ABC News reported on 21 September 2026 (opens in a new tab) that Australia has no minimum cybersecurity standards for cars and that new rules are likely years away. In the same report, a security researcher switched off a BYD Shark 6's headlights while the reporter was driving it (opens in a new tab), using access he said had no password. BYD says the first step needed physical access (opens in a new tab), and we give both sides below.
Our view is that a car has become a computer you sit in. The basic network linking its parts has no built-in way to check who is talking (opens in a new tab), and it is not hard to believe that one day an owner will be asked to pay to get a car working again. That last part is a prediction: we could not find a case of it, and we say below where the evidence stops.
This is an editorial: it argues a view that is ours, and every fact under it is linked so you can check it and disagree.
- Minimum car cyber standard in Australia
- None, per ABC (Sept 2026)
- ECUs in a premium car
- Up to 100, per Aptiv
- Sender check on CAN packets
- None, per 2010 research
- Brisbane Toyota thefts alleged
- 60 cars, 7 men charged
- Vic Police estimate, key-cloning device thefts
- More than 10,000 a year
- Ransomware incidents, car industry
- 160 in Q2 2026 (VicOne)
Why a car now counts as a computer
These figures are estimates and supplier claims, not audited counts. In 2009, IEEE Spectrum quoted informatics professor Manfred Broy (opens in a new tab) saying a premium-class car probably contains close to 100 million lines of software code; the same article said, in its own words, that this software runs on 70 to 100 ECUs. An ECU, or electronic control unit, is a small computer that looks after one part of the car. Supplier Aptiv said in 2020 (opens in a new tab) that premium cars can carry up to 150 million lines across as many as 100 ECUs.
Toyota called its new RAV4 the first step toward fully software-defined Toyota vehicles (opens in a new tab), and the software fails the way computer software does. CarExpert reported (opens in a new tab) that Toyota Australia will recall 16,238 Camrys over a software error that may stop the combination meter displaying at startup, with a dealer software update that takes around 60 minutes, though some cars may need to stay longer. One consultancy's tally counts 1,573 vehicle software recalls since 1994 (opens in a new tab), though we could not find a definition of a software recall in it.
We think "computer on wheels" has stopped being a figure of speech. It has bugs and patches, and Toyota says its Arene software platform is built to support over-the-air updates and continuous software improvement (opens in a new tab).
The CAN bus: a shared wire that doesn't ask who is talking
ECUs talk to each other over a network, and a widely used one is CAN, short for controller area network. Bosch began developing it in 1983 and introduced it in 1986, and Mercedes-Benz has used it in its upper-class cars since 1991 (opens in a new tab). We could not find any mention of security in the original design in the history we read; it mentions security only in passing, for the newer CAN XL protocol.
In 2010, researchers from the University of Washington and UC San Diego found that CAN packets carry no authenticator and no source identifier (opens in a new tab), so any component can send to any other. On a real car they disengaged the brakes while it was driving and killed the engine (opens in a new tab). Ken Tindell of Canis Automotive Labs wrote in 2023 (opens in a new tab) that in most cars the receivers simply trust internal messages, and that the weakness is industry-wide. He is chief technology officer of Canis Automotive Labs (opens in a new tab), whose own CAN security products (CAN-HG, CryptoCAN) the post discusses, which is worth knowing.
A fix is known. Tindell recommends cryptographic authentication of messages (opens in a new tab), and the authors of a 2025 paper call AUTOSAR's SecOC the foundational mechanism for securing in-vehicle communication (opens in a new tab). They say it has been used for over a decade in hundreds of millions of automotive systems. The abstract gives no source for that figure, we could not find an independent count, and two of the authors work for Bosch and NXP, which supply automotive hardware and software, while the paper proposes a competing approach for CAN XL.
Our reading: CAN grew up assuming that whatever was on the wire belonged there. That is a poor assumption once the wire has infotainment, radios and a diagnostic socket attached.
What has already happened: demonstrated, and exploited
Researchers showing something is possible is not the same as criminals doing it, so we keep the two apart.
Demonstrated by researchers
- Miller and Valasek published research in August 2015 (opens in a new tab) showing that remote attacks on an unaltered 2014 Jeep Cherokee and similar vehicles are possible, giving the attacker physical control of some aspects of the vehicle. CISA's advisory (opens in a new tab) says the Uconnect system allowed an unauthenticated connection from other access points on the Sprint network, records a voluntary recall of 1.4 million vehicles, and says Sprint has since blocked the vulnerable port.
- In the ABC test, Fortify Labs' Dan Hreszczuk also locked the doors, followed the car's route and switched on its microphone (opens in a new tab), but could not reach the brakes and cameras, which he called well protected (opens in a new tab). BYD's investigation, as reported by CarExpert (opens in a new tab), calls the cause a software defect in the infotainment software and says controlling the headlights and wipers needed direct access to the CAN bus by tapping the wiring. The same report says BYD has begun a dedicated risk assessment of whether additional measures on CAN message authenticity, integrity and freshness are necessary and technically feasible. On BYD's account, that narrows the remote claim. The same report carries Fortify Labs' reply that the investigation was not about how to gain initial access to the car.
Exploited by criminals
- Tindell describes how (opens in a new tab), in the theft of a security researcher's Toyota RAV4, the bumper had been pulled away and the headlight unplugged. He says it looks like the thieves reached the CAN bus through the headlight connector and sent a spoofed "key validated" message that unlocks the immobiliser, using a device that looks like a JBL Bluetooth speaker. The formal record, CVE-2023-29389 (opens in a new tab), limits it to attackers physically near the car.
- Information Age reported on 8 January 2026 (opens in a new tab) that seven men were charged over the alleged theft of 60 Toyotas around Brisbane. In the same report it describes a CAN bus injector exploit, previously reported in Victoria, that it says can be bought on the black market for between $5,000 and $10,000; it links the two by sequence and does not say outright that the Brisbane men used one. A Queensland Police update (opens in a new tab) on what appears to be the same case alleges the syndicate stole 60 vehicles, targeting specific Toyota models including LandCruisers and Prados, and we could not find any mention of the CAN bus in it. These are allegations, and we could not find court outcomes.
- The Nightly reported in August (opens in a new tab) that Victoria Police intelligence estimates more than 10,000 cars a year are being stolen by offenders using devices that clone or mimic car keys, a group the article says includes tools that exploit the on-board diagnostic system, with LandCruiser thefts up from 89 in 2022 to 846 last year. We could not find any mention of CAN injection or malware in the report.
- Malware has reached a car's head unit, its infotainment system. Kaspersky reported on 21 August 2026 (opens in a new tab) what it calls the first documented case of malware found on a car head unit with an infection chain specific to that kind of device: a downloader on DoFun head units, built for ad fraud and a proxy botnet. We could not find an infection count in the report, or any statement that the malware touched driving functions.
Ransomware and pay-to-unbrick: what is documented, and what we could not find
Ransomware locks a system until the victim pays. Against the car industry it is documented: VicOne, a security vendor, counted 160 ransomware incidents (opens in a new tab) in the second quarter of 2026, led by logistics and transport firms (64), then suppliers, dealers and manufacturers. We could not find any statement in its report that any hit individual vehicles or owners. Upstream Security says ransom-related incidents more than doubled in 2025 (opens in a new tab) to 44% of the 494 public incidents it counted; we could not find a definition of the term, or a count of incidents hitting individual vehicles, in the report.
Nearest to our scenario are owners being asked to pay. A Russian dealer said in mid-2025 (opens in a new tab) that fraudsters were taking over Li Auto owners' app accounts and demanding about 250,000 rubles on average, and that it had re-registered 47 accounts in the past month, some of them compromised; we could not find a police or manufacturer statement behind it. Upstream's own write-up (opens in a new tab) of what appears to be the same episode, which names a Chinese maker rather than Li Auto, says it involved no malware and no coordinated cyberattack: whoever held the phone number the app was registered to controlled the car's account, and the cause was grey-market imports whose app could only be registered with a Chinese phone number.
The nearer precedent for paying to get a car's functions back comes from manufacturers, not criminals. In late 2019 Tesla remotely removed Enhanced Autopilot and Full Self-Driving from a used Model S that a third-party dealer had bought at a Tesla auction and sold on. The Next Web reported (opens in a new tab) that the new owner says Tesla offered to sell the features back to him and that they were reinstated after media attention; the invoice said the customer had not purchased the software, and the article says Tesla had issued no official statement. Electrek reported (opens in a new tab) that an over-the-air update in October 2025 left some Jeep Wrangler 4xe plug-in hybrids bricked and towed to dealers, with Stellantis recalling 24,238 vehicles. Tesla's removal was a company decision and the Jeep failure a software error, not attacks. In our view they show what an extortionist would need: a server that can change what a car does, and an owner who cannot fix it in the driveway.
What we could not find is the scenario itself: a documented case of ransomware on a car's own computers that locked the car until the owner paid. A talk titled "AutoSec 2020 - Ransomware Targeting Automobiles" (opens in a new tab) (page last updated September 2023) describes testing a QNX-based car infotainment system. The authors found an unauthenticated debug service that allowed arbitrary code to run, and used a fork bomb to exhaust the system's resources, arguing that ransomware attacks are viable on automotive platforms. The page does not show working ransomware, and says no ransomware had been seen in the wild on the automotive surface. In the 2025 and 2026 reports we read we found none either: the vendor counts above do not say they involve individual vehicles, the Kaspersky malware chased ad fraud, and the Russian case was an account takeover. Our view is that it is not hard to believe. In our view the ingredients, remote reach, a maker's server and an app account that controls the car, already exist.
What the rest of the world is doing
The main international answer we found is a pair of United Nations rules. UN Regulation 155 (opens in a new tab) makes type approval depend on the manufacturer running a cyber security management system, and requires it to detect and prevent attacks and monitor vehicles in the field; its threat tables name malicious CAN messages and diagnostic-port dongles (opens in a new tab). UN Regulation 156 (opens in a new tab) covers software updates. Australia is listed on the UN treaty register as a participant (opens in a new tab) in R155, alongside the EU, Japan, South Korea and the UK. Heavy Vehicle Industry Australia reported (opens in a new tab) that the infrastructure department began consulting in April 2026 on adopting both as Australian Design Rules, so on that reporting neither is yet one here, and the department's drafts, ADR 115 and 116, drew a call from the association to pause for an impact analysis (opens in a new tab). The federal smart-device security standard, as made in 2025, excludes road vehicles and their components (opens in a new tab).
The country worth a closer look is the United States, because it has done two different things. NHTSA's 2022 guidance is, in the agency's words, voluntary and non-binding (opens in a new tab), and the notice says it does not have the force and effect of law and is not a regulation, though it recommends that critical safety messages on non-segmented communication buses should employ a message authentication method to limit the possibility of message spoofing. The Commerce Department's connected-vehicles rule (opens in a new tab), published in January 2025, restricts transactions involving connected-vehicle technology from persons tied to certain foreign adversaries, on a finding that such technology poses an undue or unacceptable national-security risk because it could enable them to exfiltrate sensitive data and remotely access and manipulate vehicles. The software prohibitions apply to vehicles from model year 2027 and the hardware prohibitions to vehicles from model year 2030, or to hardware not tied to a model year that is imported from 1 January 2029, according to the rule's text (opens in a new tab) (we have not checked for later amendments). In our reading, that is a supply-chain measure aimed at particular countries' technology, not a standard for how well a car's network defends itself. Our reading of the whole picture: the US has a binding rule on who supplies connected-vehicle software and communications hardware and a voluntary one on how the wiring is defended, and Australia, on the ABC's account (opens in a new tab), has no minimum standard yet.
The honest case against us
Here is the strongest counter-evidence.
- Several of the best-known demonstrations were researcher work that was fixed. Tesla said it pushed an over-the-air fix within 10 days of learning of the bugs (opens in a new tab) that Tencent's Keen Security Lab researchers used in a 2016 remote brake demonstration on a Model S, and Subaru patched a remote-control flaw within 24 hours (opens in a new tab). NHTSA's follow-up investigation into the Uconnect recall (RQ15-004, opened July 2015 and closed January 2016), as summarised by CarComplaints (opens in a new tab), identified 30 complaints or field reports, 26 of them filed after a magazine article, and found no confirmed incidents of hacking in the records it reviewed.
- Upstream's count puts most incidents on servers, not the CAN bus. WardsAuto reports (opens in a new tab) that, of 494 publicly reported incidents in 2025, 67% involved telematics and cloud systems as attack vectors. Sam Curry's January 2023 write-up of research done in 2022 (opens in a new tab) covers web, API and back-end flaws across many automakers and vendors, including a Spireon flaw that, per the authors, could let an attacker send commands to an estimated 15.5 million devices (mostly vehicles); we could not find any report of malicious exploitation in it. The RAV4 thefts Tindell describes need hands on the car, as the CVE record (opens in a new tab) says.
- Key theft in burglaries is still significant. Reporting on the NMVTRC's campaign, Insurance News said (opens in a new tab) that in up to a third of 2019 residential burglaries in major capital cities where a car was stolen, the keys were the only contents stolen. Toyota Australia told CarExpert that, as at the article's 7 September 2026 publication, it was not aware of any thefts using sophisticated devices in Australia (opens in a new tab) on the range the new immobiliser is built for. That is a manufacturer's own statement.
- The rules are arriving. We could not find a published study showing whether UN R155 has cut incidents, and an SAE paper (opens in a new tab) says there are no uniform product-level criteria for approving against it.
- Remote reach helps owners. Tesla temporarily unlocked extra battery capacity (opens in a new tab) for owners in the Hurricane Irma evacuation area in Florida in 2017, and an Australian recall of 7,301 2025 Model Ys for a window-protection software fault is being fixed by an over-the-air update (opens in a new tab).
We would sharpen our own view in one place. It is tempting to say simple cars are safe and complex ones are not. CAN is not an EV feature: Mercedes-Benz has used it in upper-class cars since 1991 (opens in a new tab), and the CAN in Automation group says almost every new passenger car made in Europe has at least one CAN network. A car with no radio link can still be stolen by someone standing at it. What connectivity adds is reach. NHTSA's follow-up said Uconnect radios not included in the recalls were not equipped with built-in cellular access or short-range wireless communication (opens in a new tab) and did not contain the vulnerabilities the recalls addressed. In our view, one flaw in a server, an app or an update can touch a whole fleet; the scale we have in mind is Spireon's estimated 15.5 million devices (opens in a new tab) and the Jeep recall's 1.4 million vehicles (opens in a new tab). A simple, unconnected car is exposed to local thieves, not to fleet-wide remote failure. That is our sharper argument: connectivity and over-the-air control are what turn one fault into a fleet-wide event, and it is why we keep arguing for simple, repairable, owner-controlled machinery.
Watch this space
Our prediction, and it is only that: the first widely reported case of a car held to ransom is more likely to arrive through a maker's server, an app account or a head unit than through a worm racing along a CAN bus. The Li Auto case above is the pattern: no malware on the car, but someone else controlled the account. We would watch three things: whether Australia's draft ADR 115 and 116 get a start date or stall; whether vendors such as VicOne and Upstream start reporting ransomware against individual vehicles separately from companies; and whether CAN message authentication appears in the specifications of cars sold here, now that BYD says it is assessing whether additional CAN message authenticity measures are necessary and feasible (opens in a new tab). A few years of enforced rules and close to no vehicle-level incidents would change our mind, and we would say we were too gloomy.
What it means if you're buying or selling in Australia
Electronic theft is a live risk in Victoria, where police intelligence says key-cloning and similar devices feature in up to 40 per cent of vehicle thefts (opens in a new tab). Toyota Australia's secondary immobiliser, a Toyota Genuine Accessory for the LandCruiser 300 Series and Prado 250 Series, costs $1,735 fitted (opens in a new tab), with installation taking about five hours, and Toyota describes it as an additional layer of vehicle-start authentication. Our guide to car theft in Australia (opens in a new tab) covers the electronic methods and what to do if your car is stolen.
If you are buying a connected used car, ask whether its recalls and software updates have been done; the Camry fix we mentioned is quoted at around 60 minutes at a dealer (opens in a new tab), and Toyota says some cars may need to stay longer. If you are selling, sign out of the car's app and remove your account and phone before handover. The Russian lockouts Upstream describes, which appear to be the Li Auto case, turned on who controlled the phone number behind the account (opens in a new tab), so treat that as a principle, not a local risk.
The expensive mistake is trusting a late-model car's factory security alone, when Victoria Police recommend adding an OBD port lock, a steering-wheel lock or an immobiliser (opens in a new tab).
Cover photo: OBD-II connector (opens in a new tab) by Alain Van den Hende, licensed CC BY-SA 4.0 (opens in a new tab), via Wikimedia Commons.
Related
- Toyota is recalling 8,521 electric C-HRs for a software error, and the fix can't be sent over the air (opens in a new tab) - the dealer-only software fix, and who holds the keys.
- When the computer fails: a newer kind of breakdown (opens in a new tab) - software faults without a broken part.
- Australia's repair information scheme, three years on (opens in a new tab) - security gateways, R155 and who can repair what.
FAQs
Can a car get ransomware?
We could not find a documented case of ransomware on a car's own computers locking the car until the owner paid. Ransomware is documented against the car industry, with VicOne counting 160 incidents in the second quarter of 2026 (opens in a new tab), but we could not find any statement in its report that any hit individual vehicles. The closest owner-level case we found, app-account lockouts of Chinese-brand cars in Russia that appear to be the Li Auto episode, involved no malware, according to Upstream's own write-up (opens in a new tab), which does not name the maker. Our view is that car ransomware is not hard to believe, but it remains a prediction.
What is the CAN bus?
CAN, short for controller area network, is the shared network that lets a car's ECUs talk to each other. Bosch introduced it in 1986 and Mercedes-Benz has used it in upper-class cars since 1991 (opens in a new tab). Researchers found in 2010 that its packets carry no authenticator and no source identifier (opens in a new tab). Message authentication exists, and the authors of a 2025 paper call AUTOSAR's SecOC the foundational mechanism (opens in a new tab) for it, but we could not find an independent count of how many cars use it.
Can my car be hacked?
Researchers have shown remote attacks on specific models, such as a 2014 Jeep Cherokee (opens in a new tab), and several cases we read were reported fixed. A security researcher describes CAN injection being used to steal Toyota RAV4s (opens in a new tab), and Information Age (opens in a new tab) describes a CAN bus injector exploit in its Brisbane report; the RAV4 method needs physical access to the car. In Victoria, police intelligence estimates more than 10,000 cars a year (opens in a new tab) are stolen using devices that clone or mimic keys. NHTSA's reviewers found no confirmed hacking incidents (opens in a new tab) in the records they reviewed in the Jeep case. We cannot tell you about your car in particular.
Are older cars safer?
It depends on the risk. NHTSA's follow-up said Uconnect radios not included in the Jeep recalls were not equipped with built-in cellular access or short-range wireless communication (opens in a new tab), so a car without a radio link lacks that remote route. But Mercedes-Benz has used CAN in upper-class cars since 1991 (opens in a new tab), and a car with no radio link can still be stolen by someone at the car. Our view is that connectivity and over-the-air control, rather than age or engine type, decide whether one fault can reach a whole fleet.
Does Australia have rules for car cybersecurity?
ABC reported in September 2026 (opens in a new tab) that Australia has no minimum cybersecurity standards for cars. Heavy Vehicle Industry Australia reported that the infrastructure department began consulting in April 2026 on adopting UN Regulations 155 and 156 as Australian Design Rules (opens in a new tab), with drafts ADR 115 and 116 and the association asking for a pause for an impact analysis (opens in a new tab). The federal smart-device standard excludes road vehicles (opens in a new tab).
