As reported by SecurityAffairs, cybersecurity researcher Dan Hreszczuk of Fortify Labs remotely compromised a BYD Shark 6 during a live demonstration for ABC's Four Corners program, controlling vehicle functions including door locks, wipers, infotainment, and critically, headlights — while the vehicle was in motion at night. The entry point required no password at all.

Security Impact: As reported by SecurityAffairs, cybersecurity researcher Dan Hreszczuk of Fortify Labs remotely compromised a BYD Shark 6 during a live demonstration for ABC's Four Corners program, controlling vehicle functions including door locks, wipers, infotainment, and critically, headlights — while the vehicle was in motion at night.

What makes this story significant is not that a connected car was hacked. Security researchers have been demonstrating vehicle compromise for over a decade — Charlie Miller and Chris Valasek's Jeep Cherokee remote takeover in 2015 established the playbook. What is significant is how little progress the automotive industry has made since then, and how a major manufacturer in 2026 still shipped a production vehicle with an unauthenticated access path to critical control systems.

The Real Threat Model Isn't the Researcher

Hreszczuk is a professional who demonstrated responsible disclosure through journalism. The actual threat model is far darker. An unauthenticated remote entry point means that anyone who discovers it — a state-sponsored actor, an organized criminal group, or a stalker with modest technical skills — gains the same access. The researcher reportedly could track location and access cabin audio. In a vehicle sold globally, that capability at scale constitutes a mass surveillance platform, not a car.

The fact that Hreszczuk, who hacks cars professionally, was surprised by how easy this was tells you everything about the maturity of BYD's security engineering.

What Was Exposed vs. What Was Protected

The uneven security posture is itself instructive. Brakes and cameras had stronger protection; lighting, wipers, door locks, infotainment, location, and cabin audio did not. This suggests BYD applied security controls selectively rather than implementing defense-in-depth across the entire vehicle attack surface. In automotive cybersecurity, the principle should be that any system that can affect driver safety or passenger privacy requires authentication, authorization, and encryption — not just the obviously critical ones.

Killing headlights at night while a vehicle is in motion is a potentially lethal action. Wipers at maximum speed while spraying the windscreen can momentarily blind a driver. Door locks being remotely controlled creates entrapment risk. These are safety-critical systems, not convenience features.

Industry-Wide Implications

What Was Exposed vs. What Was Protected
Regulatory gap: UN R155 and R156 establish cybersecurity requirements for vehicles in many markets, but enforcement and testing rigor vary widely. Vehicles certified under these standards still ship with fundamental flaws.
Data sovereignty: The researcher's question about what BYD or entities with access to BYD's China-based systems could do highlights a concern that extends beyond cybersecurity into national security. Connected vehicles generate enormous volumes of location, behavioral, and audio data.
Supply chain complexity: Modern vehicles integrate components and software from dozens of suppliers. An unauthenticated endpoint could originate from a tier-2 or tier-3 vendor's component that BYD integrated without adequate security validation.
OTA update risk: If an attacker can reach vehicle control systems without authentication, the integrity of over-the-air update mechanisms must also be questioned.

Shield53 Recommendations

For Automotive Manufacturers

  • Mandate authentication on every external-facing endpoint — no exceptions. "Internal" APIs in connected vehicles are external-facing by definition.
  • Implement network segmentation between infotainment, telematics, and safety-critical CAN bus domains. No flat networks.
  • Conduct independent third-party penetration testing before production release, with explicit testing of remote access paths.
  • Adopt a vulnerability disclosure program with bug bounty incentives. If Hreszczuk found this in two weeks, others already have.

For Regulators and Policymakers

  • Require independent security certification for all connected vehicles before market entry, not manufacturer self-attestation.
  • Mandate data localization and transparency requirements for vehicle telemetry, especially for foreign-manufactured vehicles.
  • Establish minimum cybersecurity baselines that explicitly cover remote access, authentication, and safety-critical system isolation.

For Consumers and Fleet Operators

  • Ask manufacturers about their security certifications and vulnerability disclosure practices before purchase.
  • Disable unnecessary connected features if the vehicle allows it, particularly remote cabin audio and always-on location tracking.
  • Monitor for firmware updates and apply them promptly — but recognize that OTA updates themselves can be an attack vector if the update infrastructure is compromised.
  • Fleet operators should demand contractual SLAs for security patching and breach notification from manufacturers.

The connected vehicle market is growing rapidly, with manufacturers competing on software features and connectivity rather than security. Until security becomes a competitive differentiator — or a regulatory mandate with real teeth — we will continue seeing demonstrations like this one. The next researcher may not be as responsible, and the next victim may not be a journalist on a controlled test track.