Welcome to the Fortify Labs blog

September 28, 2026 / by Fortify Labs / In BYD, Shark 6, Connected Vehicles, ADR 115, ADR 116, Four Corners

BYD Shark 6: What wasn't in the Four Corners episode.

We feel it is important to provide further details about the research we did on the BYD Shark 6, and to explain how the simulation shown in the Four Corners episode was achieved.

We were approached to undertake this research and tasked with one primary objective involving a BYD vehicle:

Simulate the remote access a car manufacturer has to a connected vehicle and demonstrate how this access could be abused.

It is important to highlight that at no point was this investigation about gaining initial access to the vehicle.

The required access was already implied, given we were simulating a manufacturer’s access to a connected vehicle. Manufacturers have the ability to reach into their vehicles remotely, run individual commands and deliver over-the-air (OTA) updates.

The facts:

  • The vehicle used throughout the research and filming was a 2025 BYD Shark 6 Premium, which we owned.

  • The vehicle was reported to be fully patched, with all software updates applied, as of 16 July 2026. Research began on 17 July 2026.

  • The head unit’s software version was reported as 56.1.2.2507080.1.

  • A publicly known technique was used to gain unprivileged access to the head unit.

  • Using this access, we installed software that achieved the majority of what was demonstrated.

  • Physical access to the vehicle was required to install the software on the head unit. From that point onwards, connectivity and control of the software functioned remotely.

  • As seen in the Four Corners episode, the CAN bus line was also tapped to demonstrate what could happen if an ECU on that network was compromised. This is how the lights were switched off and the windscreen wipers activated. This was all achieved in-line, with a Raspberry Pi simulating a compromised ECU sending out CAN bus messages.

  • No firmware was modified anywhere on the system, nor was any effort made to escalate privileges, as it was not required for the purpose of the demonstration.

  • Prior to starting the research, the SIM card was removed from the telematics box within the vehicle. This isolated the vehicle from the internet, and the vehicle was unable to interact with any part of BYD’s back-end infrastructure. This was done as a safety precaution to ensure no part of our research interacted with or affected BYD’s online services or infrastructure in any way.

  • “Out-of-band” internet connectivity was established by connecting the vehicle to a cellular hotspot within the car. The vehicle used our own infrastructure and cellular connection. At no time was the BYD-provisioned SIM card or the BYD-provided internet access used to remotely interact with the vehicle during our research or the demonstration.


Why haven’t we given details on the initial access method?

There is a simple answer, and it came down to a serious ethical concern we faced.

Given how easy it is to replicate the technique, publishing it would present a real risk to anyone who is a victim of stalking or domestic abuse. This is a widespread, systemic crisis here in Australia, and these details could put people at further risk from their abusers.

To add to the severity, this same technique can be used against other Android-based head units in vehicles from other manufacturers if they are not adequately locked down. Those in the industry will know exactly what access we used, and some have commented as such. We just don’t want to be the ones who publicly connect the dots and arm potential abusers with a way of remotely turning on a microphone in a vehicle or getting live location updates plotted on a map.

As was highlighted a number of times in the episode, and in follow-up interviews, this was never about how access was achieved. It was about how powerful that access is, and how even low-privileged access can be misused with potentially catastrophic consequences.

If you are a victim of stalking or tech-based abuse, or know someone who is, you can find help through 1800RESPECT by visiting their website (1800respect.org.au) or calling 1800 737 732.


What has BYD done well?

It is worth noting that overall, the SELinux policies in place on the head unit appear to be well implemented. This, combined with the separation achieved through the QNX hypervisor, prevented us from accessing more sensitive components within the vehicle, such as the cameras.

It is unclear how well this would stand up if a local privilege escalation (LPE) vulnerability were discovered and used, but that was outside the scope of this assessment and ultimately was not required to achieve our objectives.


Taking BYD and China out of the discussion

People shouldn’t just blindly trust that vehicle manufacturers are producing safe and secure cars, and this doesn’t only apply to Chinese manufacturers. The same goes for vehicles coming out of the US, Europe and the rest of Asia. It applies to all vehicle manufacturers.

It’s also worth highlighting that these risks are not faced by Australia alone. This is a global issue, and other countries should be concerned.


What if we introduce a “Cyber Security Star Rating”?

Wouldn’t it be amazing for a consumer shopping around for a new car to be able to compare a “Cyber Security Star Rating” alongside the ANCAP star rating for each vehicle they were considering? Sadly, it’s not as simple as that.

ANCAP assesses physical safety, where the risks are well understood and don’t change, and the protections manufacturers build in stay the same once the vehicle leaves the factory. Because both the risks and the safeguards are stable, ANCAP can design repeatable tests that verify whether a vehicle adequately protects its occupants and other road users, and that rating stays meaningful for the life of the vehicle.

Cyber security doesn’t work that way. The threat landscape shifts daily, and there is currently no established process in Australia to assess vehicles on an ongoing basis and communicate those findings to consumers so they can make well-informed purchasing decisions. Simply put, a vehicle that is rated as cyber secure today could be found vulnerable tomorrow.

We believe this would be an important step in keeping consumers informed and manufacturers accountable. However, further work is needed to identify an assessment mechanism that can practically support this.


Why should I care?

This is a question some people may be asking right now. For the everyday Australian, maybe some don’t care. Many have commented along the lines of: “if someone wants to listen in on my kids singing Baby Shark in the car, then go ahead”. Others, rightly, point out that their mobile phone goes everywhere with them and is much more of a risk than their car.

If you’re a senior executive in a multinational company or a government official, the risks may be a little different, but let’s take the privacy component out of the discussion for a moment.

With such rapid growth of connected vehicles across the globe, there is a real and often overlooked risk associated with all this connectivity across the automotive ecosystem: ransomware.

With manufacturers now incorporating powerful remote access into our vehicles, what happens if that access falls into the wrong hands? We have already seen how devastating ransomware can be, from attacks that crippled hospitals to the Toll Group and JBS Foods attacks.

Imagine a criminal group gaining access to a vehicle manufacturer’s back-end systems. In theory, they could push an OTA update to every connected vehicle that brand has on Australian roads. Picture every car from one of the country’s most popular brands stopping at once, with gridlock on the Sydney Harbour Bridge and the M80 Ring Road, and every affected car requiring a technician to physically reflash the software on each of its ECUs.

The impact would be catastrophic, and it is one of many reasons why vehicle cyber security deserves a far higher priority than securing our smart washing machines and kettles.


Some advice

A common question we get asked is “What can I do to protect myself?”

If you ask any cyber security professional, the number one thing you can do to protect yourself is patch your devices. This applies to your mobile phone, your desktop computer and even your car. So the best advice we can offer is: don’t ignore the pop-up message asking if you want to update the software on your head unit, or the connected app on your mobile phone. Just like with an engine light, the car may function for now, but if you don’t tend to that warning light, it may come back to bite you in the future.

This also applies to non-connected vehicles. Just because a vehicle is not connected to the internet doesn’t mean you shouldn’t be proactive about its cyber security. Wi-Fi and Bluetooth are still viable ways in and should be taken seriously. This can be as simple as asking your mechanic, each time your car is serviced, to make sure all software updates have been applied.


What needs to change?

With Ford, Holden and Toyota closing their local plants, Australia no longer builds its own cars, and much of the technology we rely on in our everyday lives is designed and manufactured overseas.

Like it or not, that means we have limited control over how these products are built, what software they run and who has access to them. Our vehicles are no exception. Every new car sold here is engineered offshore and connected to back-end systems we don’t own or oversee. This makes it all the more important that we set clear expectations for how those vehicles are secured, both before they arrive and throughout their life on our roads.

Our motivation for agreeing to undertake this research and appear on Four Corners was our hope that it would be a catalyst for change.

We need to take these risks seriously, and there is an opportunity right now to make real and meaningful change to the regulations governing vehicles in this country.

Although slow to the party, Australia is finally drafting new Australian Design Rules (ADRs) to address some of the cyber security risks facing passenger vehicles. Draft ADR 115 and ADR 116 are based on the well-established UN Regulations 155 and 156, and they focus on how manufacturers develop and maintain vehicle software and how they deliver OTA updates to keep it secure. This is a step in the right direction, but the draft rules still don’t address where the back-end infrastructure is located, who has access to it, or who maintains it.

Given the new ADRs are still in draft, there is still time to go further. The government could require that the systems managing connected vehicles in Australia are hosted here, run under Australian law, and overseen by an Australian regulator. It’s much easier to build that in now than to try to add it once the rules are finalised.