicle and is limited to the individual vehicle that has been physically accessed," BYD said in the statement quoted by both AutoTalk Australia and Torquecafe. 12

BYD said an external device attempting to reach the relevant vehicle network without tapping the wiring would need to use the On-Board Diagnostics interface, for which the company has implemented security measures including device authentication and physical isolation, with cybersecurity safeguards established in accordance with UN R155 requirements. The company has nevertheless launched a dedicated risk assessment of its CAN bus cybersecurity, examining the necessity and technical feasibility of additional measures relating to CAN message authenticity, integrity and freshness verification, according to its statement carried by Torquecafe. 12

For wider context, 7NEWS reported that draft Australian Design Rules ADR 115 and ADR 116, which are based on UN R155 and UN R156, are intended to better regulate vehicle security, but their introduction timing has not been finalised. Fortify Labs has called for a cybersecurity star rating for consumers to evaluate connected-car security, saying the risks apply to manufacturers from all regions, not only China. 4

The planned fix and the open questions

On the confirmed ADB-related issue, BYD said it has completed its root-cause investigation and commenced software remediation. The corrective action will remove the unintended pathway that allows ADB to be enabled through the infotainment system user interface, eliminating the access path identified during the investigation. AutoTalk Australia reported the updated software will be deployed to Shark 6 vehicles through a future over-the-air update, but only after rigorous validation testing, and no timeline for the update has been announced. BYD is also investigating whether the same update will be required for other BYD models sold in Australia. 124

BYD said the Shark 6 investigation will be used to strengthen its cybersecurity processes, including debug-interface management, application permission control, pre-release security testing, vulnerability management and cross-platform issue screening, according to its statement published by Torquecafe. The company said it remains committed to cybersecurity protection throughout the vehicle lifecycle through vulnerability analysis, security testing, risk assessment and software updates. 12

Data storage, privacy policy questions and industry pressure

The Four Corners report also raised questions about connected-vehicle data. Open Road reported that BYD Australia COO Stephen Collins said personal in-car data collected from Australian customers is stored locally on Telstra servers and governed by Australian law, and that PR director Paul Ellis said he had been told someone in China could not access Australian customer data. BYD took a separate question on notice about whether Australian data could be transferred overseas through third-party software or hardware connected to its vehicles, with Ellis saying information passed through Apple CarPlay and Android Auto remains within those ecosystems rather than with BYD. 3

CarExpert reported that BYD's Australian general privacy policy previously stated information could be collected through surveillance activities to assist in protecting people, property and company assets. The ABC reported the policy was replaced within hours of the company responding to its questions. Open Road added a note of caution, observing that archives of BYD's dedicated vehicle data and app privacy policies from July 2025 and July 2026 did not contain references to surveillance activities, and it was not clear which BYD policy document the reported wording came from. 36

BYD has publicly called for purpose-built connected vehicle legislation in Australia, describing it as a clear, enforceable standard applying equally to every brand in the market, and said it would comply fully with any such framework. Separately, the Australian Automotive Aftermarket Association has pushed for connected vehicles to be explicitly addressed in the Federal Government's privacy reforms, with chief executive Stuart Charity saying consumers should not have to surrender their privacy when buying a vehicle, and the association seeking manufacturer responsibility for software security across a vehicle's working life. 16

Ground News aggregated coverage noted that Australia currently lacks minimum cybersecurity standards for automobiles, that ASIO has warned government officials against sensitive conversations in cars, and that consultation on vehicle-specific rules has begun but enforcement remains years away. That wider context sits behind the BYD investigation, which the company has said will be made public once complete, with Collins telling Open Road the company intended to come out with its position on the issue. 53

Share

AI evidence finder

Ask about this article

Ask a question to find relevant published passages and source links. AI selects evidence; the passages remain exactly as published.

Your question is processed by AI. Please leave out personal details.

0/400

Behind this report

Sources & context

How these labels work ↗

Cited source mix

6 cited pages across 6 websites

  • News publisher 1
  • Role not assessed 5
Website breakdown

5 cited pages with an undocumented publisher role. Websites may share ownership or repeat the same reporting.

Saved research extracts

6 / 6 cited pages with saved extracts

0 shortened at our text limit · 0 without a saved-extract record

Extracts retrieved 2 Oct 2026.

Extracts can omit page content. These counts do not verify claims or measure independent reporting. Political leaning and reliability are not rated.

  1. BYD responds to Shark 6 cybersecurity claims

    autotalk.com.au · 2 Oct 2026 · accessed 2 Oct 2026

    Role not assessedSource extract saved
    Why these labels?BYD responds to Shark 6 cybersecurity claims

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 8 paragraphs: The demonstration that started the investigation; BYD's forensic findings on the infotainment access path; CAN bus access and the regulatory context; The planned fix and the open questions; Data storage, privacy policy questions and industry pressure.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  2. BYD Shark 6 anti-hacking fix on the way

    torquecafe.com · 1 Oct 2026 · accessed 2 Oct 2026

    Role not assessedSource extract saved
    Why these labels?BYD Shark 6 anti-hacking fix on the way

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 4 paragraphs: CAN bus access and the regulatory context; The planned fix and the open questions.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  3. BYD investigates Shark 6 cybersecurity vulnerability as it defends Australian data safeguards

    mynrma.com.au · 28 Sep 2026 · accessed 2 Oct 2026

    Role not assessedSource extract saved
    Why these labels?BYD investigates Shark 6 cybersecurity vulnerability as it defends Australian data safeguards

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 5 paragraphs: The demonstration that started the investigation; Data storage, privacy policy questions and industry pressure.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  4. BYD's own Shark 6 hacking investigation reveals ‘software defect’

    7news.com.au · 1 Oct 2026 · accessed 2 Oct 2026

    Role not assessedSource extract saved
    Why these labels?BYD's own Shark 6 hacking investigation reveals ‘software defect’

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 5 paragraphs: The demonstration that started the investigation; BYD's forensic findings on the infotainment access path; CAN bus access and the regulatory context; The planned fix and the open questions.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  5. BYD Investigating Hacking Concerns as It Calls for New Connected ...

    ground.news · 1 Oct 2026 · accessed 2 Oct 2026

    Role not assessedSource extract saved
    Why these labels?BYD Investigating Hacking Concerns as It Calls for New Connected ...

    Who produced it

    We have not documented this publisher’s role. An unassigned label is not a negative rating.

    How this report uses it

    Cited in 1 paragraph: Data storage, privacy policy questions and industry pressure.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.

  6. BYD investigating hacking concerns as it calls for new connected vehicle legislation in Australia

    carexpert.com.au · 25 Sep 2026 · accessed 2 Oct 2026

    News publisherSource extract saved
    Why these labels?BYD investigating hacking concerns as it calls for new connected vehicle legislation in Australia

    Who produced it

    Publishes automotive news and reviews and operates a car-buying service connecting buyers with dealers. Identity reference ↗Identity checked 22 Sep 2026.

    How this report uses it

    Cited in 2 paragraphs: Data storage, privacy policy questions and industry pressure.

    This describes its use in our report. It does not establish the source’s editorial stance or independently corroborate every claim.

    Evidence record

    Text retrieved 2 Oct 2026. The retained extract did not reach our text limit. Extraction can still omit page content.