A cybersecurity researcher reportedly listened to a live phone call through a car’s cabin microphone. No malware. No dramatic hacking montage. Just an unprotected digital access point and roughly two weeks with the vehicle. ABC’s Four Corners gave Canberra-based Dan Hreszczuk, co-founder of Fortify Labs, a BYD Shark 6 plug-in hybrid pickup to examine. What he found matters well beyond one truck or one brand — at the time of the investigation, Australia had no mandatory minimum cybersecurity standards for connected cars.
What the Researcher Actually Did
The demonstration exposed how a password-free access point can open a vehicle’s most sensitive systems to outside control.
Working through an access point that required no password, Hreszczuk reportedly reached the vehicle’s internal network — the CAN bus, the system that lets a car’s electronic control units communicate with each other. From there, he demonstrated remote operation of locks lights wipers, door locks, speakers, and infotainment system. Brakes and steering were not accessed; that distinction matters and should not get lost.
Then came the more unsettling demonstration. Hreszczuk recorded the driver saying “Hey Siri,” combined it with additional commands, and played the audio through the car’s own speakers. The phone inside responded — reportedly disclosing a home address, date of birth, and contact details. No direct compromise of the phone was demonstrated; the attack exploited the interaction between the car’s speakers, microphone, and the phone’s voice assistant.
The test showed:
- Remote real-time tracking of the vehicle’s location
- Remote operation of locks, lights, wipers, and speakers
- Live access to the cabin microphone, including an active phone call
- Voice-assistant manipulation using recorded audio replayed through the car’s speakers
- Separately, an Xpeng insider could reportedly view an Xpeng G6’s GPS position, speed, steering angle, seat settings, and occupant count in real time
BYD responded that the footage “did not conclusively prove” the vehicle could be attacked remotely without prior physical access, and said it had launched an internal investigation involving Australian and Chinese teams, with findings to be made public.
The Bigger Problem Behind One Truck
The real gap isn’t in one vehicle’s software — it’s in the absence of rules requiring any automaker to close these gaps.
At the time of the investigation, Australia had no minimum mandatory automotive-cybersecurity standards requiring automakers to push software updates, manage vulnerabilities, or maintain formal cybersecurity-risk systems. That absence means the privacy and security baseline for connected vehicles on Australian roads has depended largely on manufacturers’ own choices.
The investigation did not prove BYD or Xpeng transferred Australian customer data to Chinese authorities. What it demonstrated is how much a manufacturer may technically be able to access — location, vehicle behavior, cabin audio, and connected-device interactions. Those remain separate questions from what is actually collected, where it is stored, and whether it is shared. Xpeng said it cannot remotely immobilize vehicles and has never provided Australian customer data to Chinese authorities.
A connected car is, in practical terms, a risks of connected cars in motion. Keeping vehicle and phone software updated, reviewing app permissions, and being deliberate about when voice assistants are active are reasonable precautions — though they do not address vehicle-side vulnerabilities directly. The concern raised here extends beyond any single brand. It is that Australia’s regulatory framework has not kept pace with the connected vehicles already on its roads.
























