Detection/Alarms/CCTV Australia

The Car Park Is Now Part of the Perimeter: What the Four Corners EV Investigation Found

By
3 Minute Read

A cybersecurity researcher needed two weeks to remotely take control of a ute that's currently for sale in Australia. He didn't need a password to do it. That's the finding at the centre of "Asleep at the Wheel," the Four Corners investigation that aired on 21 September and has since moved from car-industry press into privacy law, and this week into a formal submission to government.

What was actually demonstrated

Independent researcher Dan Hreszczuk, of Fortify Labs, found an access point on a BYD Shark 6 plug-in hybrid ute with no password protection at all. Over two weeks, he used it to remotely operate the door locks, the infotainment system, the wipers and washers, and the cabin microphone while the vehicle was being driven. He also demonstrated location tracking through the same access point. BYD's original privacy policy, which contained broad surveillance language, was quietly replaced after ABC put questions to the company.

Separately, the investigation examined Leapmotor's C10 EV, which comes fitted with six cameras providing 360-degree coverage around the vehicle. Some of those cameras are made by Dahua Technology, the same manufacturer Australia removed from federal government buildings and defence sites in 2023 over concerns about built-in surveillance capability and Dahua's alleged links to human rights abuses. Nobody appears to have been checking for that hardware showing up somewhere other than a building.

A third finding sits on different footing. An insider at Xpeng showed Four Corners the company's ability to remotely access a vehicle's location, speed, steering angle, seat position, occupancy status and braking and acceleration data. Xpeng disclosed the capability itself; it wasn't independently exploited the way the BYD access point was. The company says it cannot remotely disable a vehicle and has never shared Australian customer data with Chinese authorities.

Why a banned camera matters more in a car than in a building

The 2023 Dahua ban was written for a specific problem: government buildings and defence sites with fixed surveillance infrastructure that someone could audit. It assumed the risk lived in ceilings and server rooms. It didn't anticipate the same hardware arriving pre-installed in a consumer product that then gets driven into a government car park, parked outside a hospital, or left overnight near a data centre.

Alastair MacGibbon, a former national cybersecurity adviser, put the scale of that gap in blunt terms. Enough connected vehicles, parked in enough places, "establish a mesh of video and electronic knowledge that is granular and when taken in totality is almost a near-perfect real-time picture of Australia." He's also flagged that microphones in these vehicles could be activated remotely without the owner knowing.

Home Affairs Minister Tony Burke has acknowledged "some restrictions" already apply to connected vehicles at sensitive sites. The fleet-level equivalent of the building policy, something that treats a car the way a security team already treats a laptop or an access card, doesn't exist yet.

What's actually changing

The federal government has draft Privacy Act legislation addressing connected vehicles open for public feedback right now. The Australian Automotive Aftermarket Association lodged a formal submission on 22 September calling for mandatory consent before vehicle data is collected, full deletion rights, manufacturer accountability for security across a vehicle's operational life, and secure diagnostic access for independent repairers. The Office of the Australian Information Commissioner is separately investigating Toyota and Hyundai over connected vehicle data practices, confirmed back in April.

Shadow Defence Minister James Paterson has called a connected EV from China "the highest-risk product in the marketplace," a political line, not a technical one. The more useful industry voice here is the Australian Automotive Dealer Association's James Voortman, who has called for "greater collaboration between automakers, regulators, security agencies and other stakeholders," on the basis that "Australians deserve clear answers."

What this means for a fleet right now

Organisations running Chinese-manufactured EVs, whether corporate, government, logistics or as part of a broader mixed fleet, now have a category that used to be a compliance checkbox for buildings and networks extending to vehicles too. Two practical starting points, ahead of whatever the Privacy Act reform ultimately requires. Check what cameras and connectivity hardware are actually fitted to any Chinese-made vehicle already in the fleet, the same way a building's CCTV estate gets audited. Then treat vehicle telemetry, location, audio, video, as a data category that needs the same access controls, retention limits and incident response plan as anything else the organisation collects.

The BYD exploit and the Dahua hardware were both demonstrated in practice, not alleged in a press release. Fleet and facilities security teams have working proof to act on already.


ICYMI Australian News: WA Charges Highlight a New Software Supply Chain Threat 

Register for The Security Event Australia happening  25-26 November 2026, MCEC Melbourne

 

Subscribe to The Security Briefing for monthly updates!

Karyee Lee

Karyee Lee

Karyee Lee is a Content Executive for the Safety & Security Event Series, contributing to the digital content strategy and audience engagement across a diverse range of online platforms through The Security Briefing and Workplace Unplugged. Passionate about bringing industry professionals together, Karyee develops engaging digital content and supports initiatives that keep industry audiences informed and connected.

Author