A cybersecurity researcher was able to take control of a Chinese-made electric vehicle using a vulnerability that required no password, according to an Australian television investigation that has renewed scrutiny of data collection and digital security in modern cars.
The documentary, produced by ABC News in Australia, focused on two Chinese electric vehicle brands, Xpeng and BYD, and examined how much information modern vehicles collect and transmit. In one segment, cybersecurity expert Dan Hreszczuk was given a BYD Shark 6 pickup truck for two weeks. After identifying a flaw in the vehicle's systems, he gained access that he described as requiring no authentication at all.
«The access we took advantage of didn't even have a password,» Hreszczuk said in the program.
Once inside the system, Hreszczuk demonstrated that he could lock the driver inside the vehicle, play music at high volume, and manipulate the windshield wipers and lights while the truck was moving. More seriously, he was able to listen through the vehicle's interior microphones, potentially capturing phone calls and other sensitive conversations.
The investigation also showed how a hacker could exploit voice-activated technology inside the car. Hreszczuk recorded a journalist's voice and used it to trigger the Apple iPhone's «Hey Siri» command through the truck's speakers. Once activated, the phone disclosed personal information including the journalist's date of birth, telephone number, and contacts stored in the device. Among those contacts was the phone number of the Australian prime minister.
The ABC report also examined Xpeng vehicles. An unnamed company insider was allegedly able to monitor a G6 model obtained by the network, tracking its location, speed, seat occupancy, and steering wheel angle. The program suggested that such data could be accessible to the manufacturer in China.
The findings have amplified an ongoing debate in Australia and other countries about the national security implications of Chinese-made vehicles. The Australian Security Intelligence Organisation has advised ministers and public servants not to hold sensitive conversations inside their cars or connect work devices to vehicle systems, though no directive restricts which cars they may purchase. Trade Minister Don Farrell drives a BYD Shark 6, and Climate Change and Energy Minister Chris Bowen owns an Xpeng G6.
Other nations have taken more restrictive steps. The United Kingdom and Poland have banned Chinese cars from sensitive sites. British lawmakers noted last year that the Chinese government holds legal rights to access data collected by cameras, sensors, and radar systems in vehicles built with Chinese technology. There is no public evidence, however, that China has asked its automakers to spy on other countries.
The program also placed the concerns in a broader context. Automotive security and privacy problems are not unique to Chinese brands. A 2023 study by the Mozilla Foundation examined 25 car brands and found that all of them received a «Privacy Not Included» warning for their handling of consumer data. Two brands, Nissan and Kia, were found to monitor drivers' sexual activity and information about owners' sex lives, respectively. Eighty-four percent of the brands surveyed sold collected data to third parties.
Hackers have also demonstrated the ability to access vehicles from Tesla, Kia, and Subaru, among others. As connected cars become more common, the investigation suggests that scrutiny of vehicle security and privacy policies may need to extend well beyond any single manufacturer or country of origin.