Remote Hack of BYD Shark 6 Shows Unauthenticated Access to Vehicle Controls
What Happened – Researchers from Fortify Labs remotely accessed a BYD Shark 6 electric SUV without any authentication, taking control of doors, infotainment, lights, and wipers. The demonstration, conducted over two weeks, proved that a simple keystroke could lock doors, blast music, and toggle headlights while the vehicle was in motion.
Why It Matters for Trust & Control Assurance
- This scenario is a textbook case of why continuous access‑control monitoring and evidence of authentication enforcement are essential in any connected‑device program.
- A robust control‑assurance framework provides auditable proof that authentication mechanisms are in place, tested, and continuously verified – the exact evidence needed to demonstrate due diligence to regulators or partners.
Who Is Affected – Automotive manufacturers, telematics service providers, and any organization delivering connected‑car services.
Recommended Actions
- Map the lack of authentication to the “Access Control” objective in your control‑assurance program and collect evidence of credential enforcement (e.g., MFA, token validation).
- Deploy continuous monitoring of remote‑access interfaces and integrate logs into a central audit repository for real‑time assurance.
Technical Notes – The entry point was an unauthenticated API exposed by the vehicle’s telematics module. No password or token was required, allowing full control of non‑safety‑critical functions (doors, lights, infotainment). Brakes and cameras remained protected by stronger safeguards. Source: https://securityaffairs.com/199460/hacking/a-byd-shark-6-hack-shows-the-risks-of-connected-cars.html