"Software Defect"This incident confirms suspicions that modern vehicles are hackable and log more than just your next oil change interval. Fortify Labs in Australia was able to hack a BYD Shark 6 in the span of two weeks, and the result of that effort is location data and even phone calls made in the car.In addition to the private information, the hacking also exposes a backdoor to the vehicle's functions, like the headlights, windscreen wipers, and other features being remotely accessible to hackers. Following the discovery, BYD Australia has launched a formal internal investigation regarding this matter after Four Corners, a news source in Australia, reported Fortify Labs' findings on September 21, 2026.BYD China Is Also InvestigatingBYD China labeled the cybersecurity issue as a "software defect," which was exploited using an "Android Debug Bridge" (ADB), a tool that enables access to Android devices. The Shark 6 uses the "DiLink" infotainment system, which is Android-based and used in other BYD and Denza models aside from the Shark 6.While the Android system is heavily customized by BYD, you cannot deny its base. The troubling part is that a lot of Chinese manufacturers, aside from BYD, also use Android as a base for their infotainment systems, which could mean that this exploit may also spell trouble for other vehicles with similar systems.In a report from Car Expert, the issue has been resolved. BYD discovered that the application that was involved in the experiment needed physical touch in order to confirm its installation into the infotainment. That being said, BYD has since issued a corrective action that "removes the unintended pathway that allows ADB to be enabled through the infotainment system user interface, thereby eliminating the access path identified during the investigation."BYD continued by saying that an over-the-air update for the Shark 6 will be issued "only once the updated software has undergone rigorous validation." Furthermore, BYD will look into the possibility of its other products needing such a security patch.BYD SharkBYDFortify Labs ClarifiesFortify Labs published an article of their own, detailing that the Four Corners episode didn't show everything that was done to the car. The initial intention of Fortify Labs was to "simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused." While the content of the Four Corners report did bring attention to the issue, Fortify Labs went on to clarify a few facts.The vehicle used throughout the research and filming was a 2025 BYD Shark 6 Premium, which we owned.The vehicle was reported to be fully patched, with all software updates applied, as of 16 July 2026. Research began on 17 July 2026.The head unit's software version was reported as 56.1.2.2507080.1.A publicly known technique was used to gain unprivileged access to the head unit.Using this access, we installed software that achieved the majority of what was demonstrated.Physical access to the vehicle was required to install the software on the head unit. From that point onwards, connectivity and control of the software functioned remotely.As seen in the Four Corners episode, the CAN bus line was also tapped to demonstrate what could happen if an ECU on that network was compromised. This is how the lights were switched off and the windscreen wipers activated. This was all achieved in-line, with a Raspberry Pi simulating a compromised ECU sending out CAN bus messages.No firmware was modified anywhere on the system, nor was any effort made to escalate privileges, as it was not required for the purpose of the demonstration.Prior to starting the research, the SIM card was removed from the telematics box within the vehicle. This isolated the vehicle from the internet, and the vehicle was unable to interact with any part of BYD's back-end infrastructure. This was done as a safety precaution to ensure no part of our research interacted with or affected BYD's online services or infrastructure in any way."Out-of-band" internet connectivity was established by connecting the vehicle to a cellular hotspot within the car. The vehicle used our own infrastructure and cellular connection. At no time was the BYD-provisioned SIM card or the BYD-provided internet access used to remotely interact with the vehicle during our research or the demonstration.BYDPhysical Access Is RequiredFor now, the system is susceptible to hacking, but it requires the hacker to physically be there to install software and also tap into the CAN bus line in order to gain access to the vehicle's functions.While the BYD Shark 6 was the car that came under fire for being in the episode, Fortify Labs has stated that "this same [hacking] technique can be used against other Android-based head units in vehicles from other manufacturers if they are not adequately locked down.""People shouldn't just blindly trust that vehicle manufacturers are producing safe and secure cars, and this doesn't only apply to Chinese manufacturers. The same goes for vehicles coming out of the U.S., Europe, and the rest of Asia. It applies to all vehicle manufacturers," Fortify Labs continued. "It's also worth highlighting that these risks are not faced by Australia alone. This is a global issue, and other countries should be concerned."BYD"Cyber Security Star Rating"One of the other recommendations that came out of this incident was a "Cyber Security Star Rating" that would be conducted alongside the Australian NCAP star rating. It's not as simple as crashing a car, however.For now, implementing a cyber security rating system will be a huge challenge, mainly because, unlike physical crashes, what works and what doesn't in the realm of cyber security always changes. There is also currently no established process and rubric for the industry to judge how cyber-secure a car is, and there is no guarantee that a 5-star car you buy today might be vulnerable tomorrow.