Banned Dahua Cameras Turn Up in Leapmotor’s 6-Cam EV [2026]

Australians have bought Chinese-made electric vehicles in record numbers over the past two years, drawn by prices that undercut legacy brands by thousands of dollars. On September 21, 2026, an ABC News investigation gave those buyers a reason to look twice at what is riding along with them. According to ABC News, camera hardware made by Dahua Technology, a manufacturer banned from Australian government and Defence sites since 2023, has been found inside Leapmotor electric vehicles now sold to ordinary consumers.

The report, produced as part of ABC’s Four Corners program under the title “Asleep at the Wheel,” lands the same week ABC also detailed a separate hack of a BYD Shark 6 ute by a Canberra-based security researcher. Together with a May 2026 warning from Australia’s domestic spy agency ASIO to members of parliament, the reporting paints a picture that outlets including The Eastern Herald and several Australian mastheads have converged on: a fast-growing category of consumer hardware, the connected car, has outpaced the country’s ability to regulate what it can see, hear, and transmit.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What ABC News found inside the Leapmotor

The central finding, as reported by ABC News, is straightforward and uncomfortable: a company whose surveillance cameras were pulled out of Australian government buildings on national security grounds is now supplying camera modules fitted inside a car sold in ordinary dealerships. The Leapmotor C10, one of the vehicles named in the investigation, carries six cameras providing a 360-degree view of both the vehicle’s surroundings and its interior, according to the ABC report.

Dahua’s cameras were removed from Australian Defence and other government sites starting in 2023 after security agencies flagged them as a risk, a decision that followed similar bans in the United States and the United Kingdom on Dahua and Hikvision equipment in sensitive facilities. ABC’s investigation highlights the paradox now sitting in driveways across the country: agencies were cautious enough to strip out Dahua cameras that were not even connected to the internet, yet nothing currently stops a car built with the same manufacturer’s camera hardware from being driven onto, or parked beside, those same sites.

ABC News reported that Leapmotor did not respond to questions put to it by the Four Corners team. That silence has become part of the story itself, feeding a broader complaint from Australian cybersecurity professionals that vehicle manufacturers face no obligation to explain what their onboard sensors collect, where the data travels, or who can access it remotely.

A second, separate warning: ASIO tells MPs to watch what they say in the car

The Leapmotor camera story did not emerge in isolation. It follows a May 2026 Senate estimates hearing in which ASIO Deputy Director-General Lisa Alonso Love advised members of parliament and public servants against holding conversations that contain sensitive or classified information while travelling in internet-connected vehicles, regardless of where the car was built. Federal officials told that same hearing that more than 30 percent of eligible parliamentary work vehicles are Chinese-built EVs from manufacturers including MG and BYD, according to reporting from Drive.com.au and other outlets covering the hearing.

Former national cybersecurity adviser Alastair MacGibbon, commenting on the broader connected-car risk in ABC’s reporting, described the underlying mechanics plainly: a vehicle equipped with always-on microphones and cameras does not need to be hacked to become a surveillance device, because that capability is built into the product by design. That framing is what separates this story from a conventional data breach. Nobody needs to break in. The sensors are already there, already networked, and already capable of transmitting.

Why this is different from the BYD password story

Readers who followed tech-insider.org’s earlier coverage of the BYD hack will recognize the cast of characters but should not conflate the two stories. That earlier incident centered on a security researcher demonstrating that a BYD Shark 6’s onboard systems could be accessed without a password, a classic access-control failure. The Leapmotor and Dahua story is a supply-chain and hardware-provenance problem: the concern is not that a stranger can break in, but that the camera and microphone hardware already installed at the factory comes from a supplier Australian security agencies have independently judged unfit for government premises.

Put another way, the BYD story is about a lock that does not work. The Leapmotor story is about who manufactured the security camera bolted to the wall, and why that same manufacturer was already banned from the building next door.

The regulatory gap: no minimum cybersecurity standard for cars

Australia currently has no minimum cybersecurity standard that vehicle manufacturers must meet, according to ABC’s reporting. There is no requirement compelling automakers to keep onboard software updated, to disclose what sensor data is collected, or to maintain a formal process for managing cybersecurity risk across a vehicle’s lifecycle. That stands in contrast to markets that have moved on the issue: the United States has debated a Connected Vehicle Security Act, and the European Union has folded connected-vehicle requirements into broader cybersecurity type-approval rules for new models.

The Office of the Australian Information Commissioner, the country’s privacy regulator, confirmed in February 2026 that it was investigating two Asian vehicle manufacturers over potential data-harvesting practices, though the OAIC has not named which companies remain under active review. That investigation runs on a separate track from the ASIO warning and the ABC camera findings, but all three point at the same underlying gap: nobody in the Australian government currently owns the job of certifying what a car’s sensors are allowed to do once it leaves the showroom.

Scale of the problem: how many connected cars are we talking about

The numbers explain why security officials are no longer treating this as a niche concern. Industry projections cited in Australian reporting put the share of new vehicles sold in Australia that will be internet-connected at around 95 percent by 2035, up from a large but less-than-universal share today. Chinese-built EVs, led by BYD and MG, have become some of the best-selling vehicles in the country over the past two years on the strength of price: they routinely undercut comparable Japanese, Korean, and European models by a wide margin, which is the core reason uptake has been so fast.

DevelopmentSourceKey detail
Dahua cameras found in Leapmotor EVsABC News / Four Corners, Sept. 21, 2026Leapmotor C10 carries six cameras for 360-degree interior/exterior coverage
Dahua banned from Defence and government sitesAustralian government policy, effective 2023Ban covered cameras regardless of internet connectivity
ASIO warning to MPs and public servantsSenate estimates hearing, May 28, 2026Advised against sensitive conversations in internet-connected vehicles
Chinese EV share of parliamentary fleetFederal officials, Senate estimatesMore than 30 percent of eligible work vehicles are Chinese-built EVs (MG, BYD)
OAIC investigation into vehicle manufacturersOffice of the Australian Information Commissioner, Feb. 2026Two Asian vehicle manufacturers under review for data-harvesting practices
Projected connected-vehicle share by 2035Industry projections cited in Australian reportingApproximately 95 percent of new vehicles expected to be internet-connected

Not just a Chinese-brand problem

Australian cybersecurity commentators covering the story have been careful to note that the underlying risk is not exclusive to Chinese manufacturers. Any internet-connected vehicle, regardless of country of origin, pairs to smartphones, carries a built-in SIM card, and communicates with a range of external devices and services. Drive.com.au, covering the same set of concerns, pointed out that mainstream non-Chinese automakers collect comparable telemetry and, in some cases, have weaker public disclosure practices than the brands currently under scrutiny. The difference in the Leapmotor case is provenance: it is not merely that the car collects data, but that the specific hardware doing the collecting comes from a supplier Australia has already decided cannot be trusted inside a government building.

That distinction matters for how buyers should weigh the risk. A generic complaint about “connected cars collecting data” applies to nearly every new vehicle on an Australian lot in 2026, electric or not, and is unlikely to change based on the country stamped on the badge. A specific complaint about a named supplier already excluded from Defence sites is a narrower, more actionable claim, and it is the reason this story has drawn attention from national security commentators rather than staying confined to consumer-technology coverage.

How Australia’s response compares with other markets

Australia’s cybersecurity leadership has separately flagged that the country needs what one senior official described as an AI-era early warning system for emerging technology risks, a comment that ABC News tied to the same broader conversation about oversight gaps. That framing extends naturally to connected vehicles: a car that ships with six always-on cameras and a persistent cellular connection is, functionally, an AI-adjacent edge device, yet it is regulated under transport and consumer-safety rules written long before that kind of hardware existed.

MarketApproach to connected-vehicle cybersecurityStatus as of Sept. 2026
AustraliaNo minimum cybersecurity standard for vehicle software or sensorsOAIC investigation open; no binding vehicle cybersecurity law
European UnionCybersecurity requirements folded into vehicle type-approval processApplies to new type-approved models
United StatesConnected Vehicle Security Act debated at federal levelLegislative proposal, not yet enacted nationwide
Australian government sitesHardware-level ban on Dahua and related camera manufacturersIn effect since 2023, applies to fixed installations only

What car buyers are actually being told at the point of sale

Nothing in the current reporting suggests Leapmotor or its dealers are required to disclose the origin of onboard camera hardware to a buyer signing paperwork in a showroom. That is the practical consequence of the regulatory gap described above: a manufacturer whose camera supplier is barred from Defence premises faces no obligation to say so on a window sticker, in a brochure, or during a test drive. Consumer advocates quoted across Australian press coverage of this story have argued that this is the more urgent fix, ahead of any broader debate about foreign ownership of automakers, because it affects every buyer regardless of which brand they choose.

The national security angle: parked outside the wrong building

The specific scenario security officials keep returning to is not a hacker breaking into a car from across the world. It is a parking lot. A vehicle equipped with cameras and microphones that can be activated remotely, parked near a government building or a Defence site for an extended period, can record who enters and exits without needing to breach any network defenses, because the recording capability is a standard feature rather than an exploit. That is the scenario Alastair MacGibbon described in ABC’s reporting, and it is functionally identical to the concern that got Dahua’s cameras pulled off government walls in the first place. The difference is that a wall-mounted camera cannot drive itself to a new location; a car can.

Historical context: this is not Australia’s first CCTV-in-government scare

Australia has been down this road before with fixed-location cameras. Reporting from 2018 and again in 2023 documented Chinese-manufactured surveillance cameras, including Dahua and Hikvision units, installed inside Commonwealth government buildings, prompting a multi-year effort to identify and remove them. That earlier episode is why the 2023 ban exists at all, and it is the reason the Leapmotor finding lands as a continuation of an existing story rather than a brand-new one. What has changed is the form factor: the same category of hardware that took years to physically locate and remove from office buildings is now shipping, by default, inside a consumer product that tens of thousands of Australians are buying every year.

Market impact: will this slow Chinese EV sales in Australia?

It is too early to say whether this story changes buying behavior at scale. Chinese-built EVs have won Australian market share primarily on price, and that price advantage has not disappeared. But the reporting arrives at a moment when political scrutiny of Chinese-made connected devices in Australia is already elevated, following the ASIO warning to parliamentarians and the OAIC’s open investigation. Analysts covering the Australian auto market have noted that political pressure, rather than consumer sentiment alone, is the more likely near-term catalyst for any regulatory response, given that no minimum cybersecurity standard currently exists for manufacturers to be held to.

There is also a timing question specific to this week. The Leapmotor findings landed within days of the separate BYD Shark 6 access-control story, meaning two distinct cybersecurity narratives about Chinese-built vehicles reached Australian headlines almost simultaneously. That clustering effect tends to amplify political attention beyond what either story would generate alone, since it lets critics point to a pattern rather than an isolated incident. Whether that pattern holds up under scrutiny, or turns out to be two unrelated stories that happened to break in the same week, is likely to shape how seriously federal regulators treat the underlying policy gap.

What happens next

Several threads from this story remain open. The OAIC investigation into the two unnamed Asian vehicle manufacturers has not been publicly concluded. Leapmotor has not responded to the questions ABC News put to it about the Dahua-sourced camera hardware. And no federal minister has yet announced a timeline for introducing the kind of minimum cybersecurity standard that ABC’s reporting says is currently absent. Until one of those threads resolves, the practical guidance from security officials remains the same as it was after the May 2026 ASIO warning: treat any internet-connected vehicle as a device that can potentially see and hear, regardless of the badge on the hood.

Predictions: where this story goes from here

  • Expect at least one Australian state or federal body to call for a mandatory disclosure requirement covering the origin of onboard camera and microphone hardware in new vehicles, following the pattern set by the OAIC’s existing manufacturer investigation.
  • Expect Leapmotor and other manufacturers named in similar reporting to face direct questions from Australian consumer-affairs bodies, even without a binding cybersecurity standard forcing a response.
  • Expect the debate to broaden beyond Chinese brands, as commentators keep pointing out that connected-vehicle data collection is an industry-wide practice, not one confined to a single country of origin.
  • Expect government fleet policy, not general consumer regulation, to move first, since agencies can restrict their own vehicle procurement faster than parliament can pass a new cybersecurity law.
  • Expect this story to resurface each time a new Chinese-built EV model launches in Australia, given how closely camera and connectivity questions are now tracked by security reporters at ABC and other outlets.

Frequently asked questions

What did ABC News actually report on September 21, 2026?
ABC News reported that camera hardware from Dahua Technology, a manufacturer banned from Australian government and Defence sites since 2023, has been found inside Leapmotor electric vehicles sold to Australian consumers, including a Leapmotor C10 fitted with six cameras.

Is this the same story as the BYD password hack?
No. The BYD story involved a researcher accessing a Shark 6 ute’s systems without a password, an access-control flaw. This story concerns the origin of onboard camera hardware inside Leapmotor vehicles and its ties to a manufacturer already barred from government premises.

Has Leapmotor responded to the findings?
According to ABC News, Leapmotor did not respond to questions put to it by the Four Corners investigative team.

Does Australia have a cybersecurity standard for connected cars?
No. ABC’s reporting states that Australia currently has no minimum cybersecurity standard requiring vehicle manufacturers to keep software updated or manage cybersecurity risk across a vehicle’s lifecycle.

What did ASIO tell members of parliament?
At a Senate estimates hearing on May 28, 2026, ASIO Deputy Director-General Lisa Alonso Love advised MPs and public servants against holding conversations containing sensitive or classified information while travelling in internet-connected vehicles, regardless of the vehicle’s country of origin.

Is this risk limited to Chinese-made vehicles?
No. Security commentators covering the story have noted that any internet-connected vehicle, regardless of manufacturer or country of origin, can collect and transmit data through built-in SIM connectivity, cameras, and microphones.

What is the Office of the Australian Information Commissioner investigating?
The OAIC confirmed in February 2026 that it is investigating two unnamed Asian vehicle manufacturers over potential data-harvesting practices. That investigation has not been publicly concluded.

How widespread are Chinese-built EVs in Australia’s government fleet?
Federal officials told a May 2026 Senate estimates hearing that more than 30 percent of eligible parliamentary work vehicles are Chinese-built EVs from manufacturers including MG and BYD.

Related Coverage

Sofia Lindström

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles