Auto30
NewsTechnologyTuningReviewsUsefulRetro

No Password Required: Hackers Remotely Took Control of Chinese EV Functions While the Vehicle Was Moving

An Australian investigation uncovered serious cybersecurity flaws that could expose connected Chinese vehicles to remote access.

No Password Required: Hackers Remotely Took Control of Chinese EV Functions While the Vehicle Was Moving

An Australian investigation into the cybersecurity of Chinese-built electric and plug-in hybrid vehicles has uncovered vulnerabilities that could expose drivers to remote tracking, unauthorized access and privacy risks.

The investigation by ABC's Four Corners focused on vehicles from Xpeng and BYD, examining how much information could be accessed remotely and what functions could potentially be controlled by an attacker. The findings highlight the growing cybersecurity challenges surrounding connected vehicles packed with cameras, microphones, sensors and internet-connected systems.

Xpeng G6

One of the vehicles examined was the Xpeng G6. According to the investigation, company personnel were able to remotely access information from a vehicle used by ABC journalists. That information included the vehicle's location, speed, seat occupancy and even the position of the steering wheel. The investigation also raised questions about whether such data could be accessed by personnel operating from China.

The BYD Shark 6 produced an even more dramatic demonstration.

Cybersecurity expert Dan Hreszczuk spent two weeks examining the plug-in hybrid pickup and discovered an unsecured digital access point that did not require a password. From there, he was able to reach systems controlling several vehicle functions.

During a test drive, Hreszczuk remotely locked the doors, played audio through the vehicle's speakers and operated the windshield wipers. He was also able to switch the headlights on and off while the vehicle was moving. At one point, he turned the headlights off completely, leaving the driver in darkness.

The testing was conducted at low speed, and Hreszczuk said he could not access critical systems such as the brakes or steering. Still, the ability to manipulate vehicle functions remotely while someone was driving raised questions about how such vulnerabilities could be exploited by a malicious attacker.

The investigation also uncovered a potentially more serious privacy issue: remote access to the vehicle's microphone.

BYD Shark 6

During an ABC demonstration, Hreszczuk listened to a conversation taking place inside the BYD Shark 6. The test showed how audio captured through the vehicle could potentially be used to obtain sensitive information. In a separate demonstration, recorded voice commands were played through the car's speakers to interact with an iPhone's Siri assistant and retrieve personal information, including a date of birth, phone number and contacts.

The scenario demonstrated how connected vehicles can become more than transportation devices. With microphones, cameras, cellular connections and sophisticated infotainment systems, modern cars can also function as data-collection platforms.

The findings have drawn attention from Australian security officials. Australia's intelligence agency, ASIO, has advised ministers and public servants not to discuss sensitive matters inside Chinese-made vehicles or connect work devices to them. Australia does not currently have a blanket ban preventing government employees from owning Chinese-made EVs.

Similar concerns have emerged elsewhere. The U.K. military has restricted Chinese electric vehicles from parking near some sensitive facilities, citing surveillance concerns. The broader issue is not limited to one manufacturer or one country, as connected vehicles from many automakers collect large amounts of location, audio, driving and other data.

At the same time, there is no publicly established evidence showing that Chinese automakers are using these vulnerabilities at the direction of Chinese authorities to conduct surveillance. Xpeng told ABC that it has never provided Australian customer data to Chinese authorities and has never received a request for such information.

BYD has also disputed the broader implications of the investigation. The company said it was reviewing the claims and emphasized vehicle and customer safety, while BYD Australia has said it is conducting its own investigation into the reported vulnerability.

BYD Australia

The Australian investigation underscores a problem facing the entire connected-car industry: as more vehicle functions move into software, cybersecurity becomes increasingly intertwined with vehicle safety and consumer privacy.

For automakers, the challenge is no longer limited to protecting a vehicle's infotainment system. An unsecured digital entry point can potentially provide access to locks, lights, wipers, microphones, location data and other connected features. The BYD Shark 6 test shows why cybersecurity standards are becoming an increasingly important part of the modern automotive industry.


You may also be interested in the news:

A Lifelong Ford Family Is Ready to Walk Away From F-150s for This $79K Toyota Tundra

A longtime Ford family is considering a $79,000 2026 Toyota Tundra 1794 i-FORCE MAX after questioning loaded F-150 prices.

Copart to Acquire ACV Auctions in $1.9 Billion Deal, Expanding Into Dealer-to-Dealer Car Auctions

Copart is acquiring ACV Auctions for about $1.9 billion, expanding its online auction business into dealer-to-dealer vehicle sales.

Best Sedans for Interior Space: The Roomiest Cars of 2026

These six sedans offer generous legroom and shoulder room, giving families a comfortable alternative to larger SUVs for long trips.

Best Cars for Teen Drivers: Affordable and Safe Picks

These affordable used and new vehicles combine strong safety ratings, reliability, and reasonable prices for young drivers and their families.

YouTube Has a New Problem: AI Is Creating Fake Mechanics Who Look Completely Real

Artificial intelligence is now being used to create convincing fake auto mechanics on YouTube, raising concerns about misleading advice.