Connected cars: who can reach them, and what they know about you

A car that can pre-cool the cabin from your phone is useful. The same connection can also tell a manufacturer, and sometimes others, where you are, where you go and what you say in the car.

On 21 September, ABC’s Four Corners put that on national television. The programme, Asleep at the Wheel, showed researchers tracking a BYD Shark 6, listening through its microphone and switching its lights and wipers on and off from a laptop. It’s a good prompt to look at how connected cars are secured, what they collect and what rules apply in Australia.

What the BYD demonstration showed

The researchers, Fortify Labs, later published how they prepared the car. [2] Their brief was to simulate the remote access a manufacturer has to a connected vehicle and show how it could be abused. Finding a way into an untouched car over the internet was not the task. According to Fortify:

  • Someone had physical access to install software on the head unit, which could then be controlled remotely.
  • The lights-and-wipers demonstration used a device physically connected to the CAN bus, the car’s internal network, to stand in for a compromised electronic control unit.
  • The researchers removed the car’s telematics SIM and used their own cellular hotspot and infrastructure. They never touched BYD’s back-end services.
  • No firmware was modified, and they made no attempt to escalate their privileges. [2]

So this was remote control of a car prepared by hand first, which is a different finding from breaking into a stock car from afar. The ABC transcript calls part of the sequence a devised scenario, but the episode left out much of the preparation above, which is why Fortify published its own account afterwards. [1][2] What the demonstration shows is what an actor with manufacturer-level access, or a compromised system that mimics it, could do. It doesn’t show that BYD’s own systems would allow all of it.

There were limits as well. Fortify says security policies and separation inside the head unit blocked access to more sensitive components, including the cameras, and the ABC reports the researcher couldn’t tamper with brakes or steering. [1][2] That describes this one assessment, not every future attack.

The manufacturers responded too. XPeng, whose car Four Corners examined using manufacturer-system access, denies it can remotely immobilise customers’ vehicles. BYD told the ABC that the data it collects is stored in Australia and has not been, and will not be, passed to Chinese authorities. [1] Local storage matters, but it doesn’t say who can administer the service or reach the data remotely.

The Shark 6 is a plug-in hybrid, so strictly not an EV. The issue is connectivity, not the drivetrain.

Three problems, not one

Connected-car stories tend to blur these together:

  • Cybersecurity. Can an unauthorised person get into the car, its app or the services behind it? That depends on the specific flaw and on what the car does to contain it.
  • Privacy. What does the car collect, who receives it, and what may they do with it? A well-secured system can still collect too much.
  • Supply-chain risk. Who controls the software, the update servers and the administrative access, and which country’s laws apply to them?

A demonstration of one says little about the others. The distinction matters because the fixes differ: a patch, a limit on data use, tighter access controls or a procurement rule.

“The car” is more than the car

Kia is the usual example. In 2024, researchers reported flaws in its connected services that allowed remote access to a car’s location and door locks, and exposed owners’ personal details. The weakness was in the online systems, not in a car someone had opened up first. The researchers say it was fixed, and it isn’t a claim about Australian Kias today. [3]

It shows that a connected car now includes servers, dealer tools, mobile apps and account permissions, so securing the dashboard isn’t enough.

It also isn’t a problem peculiar to Chinese brands. There are fair reasons for governments to look at foreign legal obligations and at how much remote access manufacturers hold. But nationality is not a security assessment, and Fortify itself says cars from the US, Europe and the rest of Asia deserve the same scrutiny. [2]

Privacy doesn’t need a hacker

Your regular destinations can show where you work, who you visit and which clinics you attend. Driving behaviour can feed an insurance score. Voice commands and paired phones add more. Not every car collects all of it, but it is hard to find out what yours does.

A 2024 UNSW study of 15 popular connected-car brands in Australia found that owners are sent to an average of three documents, around 14,000 words per brand, to understand the terms. It found vague purposes and broad sharing arrangements. It was a study of policies, not of what each car actually transmits. [4]

The clearest enforcement case is overseas. In January 2026 the US Federal Trade Commission finalised an order settling allegations that General Motors and OnStar collected and sold precise location and driving data without adequate notice and consent. [5] No one broke into anything. The company handled the data itself.

For someone escaping domestic abuse, a connected account that still works can expose their location with no exploit at all. Australia’s Privacy Commissioner has flagged this, along with leftover access and personal data when a car changes hands. [6]

What the rules say

There is no single global connected-car law. As of 30 September 2026:

Europe treats cybersecurity and software updates as part of vehicle approval. UN Regulations 155 and 156 have applied internationally since 2021, and the EU phased them in between 2022 and 2026. [7][8] That doesn’t make a car unhackable, and it doesn’t cover data use.

The US restricts connected-vehicle software and hardware with specified links to China or Russia, phased in from model year 2027 for software and 2030 for hardware. It is US law, not an Australian ban. [9]

Australia has promised national road-vehicle cybersecurity standards in its 2026 Horizon 2 action plan, along with a look at connected-vehicle privacy and data storage. [10] Draft ADR 115 and 116, based on R155 and R156, are the likely vehicle. In August, Heavy Vehicle Industry Australia reported open questions on cost, timing and supplier responsibility. [11] They are not in force, and I found no final start date.

That doesn’t mean Australia has no rules. Manufacturers covered by the Privacy Act already have duties on collection, use, disclosure and security. [6] The open question is whether those duties, their enforcement and the coming vehicle standards are enough.

What owners can do

  • Install legitimate updates. Keep the car’s software, the app and your phone current, and ask about software at servicing.
  • Secure the account. Use a unique password and multi-factor authentication if offered. Review authorised users and linked devices.
  • Check the data settings. Look at analytics, location history, voice services and sharing, and ask what switching each off does, including to safety features.
  • Treat a sale as an access change. When buying or selling, transfer the account, remove old users and digital keys, and clear paired phones and saved destinations. A dashboard reset may not cut off server-side access.
  • Ask before buying. How long will security updates last? Can a previous owner keep access? Who can retrieve location data, and from where?

If tracking or coercive control is a worry, get specialist help before changing settings that might alert an abuser. Fortify points Australians to 1800RESPECT: 1800 737 732. [2]

None of this fixes an insecure back end, an overbroad data policy or a car that no longer gets updates.

What to ask manufacturers

Connected features make cars easier to live with, and they are not going away. The questions worth putting to every brand are specific: how long are cars supported, how are updates protected, who holds administrative access, what data leaves the car and where does it go? A buyer can ask those at the dealership today, and a regulator should be able to check the answers.


Sources

  1. ABC Four Corners, Asleep at the Wheel—programme and transcript, 21 September 2026. Includes the BYD and XPeng demonstrations and manufacturer responses.
  2. Fortify Labs, BYD Shark 6: What wasn’t in the Four Corners episode, 28 September 2026. Researchers’ account of scope, physical preparation, connectivity and limitations.
  3. Sam Curry and fellow researchers, Hacking Kia: Remotely Controlling Cars With Just a License Plate, September 2024. Original disclosure; reports the vulnerabilities were fixed.
  4. UNSW / Katharine Kemp, Modern cars are surveillance devices on wheels with major privacy risks—new report, 1 November 2024. Australian connected-car privacy-policy research.
  5. US Federal Trade Commission, FTC Finalizes Order Settling Allegations that GM and OnStar Collected and Sold Geolocation Data Without Consumers’ Informed Consent, 14 January 2026.
  6. Office of the Australian Information Commissioner, Privacy Commissioner’s remarks to the UNSW connected-cars workshop, 2 May 2025. Existing Australian privacy obligations, data categories and abuse risks.
  7. UNECE, Three landmark UN vehicle regulations enter into force, 5 February 2021. R155/R156 purposes and EU cybersecurity implementation schedule.
  8. European Union, Commission Delegated Regulation (EU) 2022/2236, Article 2. Binding software-update transition provisions, including the complete/completed vehicle distinction.
  9. US Bureau of Industry and Security, Connected Vehicles. Final-rule scope, phased model-year restrictions and authorisation mechanisms; checked against the January 2025 final rule.
  10. Australian Government, Horizon 2 Action Plan, 2023–2030 Australian Cyber Security Strategy, 2026. Commitment to national road-vehicle cybersecurity standards.
  11. Heavy Vehicle Industry Australia, Call for Impact Analysis on Cyber Regs, 26 August 2026. Industry account of draft ADR 115/116 consultation; not a final legal instrument.