Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

A Hacker Took Control Of A Byd For Tv, But Should Should You Be Worried?

Card image cap

  • An investigation into the cybersecurity of Chinese EVs showed how much data they collect.
  • One hacker was easily able to take control of a BYD, tracking it and accessing most of its functions.
  • Report highlights data privacy and vehicle security concerns for Australians.

A documentary carried out in Australia has highlighted the potential cybersecurity risks associated with the rapid influx of Chinese electric cars in the country. In it, it highlighted how car companies have access to a treasure trove of information from each vehicle, with modern machines able to harvest an immense amount of data, not just on driving state, but potentially on the users themselves.

The investigation centered mainly around two Chinese EV brands: Xpeng and BYD. With Xpeng, an unnamed company insider was allegedly able to monitor a G6 obtained by ABC News. They were able to report the vehicle’s location, speed, seat occupancy, and even steering wheel angle, among other things. This information and more were also allegedly available and accessible to the company in China.

Read: Cameras Logged Everything About Your Car And Made It Public

The story highlights the potential national security risks that Chinese cars could pose, with the potential for sensitive data to be sent back to China. This is compounded when government officials themselves are the ones buying Chinese cars. The Australian Security Intelligence Organisation has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices, but there’s no directive on what cars they can or can’t buy. In fact, Australia’s trade minister, Don Farrell, has a BYD Shark 6, while the minister for climate change and energy, Chris Bowen, drives an Xpeng G6.

The Hacking Danger

Xpeng G6

ABC’s report delved deeper into the issue when they highlighted what a hacker can do when left alone. Dan Hreszczuk, a cybersecurity expert who specialises in cars, was given a BYD Shark 6 pickup truck for two weeks. After identifying a vulnerability, he was able to access the car’s systems quite easily. “The access we took advantage of didn’t even have a password,” he said.

Hreszczuk was able to lock the driver inside the car, play music loudly, and mess around with the wipers and lights while the car was on the move. While these hijinks may be annoying and potentially hazardous, the scary stuff happened when the hacker listened in on the car’s interior microphones. Not only could he listen to potentially sensitive information, such as phone calls, Hreszczuk was then able to record the voice of the journalist and clip his Apple phone’s wake-up command to be played over the Shark’s speakers.

See Also: Your Phone May Rat You Out After A Crash, Even If The Cops Don’t Realize It

Once “Hey Siri” was triggered, the hacker’s own commands were added, with the iPhone revealing all manner of information. This included the user’s date of birth, telephone number, and even the contact numbers of people in his phone book, one of which happened to be the Australian Prime Minister’s phone number.

Should We Be Worried?

While the national security angle has already prompted other nations, such as the UK and Poland, to ban Chinese cars from sensitive sites, there’s as yet nothing to suggest that China has requested its automakers to spy on other countries. Still, UK lawmakers noted last year that the Chinese government holds legal rights to access data collected by the cameras, sensors, and radar systems in vehicles built with Chinese technology.

However, while it highlights that there are some serious issues surrounding data collection in modern cars, and how that information is processed and protected, are Chinese cars inherently untrustworthy?

Well, one could argue that automotive security concerns are nothing new, and the fears are certainly not confined to just Chinese cars. In 2023, a Mozilla study found that all 25 car brands it looked into earned its “Privacy Not Included” warning label for their poor treatment of consumer data. Two brands, Nissan and Kia, even monitored drivers’ “sexual activity” and information about owners’ “sex life,” respectively. Eighty-four percent of the brands surveyed sold the data they collected to third parties too.

We’ve also reported on numerous instances of hackers allegedly being able to gain access to all manner of cars, including Tesla, Kia, and Subaru. In an age where every device, big and small, is collecting as much data on its users as it can find, perhaps it’s time all cars came under more scrutiny for their security and privacy policies.

A Hacker Took Control Of A BYD For TV, But Should Should You Be Worried?
BYD Shark 6