
Key points:
BYD Australia has launched an internal investigation into security vulnerabilities identified in its Shark 6 plug-in hybrid ute, while moving to clarify how Australian customer and vehicle data is stored and accessed.
The investigation follows an ABC Four Corners report in which cybersecurity expert Dan Hreszczuk demonstrated remote access to a BYD Shark 6, controlling functions including its headlights, wipers, door locks, speakers and infotainment system.
Hreszczuk had physical access to the vehicle for around two weeks before the demonstration and reportedly tapped into its CAN bus, a standard communications network that allows a machine or vehicle's electronic control units to communicate.
The ABC reported that Hreszczuk then found a digital access point that was not password protected, although he was unable to access more safety-critical functions such as the vehicle’s brakes. They said Hreszczuk was also able to track the vehicle's location and access its microphone, allowing him to listen to a phone conversation taking place inside the vehicle.
Speaking to Open Road, BYD Australia chief operating officer Stephen Collins said the company was still establishing exactly how the vehicle had been accessed and whether the issue extended beyond the vehicle tested.
“We’re only a few days since it aired. We saw it at the same time everyone else saw it,” Collins said.
“We’re going to look at it holistically, and once we’ve done that, then we’ll come out with statements as to what we’ve found and what our position is.”
Collins said it was too early to say whether any vulnerability identified by the investigation could be rectified with a software update.
“Quite possibly, but it’s probably premature to say,” he said.
“Certainly over-the-air updates are an important feature of our vehicles and of our technology.”
Also read: BYD targets 200 Australian service sites and shorter wait times
BYD Australia director of public relations Paul Ellis said the company was also seeking more information about the circumstances surrounding the demonstration.
“You can’t just stand on the side of the road and hack into a BYD that drives past,” Ellis said.
“The software that’s used doesn’t work like that.”
Ellis said BYD had questions for the ABC about whether additional hardware had been connected to the Shark 6 before the remote demonstration.
“We’re asking questions of the ABC. Was there a connected device in the vehicle when the remote tampering was done as well?” he said.
“We need a bit of their cooperation as well, because we have an absolute obligation, as Steve has pointed out. We’ve got to do this absolutely right.”
That point does not remove the cybersecurity questions raised by the demonstration, but determining how initial access was achieved, whether physical access or additional hardware was required and which software versions may be affected will be important in establishing the extent of any vulnerability.
BYD has not given a timeframe for completing the investigation, although Collins said the company intended to make its position public.
“We’ll do it as quickly but as thoroughly as we can,” he said.
“I’m not sure we’ll come out with a full report, but we’ll certainly come out with our position on that issue.”
An official statement regarding the Four Corners story was issued by BYD on Friday morning, stating: “BYD Australia takes vehicle security very seriously for its customers and all road users.
"We are taking full and immediate action in reviewing alleged claims made in the Four Corners program relating to unauthorised remote access of certain non-critical vehicle control functions. We will respond in detail once we have completed our investigation. The safety of our customers and all road users is our absolute priority.”
Regarding in-vehicle data, the EV maker stated: “BYD Australia notes concerns raised about connected vehicle data security in Australia. Personal data generated by BYD vehicles in Australia is stored on Australian servers.
"We have publicly called for purpose-built connected vehicle legislation in Australia – a clear, enforceable standard applying equally to every brand in this market. We welcome that scrutiny and would comply fully with any such framework.”
— BYD chief operating officer, Stephen Collins
The investigation comes amid broader scrutiny of the amount of data collected by connected vehicles, who can access it and where that information is stored.
Collins said personal in-car data collected from Australian BYD customers was stored locally on Telstra servers and governed by Australian law.
“That data is held locally, and where it’s personal in-car data, it’s held locally. It’s governed by Australian law,” he said.
“There was some discussion, I think, about Chinese law being able to access that data, but it’s overridden by Australian law.
“That data is protected. We’re confident it’s protected, and we can give our customers that confidence.”
When asked directly whether someone in China could access Australian customer data, Ellis said he had asked the company that question the previous day and had been told “they can’t”.
However, BYD took a separate question on notice about whether Australian customer data could be transferred overseas through third-party software or hardware connected to its vehicles.
Ellis said information used through services such as Apple CarPlay and Android Auto remained within those respective ecosystems rather than being stored by BYD.
“If you have your apps on your phone connected to the car, we can’t do anything. We don’t have any visibility on that,” he said.
“So that information doesn’t sit with BYD.”
He said BYD also prevents owners from directly installing third-party apps onto its infotainment hardware as a cybersecurity measure.
The distinction is important because data generated or handled by BYD’s own systems and information processed through third-party devices and services may be subject to different privacy arrangements.
The ABC separately reported that BYD had removed references to China and “surveillance” from an Australian privacy policy shortly after receiving questions from Four Corners.
However, it was not clear in the report whether the wording cited came from BYD’s general Australian privacy policy, its dedicated vehicle privacy policy or its app privacy policy.
The distinction is relevant because BYD maintains separate privacy documents covering different parts of its Australian operations.
NRMA has accessed archives of BYD’s dedicated vehicle data and app privacy policies from July 2025 and July 2026. Neither document viewed by NRMA contained references to collecting customer information through “surveillance activities”.
However, the EV maker's general privacy policy which Open Road accessed on 25th September, 2026 at 10:25am states " We may collect, hold, use and disclose your information for the following purposes.... through surveillance activities undertaken to assist in the protection of people, property and company assets and resources (including ICT assets), information which may also be used to gather operational data, in connection with suspected illegal or improper activities and as part of disciplinary investigations."
This does not resolve the broader question of what information BYD vehicles collect, where it may ultimately be transferred or who may be able to access it.
BYD’s current Australian website policy also directs customers to separate privacy policies within the vehicle and BYD app for information specifically relating to those systems.
Collins said BYD supported clearer Australian regulation around vehicle privacy and data collection.
“For some time we’ve encouraged the government to consider and particularly make the requirements crystal clear,” he said.
“We’re happy to consult as much as we need to with any authorities on this matter, and secondly, whatever that outcome is for the legislators, we’ll comply.”