Wireva

Australian TV Investigation Exposes Cybersecurity Risks in Chinese EVs

A documentary in Australia demonstrated how a hacker easily took control of a BYD Shark 6, raising data privacy and national security concerns as Chinese electric vehicles gain popularity.

This item was produced with AI assistance under the editorial responsibility of Haydamax OÜ.

A documentary broadcast in Australia has revealed significant cybersecurity vulnerabilities in Chinese electric vehicles, with a hacker successfully taking control of a BYD Shark 6 pickup truck and accessing sensitive personal data. The investigation, conducted by ABC News, highlights growing concerns about data privacy and national security as Chinese-made EVs rapidly gain market share in the country.

In the documentary, cybersecurity expert Dan Hreszczuk was given a BYD Shark 6 for two weeks. After identifying a vulnerability, he was able to access the vehicle's systems with alarming ease. «The access we took advantage of didn't even have a password,» Hreszczuk said. He demonstrated the ability to lock the driver inside the car, blast music, and manipulate the wipers and lights while the vehicle was in motion. More troubling, he accessed the car's interior microphones to listen in on conversations and record a journalist's voice. By clipping the journalist's Apple phone wake-up command and playing it over the Shark's speakers, Hreszczuk triggered «Hey Siri» and then added his own commands. The iPhone subsequently revealed the user's date of birth, telephone number, and contact numbers, including that of the Australian Prime Minister.

The investigation also examined another Chinese brand, Xpeng. An unnamed company insider allegedly monitored a G6 obtained by ABC News, reporting the vehicle's location, speed, seat occupancy, and steering wheel angle. According to the report, this information and more were accessible to the company in China, raising fears that sensitive data could be transmitted abroad. The Australian Security Intelligence Organisation has warned ministers and public servants not to hold sensitive conversations in their cars or connect work devices, though no directive restricts which cars they can purchase. Notably, Australia's trade minister, Don Farrell, drives a BYD Shark 6, while the climate change and energy minister, Chris Bowen, owns an Xpeng G6.

These revelations have intensified the debate over the national security implications of Chinese electric vehicles. The United Kingdom and Poland have already banned Chinese cars from sensitive sites. Last year, UK lawmakers noted that the Chinese government holds legal rights to access data collected by cameras, sensors, and radar systems in vehicles built with Chinese technology. However, there is no evidence that China has requested its automakers to spy on other countries.

While the documentary focuses on Chinese EVs, automotive security and data privacy concerns are not limited to them. A 2023 study by Mozilla found that all 25 car brands it examined received a «Privacy Not Included» warning label for poor handling of consumer data. Two brands, Nissan and Kia, even monitored drivers' sexual activity and information about owners' sex lives, respectively. Eighty-four percent of the brands surveyed sold collected data to third parties. Hackers have also gained access to vehicles from Tesla, Kia, and Subaru.

The investigation underscores that as modern cars become increasingly connected, they collect vast amounts of data on driving habits and users themselves. The findings suggest that all vehicles, regardless of origin, may warrant greater scrutiny regarding their security and privacy policies.

Same event, other desks

Story file →