Related - Original Article: We got a cybersecurity expert to hack this BYD. It was too easy - ABC News
With BYD on track to sell around 100,000 cars this year, roughly double its 2025 sales and competing with Toyota for the top position, I thought some of the recent reporting was pretty concerning.
A cybersecurity expert was able to remotely access a BYD Shark 6 and control some of its features without needing a password. BYD says the footage doesn’t conclusively prove that remote hacking was possible.
BYD’s original Australian privacy policy allowed data collection “in connection with suspected illegal or improper activities” through “surveillance activities”, and listed China as a destination for data transfers.
After Four Corners asked questions about the policy, the references to China and “surveillance” were removed from the BYD website. This happened just 1 hour and 16 minutes before the updated policy was sent to Four Corners. BYD denies the change was related to the investigation.
My understanding is that, regardless of what the updated Privacy Policy says, China’s national security laws can still require companies to cooperate with authorities if requested.
China has already restricted Tesla vehicles from government buildings, military sites and cultural and exhibition centres over data security concerns.
In 2025 the UK military also banned EVs with Chinese components from parking within 3.2km of certain locations. UK military personnel have apparently been told not to have conversations inside electric vehicles because of concerns about built-in microphones recording and transmitting audio, and there are dashboard stickers warning about connecting military devices to vehicles.
I’m not saying BYD is necessarily worse than every other modern connected car. It may not be. What concerns me more is that Australia doesn’t have a minimum cybersecurity standard for modern vehicles. The Privacy Act was written in 1988 and was not created for modern vehicles.