Case TS-9BBC218022 Sept 2026MixedCompound claim

A cybersecurity expert successfully hacked a BYD Shark EV and remotely took partial control of it, including triggering the windshield wipers and turning off the vehicle's lights while it was being driven, without needing a password.

Plain restatementA commissioned security researcher obtained remote access to a BYD Shark 6 and, during a staged demonstration, operated the wipers and switched the headlights off while a journalist drove the vehicle. The access point he used was not password protected.

Mostly accurateConfidence High
What this verdict means →

This claim is mostly accurate. The ABC's Four Corners programme did commission a cybersecurity researcher, Dan Hreszczuk of Fortify Labs, to hack a BYD Shark 6, and the ABC's own reporting confirms he remotely triggered the wipers, played music, locked the doors and switched the headlights off while a reporter drove at about 30 km/h. The researcher said the access point he used had no password on it. Two details are worth knowing: the Shark 6 is a plug-in hybrid, not a fully electric car, and the researcher had the vehicle in a lab for two weeks studying its software before the roadside demonstration, so this was a prepared proof of concept rather than an instant break-in. What remains unverified is the technical nature of the flaw, since no vulnerability write-up or advisory has been published, and no second researcher has independently reproduced the result. There is also no evidence in the reporting that steering, braking or acceleration were ever taken over, and BYD's public response addressed data storage rather than the hack itself.

The drift / as claimed vs as evidenced

A [drifted from the evidence:] cybersecurity expert successfully hacked a BYD Shark [drifted from the evidence:] EV and [drifted from the evidence:] remotely took partial control of it, including triggering the [drifted from the evidence:] windshield wipers and [drifted from the evidence:] turning off the [drifted from the evidence:] vehicle's lights while [drifted from the evidence:] it was being driven, without needing a password.


A [added by the neutral restatement:] commissioned security researcher obtained remote access to a BYD Shark [added by the neutral restatement:] 6 and, [added by the neutral restatement:] during a staged demonstration, operated the wipers and [added by the neutral restatement:] switched the [added by the neutral restatement:] headlights off while a [added by the neutral restatement:] journalist drove the vehicle. The access point he used was not password [added by the neutral restatement:] protected.

Red-tinted words in the claim drifted from the evidence. Green-tinted words are what a neutral restatement needs.

The trace / claim to source

Where it appeared
Omitted qualifier
A load-bearing condition from the source quietly disappears from the claim.
Tertiary source
**SecurityAffairs, Tarmac Life, Test Miles, tech-insider.org, rankiteo blog**
Secondary sourcespecialist motoring outlet
**Drive.com.au, "'Extends beyond cars': It's not just Chinese cars who can 'spy' on you"**
Primary sourcepublic broadcaster
**ABC News, "We got a cybersecurity expert to hack this BYD. It was too easy"** (21 Sep 2026)
Primary sourcepublic broadcaster
**ABC Four Corners full transcript, "Asleep at the Wheel"**
Primary sourcepublic broadcaster
**ABC Radio AM, "Security flaws in top-selling BYD EV"**
Primary source
**ABC News, "EV manufacturer BYD scrubs references to 'China' and 'surveillance' from its privacy policy"** (22 Sep 2026)
● Primary source found
What is true
  • A cybersecurity expert, Dan Hreszczuk of Fortify Labs, did gain remote access to a BYD Shark 6 and took partial control of non-driving functions. Confirmed in the ABC's own reporting and transcript.
  • The wipers were remotely triggered while the vehicle was being driven. Confirmed.
  • The headlights were remotely switched off while the vehicle was moving. Confirmed.
  • The access point used was not password protected. This is a direct quote from the researcher, reported consistently across the ABC's text, radio and television versions.
  • The post's caption details, including music over the speakers and the two-week timeframe, match the source reporting.
What is misleading
  • **Product mislabelling.** The claim calls it a "BYD Shark EV." The Shark 6 is a plug-in hybrid ute , not a battery electric vehicle. Minor, but the error appears throughout the aggregated coverage and in some ABC headline framing.
  • **Omitted qualifier: two weeks of dedicated, hands-on preparation.** "Without needing a password" is literally what the researcher said about one entry point, but presented alone it suggests trivial, instant compromise. The researcher had the vehicle in a lab for two weeks studying its code before the demonstration. The password-free access point was the starting point of the work, not the whole of it.
  • **Implied scope.** The headline framing invites readers to infer that a stranger could do this to a Shark 6 on the road today. The evidence supports a proof of concept under researcher-controlled conditions on a vehicle the researcher owned and had extended physical access to. The demonstration does not establish a remotely exploitable attack path against arbitrary vehicles in the wild.
  • **"Partial control" ambiguity.** Multiple secondary reports state that core driving systems such as brakes were not compromised and that the affected functions were customer-facing connected features. I could not confirm this specific carve-out against the ABC primary text within my searches, so treat it as reported but unconfirmed. Either way, nothing in the retrieved evidence shows steering, braking or propulsion being taken over.
What is uncertain
  • **The technical nature of the vulnerability.** No technical write-up, CVE, or vendor advisory was located. The ABC describes an unprotected "digital access point" without specifying whether it was a diagnostic interface, a telematics service, a debug port, or a cloud endpoint. This distinction determines whether the risk is remote or requires prior physical access.
  • **Whether prior physical access was required.** The transcript shows physical inspection of the vehicle during the two-week period. Whether that physical work was necessary to enable the later roadside remote control is not stated in the material I retrieved.
  • **Independent reproduction.** The finding rests on a single commissioned test by one firm. No second researcher or lab has confirmed it in the retrieved sources. It has not been peer reviewed or validated by a national CERT.
  • **BYD's technical response.** No primary BYD statement addressing the vulnerability itself was located, only its statements about data handling.
  • **Whether the vulnerability has been patched or affects other vehicles or markets.** Not established. The researcher's broader comment to Drive suggests he regards the issue as applicable to connected vehicles generally rather than unique to BYD. He told Drive the security risk extends to all connected vehicles and anything with a telematics box containing a cellular modem.
Evidence summary

The demonstration described in the post is real, was conducted by the ABC, and is documented in the broadcaster's own reporting. On a country road outside Canberra, Four Corners reporter Angus Grigg drove a BYD Shark 6 while a hacker had access to the car, and with the stroke of a key the researcher killed the headlights. The vehicle had spent the preceding two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars, whose task was to hack it and find out what could be seen and done remotely by the manufacturer. Hreszczuk said it was easier than expected. On the password element, the claim tracks the researcher's own words. Hreszczuk, co-founder of Fortify Labs in Canberra, said the access they took advantage of "didn't even have a password" and described the vehicle as open to a hacker. He also said he "didn't need to pick the lock as BYD left the front door open." The specific actions match. The ABC reported that the researcher first locked the doors while the reporter was inside, played music over the speakers and displayed images on the infotainment screen, then, as the reporter drove, remotely switched the wipers on at top speed, sprayed the windscreen with water and turned the lights on and off. ## METHODOLOGY AND CONTEXT **Vehicle:** The vehicle was a BYD Shark 6, a plug-in hybrid ute. It is not a battery electric vehicle. **Preparation:** This was not an opportunistic intrusion. The transcript records that at an unmarked lab in the Canberra suburbs the researcher spent two weeks poring over lines of code and hunting for vulnerabilities in the BYD Shark. The transcript also shows him examining the vehicle physically, referring to looking at where the camera connectors are, and notes he had bought the Shark 6 himself for the exercise. **Test conditions:** A controlled, staged run. The reporter was driving at about 30 km/h along a straight country road while the researcher operated the laptop from the roadside. The ABC broadcast account places the demonstration just before midnight on a quiet country road outside Canberra. **Stated purpose:** The stated mission was to find out what could be seen and done remotely from China , meaning the exercise was designed to simulate manufacturer-level remote access rather than to prove that an arbitrary internet attacker could do the same. **Regulatory backdrop:** The ABC reported that the hacking challenge was made easier because Australia has no minimum cybersecurity standards for cars, meaning BYD is not compelled to keep its software up to date or to have a system for managing cybersecurity risks to its vehicles. **Company response:** BYD said the data it collects is stored in Australia and that it has not and would not hand over the data of Australians to Chinese authorities. I did not locate a direct BYD technical rebuttal of the hack itself in retrieved primary material. One low-authority secondary outlet reported the company said it took the allegations seriously and had begun an investigation, which I could not confirm against a primary statement.

Complete reasoning
Every substantive element of the claim is confirmed by the primary source, which is the ABC's own reporting and full programme transcript: the researcher, the vehicle, the remote wipers, the headlights being killed mid-drive, and the password-free access point. The claim is not a distortion of the source; it is a close restatement of it. The deductions are that the Shark 6 is a plug-in hybrid rather than an EV, and that the striking "without needing a password" line is presented without the context that the researcher had the vehicle for two weeks in a lab and had bought it himself. Confidence is high because the primary source was directly retrieved and matches the claim, but note that confidence in the claim-to-source match is not the same as confidence in the underlying security finding, which rests on one unreplicated commissioned test with no published technical detail.
Use this case

The reply receipt is formatted for pasting into the thread where the claim is circulating.

Compact share page: verify.trueseeker.com/s/9bbc21807569/0sCkFtebN5F1bnkKFBL_6ZJ

Similar cases on record

Mostly accurate: A commissioned security researcher obtained remote access to a BYD Shark 6 and, during a s… | TrueSeeker