Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Remote Hack of BYD Shark 6 Demonstrates Unauthenticated Access to Vehicle Controls

Researchers remotely accessed a BYD Shark 6 without any password, taking control of doors, lights and infotainment. The incident underscores the need for auditable access‑control evidence in connected‑car programs.

LiveThreat™ Intelligence · 📅 September 21, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

Remote Hack of BYD Shark 6 Shows Unauthenticated Access to Vehicle Controls

What Happened – Researchers from Fortify Labs remotely accessed a BYD Shark 6 electric SUV without any authentication, taking control of doors, infotainment, lights, and wipers. The demonstration, conducted over two weeks, proved that a simple keystroke could lock doors, blast music, and toggle headlights while the vehicle was in motion.

Why It Matters for Trust & Control Assurance

  • This scenario is a textbook case of why continuous access‑control monitoring and evidence of authentication enforcement are essential in any connected‑device program.
  • A robust control‑assurance framework provides auditable proof that authentication mechanisms are in place, tested, and continuously verified – the exact evidence needed to demonstrate due diligence to regulators or partners.

Who Is Affected – Automotive manufacturers, telematics service providers, and any organization delivering connected‑car services.

Recommended Actions

  • Map the lack of authentication to the “Access Control” objective in your control‑assurance program and collect evidence of credential enforcement (e.g., MFA, token validation).
  • Deploy continuous monitoring of remote‑access interfaces and integrate logs into a central audit repository for real‑time assurance.

Technical Notes – The entry point was an unauthenticated API exposed by the vehicle’s telematics module. No password or token was required, allowing full control of non‑safety‑critical functions (doors, lights, infotainment). Brakes and cameras remained protected by stronger safeguards. Source: https://securityaffairs.com/199460/hacking/a-byd-shark-6-hack-shows-the-risks-of-connected-cars.html

📰 Original Source
https://securityaffairs.com/199460/hacking/a-byd-shark-6-hack-shows-the-risks-of-connected-cars.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →