No Password Required: Hackers Remotely Took Control of Chinese EV Functions While the Vehicle Was Moving

An Australian investigation uncovered serious cybersecurity flaws that could expose connected Chinese vehicles to remote access.

September 28, 2026 at 11:59 AM / Technology

An Australian investigation into the cybersecurity of Chinese-built electric and plug-in hybrid vehicles has uncovered vulnerabilities that could expose drivers to remote tracking, unauthorized access and privacy risks.

The investigation by ABC's Four Corners focused on vehicles from Xpeng and BYD, examining how much information could be accessed remotely and what functions could potentially be controlled by an attacker. The findings highlight the growing cybersecurity challenges surrounding connected vehicles packed with cameras, microphones, sensors and internet-connected systems.

One of the vehicles examined was the Xpeng G6. According to the investigation, company personnel were able to remotely access information from a vehicle used by ABC journalists. That information included the vehicle's location, speed, seat occupancy and even the position of the steering wheel. The investigation also raised questions about whether such data could be accessed by personnel operating from China.

The BYD Shark 6 produced an even more dramatic demonstration.

Cybersecurity expert Dan Hreszczuk spent two weeks examining the plug-in hybrid pickup and discovered an unsecured digital access point that did not require a password. From there, he was able to reach systems controlling several vehicle functions.

During a test drive, Hreszczuk remotely locked the doors, played audio through the vehicle's speakers and operated the windshield wipers. He was also able to switch the headlights on and off while the vehicle was moving. At one point, he turned the headlights off completely, leaving the driver in darkness.

The testing was conducted at low speed, and Hreszczuk said he could not access critical systems such as the brakes or steering. Still, the ability to manipulate vehicle functions remotely while someone was driving raised questions about how such vulnerabilities could be exploited by a malicious attacker.

The investigation also uncovered a potentially more serious privacy issue: remote access to the vehicle's microphone.

During an ABC demonstration, Hreszczuk listened to a conversation taking place inside the BYD Shark 6. The test showed how audio captured through the vehicle could potentially be used to obtain sensitive information. In a separate demonstration, recorded voice commands were played through the car's speakers to interact with an iPhone's Siri assistant and retrieve personal information, including a date of birth, phone number and contacts.

The scenario demonstrated how connected vehicles can become more than transportation devices. With microphones, cameras, cellular connections and sophisticated infotainment systems, modern cars can also function as data-collection platforms.

The findings have drawn attention from Australian security officials. Australia's intelligence agency, ASIO, has advised ministers and public servants not to discuss sensitive matters inside Chinese-made vehicles or connect work devices to them. Australia does not currently have a blanket ban preventing government employees from owning Chinese-made EVs.

Similar concerns have emerged elsewhere. The U.K. military has restricted Chinese electric vehicles from parking near some sensitive facilities, citing surveillance concerns. The broader issue is not limited to one manufacturer or one country, as connected vehicles from many automakers collect large amounts of location, audio, driving and other data.

At the same time, there is no publicly established evidence showing that Chinese automakers are using these vulnerabilities at the direction of Chinese authorities to conduct surveillance. Xpeng told ABC that it has never provided Australian customer data to Chinese authorities and has never received a request for such information.

BYD has also disputed the broader implications of the investigation. The company said it was reviewing the claims and emphasized vehicle and customer safety, while BYD Australia has said it is conducting its own investigation into the reported vulnerability.

The Australian investigation underscores a problem facing the entire connected-car industry: as more vehicle functions move into software, cybersecurity becomes increasingly intertwined with vehicle safety and consumer privacy.

For automakers, the challenge is no longer limited to protecting a vehicle's infotainment system. An unsecured digital entry point can potentially provide access to locks, lights, wipers, microphones, location data and other connected features. The BYD Shark 6 test shows why cybersecurity standards are becoming an increasingly important part of the modern automotive industry.

You may also be interested in the news:

Late Owner’s 1969 Ford Mustang Boss 429 Sat Hidden in a Wisconsin Garage for Years
A Ford Maverick Towed a 3,200-Pound Camper 6,500 Miles—Then Wyoming Winds Changed Everything
He Bought Seven 2007 Chryslers in the Exact Same Color — Then People Started Asking Why
Your Old Car Can Feel New Again With These 7 Upgrades That Actually Make a Difference
Expert Cautions: Spraying This on These 10 Car Parts Could Make the Problem Worse
These 7 Dashboard Warning Lights Could Leave You Stranded—Here’s What They Really Mean
Chevrolet Express Unicell Conversion Combines Tiny-Home Comfort With a 23-Foot Mobile Layout
Americans Are Turning Away From EVs — And Hybrids Are Taking Their Place