Cars used to be simple. Now they’re rolling software platforms with microphones, cameras and an internet connection that’s always on, making them tempting targets for cyber criminals. An Australian cyber security expert decided to see just how tempting a target his own BYD Shark 6, one of Australia’s best-selling trucks, would turn out to be. Turns out, this Chinese EV was less locked down than he thought it would be, with some data not even stored behind passwords, and clearly behind rivals such as Tesla. Considering BYD is shipping cars in volumes to rival Toyota, that’s pretty concerning.Â

BYD
What A Hacker Can Actually Do To A Chinese Car
With the BYD compromised in under two weeks, the team could track its location live, and even switch on the in-car microphone and listen in on phone conversations inside the car. They then used Siri through the car’s speakers to coax personal details out of the smartphone left inside, details that included a home address and a birthday. They were also able to trigger the wipers and toggle the lights. The hacker said he couldn’t touch the vital controls of the car, i.e the brakes or steering, but that’s not a guarantee that a more determined hacker couldn’t bring that result. The more important takeaway is that a cybercriminal with time and skill could turn your connected car into a listening device and a map of your routine. What this test proved is that some Chinese EVs are probably more susceptible to attack than other connected cars.Â
Is In-Car Privacy Just An Illusion?

Another part of this particular experiment from ABC News In-Depth involved an insider from another Chinese EV carmaker, Xpeng. The agent was able to connect to an Xpeng G6 electric coupe SUV as the reporter drove around town, and could see the GPS coordinates of the car, its speed, steering angle, and even the seat settings in real time. He was even able to tell how many people were in the car. Officially, Xpeng says it can’t immobilize vehicles remotely, nor has it ever handed over Australian customer data to Chinese authorities.Â
And that is one thing this test didn’t end up proving: that Chinese EVs are sharing data with China. But what it shows is capability. Manufacturers can see a startling amount of information about their buyers, and some are selling your data without your consent. The rules for connected car security are not watertight in many parts of the world. Whether that worries you or not just might come down to how much you trust the badge on the hood of your connected car.Â
Â