BYD Shark 6 Hack Exposes a Much Bigger Car Risk

September 21, 2026
Featured image for “BYD Shark 6 Hack Exposes a Much Bigger Car Risk”

The reported BYD Shark 6 hack should make every driver question how well a connected car protects its controls, microphone and personal data.

A pickup sold on the other side of the Pacific has handed American drivers a useful warning. Australian broadcaster ABC’s Four Corners provided a BYD Shark 6 to Fortify Labs for a controlled cybersecurity test. According to a published account of that investigation, researcher Dan Hreszczuk remotely manipulated the truck’s lights, wipers, locks, audio and cabin microphone while a reporter drove nearby.

Hreszczuk’s most arresting statement was wonderfully uncomplicated: “The access we took advantage of didn’t even have a password.” The company said it regarded the allegations seriously and had begun an investigation. Until that work is complete, this should be described as a reported demonstration—not proof that criminals are roaming Australia unlocking every Shark 6.

You may also like this video about technology:

What the BYD Shark 6 hack reportedly reached

The functions matter more than the nationality of the badge. Changing music is an irritation. Disabling lights or windshield wipers could affect visibility. Operating locks reaches the physical cabin, while accessing a microphone turns a vehicle into a possible listening device. The researcher also reportedly used captured audio to imitate the journalist’s voice, connecting vehicle security to the expanding problem of synthetic-voice fraud.

The public account does not provide a reproducible technical chain. We do not yet know whether initial physical contact was required, whether the weakness lived in BYD software, a supplier component or a cloud service, or which versions were exposed. Limiting exploit details while a fix is developed can be responsible. It also means sweeping claims about every Shark 6 would run ahead of the evidence.

You may also enjoy: Trump’s Chinese Car Gamble: Jobs or Detroit Devastation?

BYD should now publish the useful parts: affected models and software versions, the conditions needed for access, whether owners face an immediate risk and how the company will close the route. A security investigation without an owner-facing conclusion is merely suspense with a service department attached.

BYD Shark 6 Truck
BYD Shark 6 Truck

Your connected car already holds more than you think

The Shark 6 has no official U.S. sales channel, but the architecture described here is familiar. American vehicles connect to cellular networks, phone apps, cloud accounts and remote services; platforms such as Android Automotive can run directly on vehicle hardware. Cars may store destinations, contacts and garage information while processing voice, location and driving data. The FTC’s connected-car guidance warns that geolocation and biometric information can be sensitive and that manufacturers remain responsible for lawful collection and use.

You may also enjoy: Hyundai Alexa Built-in: Useful or One Assistant Too Many?

This is the bargain drivers make every morning. Remote climate control is helpful; remote access is still remote access. A navigation system needs location to guide you, yet a detailed travel record can reveal where you live, work, worship or receive medical care. The answer is not to make cars stupid again. It is to demand that useful access be authenticated, limited and visible to the owner.

NHTSA’s vehicle cybersecurity material advocates a risk-based approach that is maintained and updated over time. That last phrase matters because cars commonly remain on the road for well over a decade. Buyers need to know how long the manufacturer will issue critical fixes, even after the infotainment hardware stops feeling fashionable.

You may also enjoy: Pleos Connect: What Hyundai’s New Software Gets Right

BYD Shark 6 Truck
BYD Shark 6 Truck

America already treats connected vehicles as a security issue

The U.S. government has moved beyond hypothetical concern. The Commerce Department’s connected-vehicle rule restricts certain vehicle-connectivity and automated-driving hardware and software with links to China or Russia. The policy reflects fears about data access, remote influence and dependence on foreign technology—not a finding that every Chinese-built car is malicious.

You may also enjoy: Can Hyundai’s Cloud Make EV Batteries Last 20% Longer?

That distinction keeps the discussion useful. Country of origin can shape regulatory risk, but engineering determines whether an attack succeeds. The standard should include strong authentication, separation between convenience systems and safety-critical controls, monitoring for unusual commands, rapid patching and a disclosure process that rewards researchers for reporting weaknesses before criminals exploit them.

The NIST Cybersecurity Framework organizes risk around identifying, protecting, detecting, responding and recovering. Applied to cars, that means preventing unauthorized entry is only the beginning. An automaker also needs to recognize suspicious behavior, contain it, communicate with owners and restore the vehicle safely.

You may also enjoy: AM Radio Mandate: What Drivers Would Actually Get

BYD Shark 6 Truck
BYD Shark 6 Truck

What owners should do while manufacturers investigate

There is no reported owner action for American Shark 6 drivers because the vehicle is not officially sold here. The broader cybersecurity hygiene is still worthwhile. Give the automaker account a unique password, turn on multifactor authentication when available, install legitimate vehicle and app updates, remove former users and review which permissions the companion app actually needs.

Before selling, trading or returning a connected vehicle, delete paired phones, navigation history, garage codes, digital keys and personal profiles. The factory-reset option is useful, but owners should confirm what it erases and separately remove the vehicle from manufacturer and third-party accounts.

The bigger shopping questions belong at the dealership. Ask how long security updates are promised, whether core controls work without a remote account, whether the microphone can be disabled and where vulnerability notices appear. Those answers are less exciting than a giant touchscreen, but they may matter far longer.

The reported BYD Shark 6 hack is not a verdict on every Chinese vehicle, and it is not permission to ignore vulnerabilities from Western automakers. It is a sharp reminder that a modern vehicle can be entered through software as surely as through a broken window. We inspect brakes, tires and crash structures because failure can harm people. Connected controls and cabin data now deserve the same seriousness.


Share: