Hacker Finds This Chinese BYD Pickup Shockingly Easy to Break Into and Control RemotelyMotorBiscuitSaajan JogiaThu, September 24, 2026 at 11:30 AM UTCAdd us on GoogleA cybersecurity expert has demonstrated how easily a BYD Shark 6 can be accessed remotely, raising questions about the potential consequences if the vehicle's connected systems fall into the wrong hands.Australia's ABC News aired footage of the demonstration, conducted by Dan Hreszczuk, a Canberra-based cybersecurity expert and co-founder of Fortify Labs. He spent two weeks examining the plug-in hybrid before remotely accessing several of its functions."It was easier than we were expecting," Hreszczuk said.AdvertisementAdvertisementOne of the biggest problems he discovered was that the digital access point he exploited did not even have a password."The access we took advantage of didn't even have a password," he explained. "It's a little bit scary how open … the BYD Shark is to a hacker."Hacker Could Toggle Multiple ControlsOnce inside, Hreszczuk was able to lock the vehicle's doors, play music through its speakers and display images on the large infotainment screen.While the Shark 6 was being driven, he remotely activated the windshield wipers, sprayed the windshield with water, and switched the headlights on and off. He eventually turned the headlights off completely while the vehicle was moving.AdvertisementAdvertisementThe test did not provide Hreszczuk access to the Shark 6's brakes or cameras, which he said were protected. However, the ability to remotely interfere with lights, wipers, and other functions could still become dangerous if exploited by a malicious actor, particularly while a vehicle is traveling quickly.The demonstration also highlighted the surveillance potential of a connected vehicle. Hreszczuk was able to track the Shark 6 in real time and remotely activate its microphone, allowing him to listen to conversations taking place inside the cabin.He even demonstrated how recorded audio could potentially be used with the vehicle's speaker system to interact with Siri and extract information, including personal details and an internet banking password.The findings are particularly significant in the United States, where the government has restricted certain connected-vehicle technology linked to China over national-security concerns. U.S. rules cite the risk that foreign adversaries could access sensitive vehicle data or remotely manipulate connected vehicles.AdvertisementAdvertisementThe BYD demonstration shows how those concerns could translate into real-world risks, with an outside party able to interfere with vehicle functions, access its microphone, and track its location.The test does not show that BYD or the Chinese government has carried out such activity. However, it demonstrates how a vulnerability could potentially give an attacker remote access to a connected vehicle, reinforcing the security concerns behind the U.S. restrictions.Hreszczuk summed up the issue bluntly: "I didn't need to pick the lock as BYD left the front door open." He added, "I think people overlook a lot of these concerns for the convenience. It is a beautiful car to drive. It looks beautiful inside, but there are real security concerns."This cybersecurity test raises a broader question: how vulnerable are connected cars, including electric vehicles from other manufacturers, to similar attacks? If hackers can remotely access critical vehicle systems, both driver safety and personal privacy could be at stake.