We Hacked a BYD and It Was Too Easy

We Hacked a BYD and It Was Too Easy The Hidden Risks of China’s EV Revolution.

Chinese electric vehicles (EVs) led by manufacturing giants like BYD are undeniably revolutionising motoring. Offering high-end features at a fraction of the cost of traditional western or Japanese brands, it’s no wonder Aussie consumers are buying them in droves.

But as our roads fill with these hyper-connected machines, a looming question is being asked in boardrooms, parliament houses, and cybersecurity labs: At what cost?

Recent investigations, including a chilling report by reporter Angus Grigg on ABC’s Four Corners, have exposed a reality that many motorists are blissfully unaware of. We had a BYD hacked, and frankly, it was too easy.

As Australia embraces the electric vehicle boom, we need to talk about the serious privacy and national security risks hiding behind those touchscreen displays.

The BYD Connected Car is Not Just a Car It’s a Computer on Wheels

To understand the risk, we have to shift how we view modern automobiles. Today’s EVs are no longer mechanical machines powered by internal combustion; they are essentially smartphones on four wheels.

Modern Chinese EVs are packed with:

  • High-definition exterior cameras mapping our streets and driveways in real-time.
  • Cabin-facing cameras and microphones monitoring driver fatigue and listening to conversations.
  • GPS and location trackers logging every journey, destination, and frequent stops.
  • Constant cellular and Wi-Fi connectivity, meaning data is constantly being beamed back to cloud servers often hosted overseas.

For consumers, this creates unprecedented convenience. For cybersecurity experts and potentially foreign intelligence agencies it creates an unprecedented surveillance vector.

“It Was Too Easy”: What the BYD Hacks Reveal

When cybersecurity researchers turn their attention to modern connected vehicles, the vulnerabilities are alarming. In recent tests and demonstrations featured on Four Corners, ethical hackers managed to compromise connected vehicles with terrifying ease.

From accessing real-time location data to intercepting interior microphone feeds and even manipulating vehicle systems, the barrier to entry for malicious actors is far too low.

While everyday drivers might assume their data stays between them and the steering wheel, the reality is that the software architecture of these vehicles leaves doors wide open. And because these cars are perpetually online, a vulnerability doesn’t just affect one car it can theoretically expose an entire fleet simultaneously.

The National Security Dilemma: Privacy vs. Progress

The issue goes far beyond personal data leaks. It touches the core of Australia’s national security.

Right now, federal cabinet ministers and high-ranking government officials are driving or being chauffeured in these exact vehicles. Consider the sensitivity of the data moving through these cars:

  • Where politicians travel and who they meet.
  • Private conversations held inside the cabin.
  • Visual maps of secure government facilities captured by the car’s external sensors as it drives through Canberra.

Under Chinese national intelligence laws, companies headquartered in China are legally obligated to cooperate with state intelligence operations. This means that data collected by a BYD or other Chinese-manufactured EV could, in theory, be accessed by foreign authorities.

While there is no suggestion that every car is actively being used for espionage, the potential for mass surveillance and in worst-case scenarios, remote sabotage cannot be ignored. As cybersecurity experts point out, Australia’s current regulatory framework simply isn’t equipped to handle the unique threat profile of software-defined vehicles.

Are Australia’s Cybersecurity Laws Too Weak?

Australia is caught in a paradox. We have aggressive carbon-reduction targets and a desperate need to accelerate EV uptake to meet them. Cheap Chinese EVs are the fastest, most effective vehicle for that transition.

However, our privacy and cybersecurity laws are lagging painfully behind the rapid pace of technological innovation.

Unlike the telecommunications sector where high-risk vendors like Huawei were barred from 5G rollouts due to national security concerns the automotive sector remains largely unregulated in this regard. There are currently no stringent local standards governing where vehicle data is stored, who can access it, or how vulnerable a car’s firmware must be before it is allowed on Australian asphalt.

What Does This Mean for Aussie EV Owners?

If you already own a Chinese EV or are thinking of buying one don’t panic. These cars are fantastic to drive, incredibly efficient, and represent the future of transport. The issue isn’t necessarily isolated to Chinese brands either; all modern connected cars, regardless of where they are made, collect vast amounts of data.

However, consumers do need to become more “cyber-aware”:

  1. Check Your Permissions: Dive into your car’s infotainment system settings. Turn off data-sharing permissions where possible, especially regarding location tracking and cabin analytics if they aren’t essential for driving.
  2. Be Mindful of Conversations: Remember that modern car cabins are essentially smart-rooms. Treat sensitive phone calls or business discussions inside the car with the same caution you would give an untrusted smart speaker.
  3. Demand Better Regulation: Consumers should pressure lawmakers and manufacturers to adopt transparent data practices, local data storage mandates, and higher cybersecurity standards.

The Bottom Line

The EV revolution is unstoppable, and Chinese automakers deserve credit for driving down prices and accelerating global adoption. But convenience should never come at the expense of sovereignty.

As investigations like the one on Four Corners prove, our cars are talking and somebody might be listening. It’s time for Canberra to wake up, update our cybersecurity laws, and ensure that our driveways don’t become Australia’s biggest security blind spot.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.