Security researcher Dan Hreszczuk of Fortify Labs demonstrated remote access to a BYD Shark 6 through an allegedly unprotected, passwordless entry point. In a controlled test near Canberra, he manipulated door locks, headlights, windscreen wipers and washer, infotainment display, audio volume, and music while the vehicle was being driven; he also tracked its location and activated the cabin microphone. The vehicle’s brakes and cameras were not accessible in the demonstration.
The test showed that captured in-cabin voice audio could be used to interact with Siri on an unlocked phone and obtain personal information. The exposure highlights privacy and safety risks in connected vehicles and has renewed attention on Australia’s lack of mandatory automotive cybersecurity standards, while the government consults on potential requirements.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The Australian government began industry consultations on prospective automotive cybersecurity requirements, as Australia reportedly lacks mandatory car-specific cybersecurity standards. The report said implementation of the proposed rules remains years away.
Hreszczuk replayed a recording of reporter Angus Grigg saying “Hey Siri” and sent further spoken queries through the vehicle speakers to activate Grigg's unlocked phone. The demonstration retrieved Grigg's home address, date of birth, age, and a contact number for former Prime Minister Malcolm Turnbull.
During a two-week Four Corners security test, Fortify Labs researcher Dan Hreszczuk found a BYD Shark 6 entry point with no password protection and used it in a controlled demonstration outside Canberra. He remotely controlled door locks, infotainment, audio, wipers, windscreen washer and headlights, tracked the vehicle, and activated its cabin microphone; the brakes and cameras remained protected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.