For years, the electric-vehicle industry has focused on battery capacity, range, charging speed, and fire safety.

But a recent case in India raises a different question:

What happens when the battery is physically safe, but digitally vulnerable?

A Small Feature, a Serious Risk

In July 2026, the Indian government disclosed a cybersecurity concern involving the Battery Management Systems used in some low-cost electric rickshaws.

According to the government, certain BMS units contained Bluetooth modules with default credentials, or no access credentials at all.

This could allow unauthorized users to connect through publicly available mobile applications, change battery settings, or even interrupt battery discharge.

In the worst case, that could cause a moving vehicle to suddenly lose power.

Indian authorities identified the relevant applications, requested their removal from app stores, and issued an industry advisory addressing the vulnerability.

The reported case involved electric rickshaws. But the lesson is much broader.

What Is a BMS?

A Battery Management System, or BMS, monitors and controls an electric vehicle's battery.

Among other things, it can manage:

  • Voltage and current
  • Battery temperature
  • Charging and discharging
  • Cell balancing
  • State of charge
  • Fault protection

A well-designed BMS is essential to battery performance and safety.

Many modern systems also offer Bluetooth connectivity, mobile diagnostics, remote data access, and configurable settings. These functions can make maintenance easier, but every new connection can also create a new point of vulnerability.

"Smart" Does Not Automatically Mean "Secure"

A Bluetooth-enabled BMS may look like a valuable product feature.

But importers and vehicle brands should ask deeper questions:

  • Does every device have a unique password?
  • Can the default credentials be changed?
  • Which settings can users or technicians modify?
  • Can unauthorized applications connect to the system?
  • What happens if communication is interrupted?
  • Is there a safe operating mode when abnormal access is detected?
  • Who is responsible for software and firmware updates?

These questions apply not only to electric three-wheelers.

Electric motorcycles, delivery vehicles, passenger cars, commercial vehicles, energy-storage systems, and other battery-powered products all depend on electronic control systems.

As vehicles become more connected, cybersecurity becomes part of vehicle safety.

The Last Line of Defence Cannot Be the Local Mechanic

There is another practical reality that the industry should acknowledge.

Low-cost electric vehicles are often assembled, maintained, and repaired in highly price-sensitive markets. The people doing this work may receive limited product-specific training, especially when vehicles, batteries, controllers, and diagnostic applications come from multiple suppliers.

Their training usually focuses on immediate and visible problems:

  • Replacing damaged components
  • Repairing wiring
  • Diagnosing charging failures
  • Restoring vehicle operation
  • Reducing customer downtime

Cybersecurity, software permissions, password management, and firmware integrity are far less likely to be part of routine workshop practice.

This is not a criticism of local technicians. It is a reminder that they cannot reasonably be expected to correct security weaknesses that were built into the product before it reached them.

If a BMS leaves the factory with an open Bluetooth connection, a universal password, or unrestricted access to safety-critical settings, a warning in the service manual is not enough.

Security must be designed into the product, not added later in the repair shop.

The Cheapest Component Can Create the Most Expensive Problem

In a price-sensitive market, it is tempting to compare vehicles mainly by battery capacity, motor power, range, and purchase price.

But a low-cost component with weak access control can create consequences far greater than its original value:

  • Safety incidents
  • Product recalls
  • Warranty claims
  • Reputational damage
  • Regulatory intervention
  • Loss of consumer confidence

For an importer or private-label brand, these risks do not remain at the factory.

They travel with the vehicle, and ultimately appear under the local brand's name.

Responsibility Must Begin Upstream

Training service technicians is still important, but training alone cannot solve a problem created by product architecture.

The stronger response must begin at two levels.

At the production level:

  • Unique credentials should replace universal default passwords.
  • Safety-critical settings should have restricted access.
  • Wireless functions should be disabled when they are unnecessary.
  • The system should fail safely when abnormal access is detected.
  • Software and firmware responsibilities should be clearly assigned.
  • Cybersecurity checks should be included in supplier approval and vehicle validation.

At the regulatory level:

  • Safety standards should address connected battery and control systems.
  • Manufacturers and importers should document software access and update mechanisms.
  • Testing should consider unauthorized access, not only electrical and mechanical failure.
  • Responsibility for vulnerabilities, recalls, and corrective updates should be clearly defined.

Without these upstream controls, the market is effectively asking local workshops and vehicle owners to manage risks they may not even know exist.

A New Definition of Vehicle Safety

The Indian case should not be used to suggest that all electric vehicles, or all BMS products, are vulnerable.

It is a warning about what can happen when connectivity is added without sufficient security controls.

At NAVERO MOBILITY, we believe vehicle development must look beyond visible specifications. Batteries, motors, controllers, software, documentation, supplier accountability, and service readiness all contribute to the reliability of the finished product.

The next generation of electric vehicles will not be judged only by how far they can travel on one charge.

They will also be judged by how safely they manage the data, permissions, and software behind every journey.

In a connected vehicle, cybersecurity is no longer just an IT issue. It is a manufacturing, regulatory, and road-safety issue.

Source: Press Information Bureau, Government of India - Cybersecurity Vulnerabilities in E-Rickshaw BMS and Role of Certification Agencies.

Originally published on LinkedIn: Can a Smartphone Stop an Electric Vehicle?

Cover photo by Brad Rucker on Unsplash.