Skip to main content

A Norwegian public transit operator drove a brand-new electric bus into an underground mine last year to figure out whether the manufacturer could shut it down from the other side of the world. The mine was chosen deliberately: strip away the cellular signal, isolate the vehicle, and see what happens. What they found in that dark tunnel set off investigations on four continents.

The bus was a Yutong, built in Zhengzhou, China. The operator was Ruter, Oslo’s public transport authority. The answer to their question was not reassuring. The UK’s Department for Transport began working with the National Cyber Security Centre to understand and mitigate any risk after Ruter conducted cybersecurity tests on a new Yutong vehicle and said it identified vulnerabilities in its on-board systems. The mine test wasn’t some fringe experiment. It was the moment a quietly spreading technology problem became impossible to ignore.

Every connected vehicle on every road today shares a version of the same exposure the Ruter tests revealed – including the one sitting in your driveway.

What Ruter Actually Found

During the tests, Ruter found that Yutong had access to the operating systems for software updates and diagnostics, and to the control system for the battery and power supply, via a mobile network SIM card – specifically, a Romanian SIM. When engineers drove the bus into the Franzefoss Mine to block all external signals, they compared it side by side with a three-year-old bus from Dutch manufacturer VDL. Test results showed that Yutong had access to the bus’s control systems for software updates and diagnostics, and “in theory, this could be exploited to affect the bus.”

Ruter’s own report stated: “There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer.” The Dutch VDL bus, by contrast, had no comparable over-the-air update capability at all.

So far, there is no evidence of an actual shutdown or incident – Ruter confirmed no malicious use had occurred – but authorities are warning that stricter security requirements are urgently needed. Yutong responded by saying it “strictly complies with the applicable laws, regulations, and industry standards of the locations where its vehicles operate,” adding that in the EU, vehicle data is stored on encrypted Amazon Web Services servers in Frankfurt and accessible only with customer authorization. The company’s UK and Australian distributors have both stated that software updates in those markets are carried out manually, not remotely.

Intention, however, is not the same as capability. The access channel exists whether it’s used or not.

How Far This Has Spread

The reaction to Ruter’s findings was swift and multinational. Modern EVs from Tesla, Ford, BMW, BYD, and GM all support some form of over-the-air updates, but it was Yutong’s scale that drew the most scrutiny. The company is the world’s largest bus manufacturer by volume, with its vehicles operating across dozens of countries.

The UK’s Department for Transport began working with the National Cyber Security Centre to understand and mitigate the risk that Chinese-made electric buses could be remotely accessed and potentially disabled. In Norway, 850 Yutong e-buses are in operation. In Denmark, public transport operator Movia operates 262 Yutong buses as part of a larger Chinese-built electric fleet.

Yutong has supplied electric buses to Norway, Denmark, and the Netherlands. According to The Register, approximately 700 Yutong-made buses are already in service in the UK, primarily in Nottingham, south Wales, and Glasgow, operated by companies including Stagecoach and First Bus. Australia’s ACT Government launched its own investigation into its Canberra fleet after reports from Europe suggested the vehicles could be remotely disabled.

Alicia Kearns, a British MP who has pressed ministers on Chinese security risks in Parliament, warned that Norway and Denmark had alerted the UK to the existence of what she called “dual-use kill switches” in Chinese-made electric buses – mechanisms built for software updates that could theoretically also be used to bring transport systems to a halt.

The OTA Problem Isn’t Just a Bus Problem

Over-the-air software updates – first introduced by Tesla for the Model S in 2012 – allow remote fixes but also open cybersecurity risks. What began as a way to push bug patches without requiring a dealership visit has since become standard across the entire automotive industry. Modern cars are no longer machines that stay the same after they leave the showroom. Increasingly, they’re becoming software-defined vehicles that receive new features, bug fixes, and security patches wirelessly, much like smartphones.

OTA technology now spans buses, commercial fleets, rail systems, and industrial robots. Cybersecurity analysts warn that the same wireless update channel that adds convenience is the same one that creates exposure. According to CNBC, the automotive industry’s increasing use of over-the-air technology makes it more susceptible to cyberattacks. Gabriel Lim, a senior research fellow at Singapore’s S. Rajaratnam School of International Studies, told CNBC that OTA updates in vehicles represent “a unique national security concern,” adding: “Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about.”

Fleet disruption and data theft pose the most realistic cybersecurity threats in the near term, even if Hollywood-style car takeovers remain unlikely in practice. When not secured properly, OTA update pipelines can become a gateway for data theft, malware injection, vehicle theft, and other malicious activity.

A 2025 connected car security survey from RunSafe Security found that fewer than one in five connected car drivers – just 19% – feel very confident their vehicle is protected from cyberattacks. The survey polled over 1,000 US drivers and fleet managers. Modern vehicles now run on over 100 million lines of code, more than most fighter jets, creating an attack surface that simply didn’t exist when cars were mechanical.

Why the Jeep Hack From 2015 Still Matters

The unease about remotely accessible vehicles isn’t new. In 2015, security researchers Charlie Miller and Chris Valasek demonstrated they could take control of a Jeep Cherokee over the internet while it was being driven on a highway. The pair hijacked the Jeep’s UConnect infotainment system via the car’s cellular network. Once in, they were able to send signals to the car’s computer system, manipulating the brakes, engine, and transmission from a living room. All they needed was the vehicle’s IP address. Fiat Chrysler recalled 1.4 million vehicles as a result, under pressure from the National Highway Traffic Safety Administration.

In October 2025, some Jeep owners found their vehicles had suddenly lost power while driving after a failed OTA update – a reminder that remote access to vehicle systems carries real-world consequences even when the intent is benign. In May 2025, the driver of a Volvo XC90 crashed after an OTA update affected braking functionality.

As over-the-air wireless software update technology spreads rapidly in the auto industry, concerns are growing that vehicle systems could become vulnerable to cyberattacks in ways that go well beyond the Jeep scenario.

The US Legislative Response

The Yutong case has accelerated legislative action in the United States. The Commerce Department finalized rules in January 2025 restricting Chinese-linked software and hardware in connected vehicles, citing the same kind of remote-access risk Ruter’s tests demonstrated.

In 2026, US Senators Bernie Moreno (R-Ohio) and Elissa Slotkin (D-Michigan) introduced the Connected Vehicle Security Act of 2026, a bipartisan bill that would ban Chinese vehicles and connected technologies from US roads entirely. The legislation would prohibit the import, sale, and operation of vehicles manufactured in China or other countries of concern. It would also block the use of connected vehicle software, data systems, and hardware developed or linked to those nations. Restrictions on vehicles and software are set to take effect in 2027, with hardware restrictions following in 2030.

Senator Slotkin described Chinese connected vehicles as “surveillance packages on wheels – fully capable of geolocating individual drivers, collecting full-motion video, and mapping sensitive infrastructure sites, including our military.” The bill drew support from across the American auto industry, including the UAW, General Motors, Ford, Stellantis, Honda, the Alliance for Automotive Innovation, the Teamsters, and the American Iron and Steel Institute.

Read More: The Truth Behind 7 Popular Electric Car Myths

What to Do Now

Any vehicle with a live cellular connection and an OTA update channel has some version of the same exposure the Yutong investigation revealed – the question is who holds the keys, what they’re permitted to access, and how well that access channel is secured. This applies to Chinese-made buses, American-made EVs, and everything in between.

For most drivers, the practical steps are limited but meaningful. Ask your automaker or dealer directly whether your vehicle receives over-the-air updates, and if so, what systems those updates can access. Although experts say the risk of being hacked or of a software update failing is low, drivers should still be aware of what an OTA update entails before installing one. If your car prompts you to install an update, check the manufacturer’s official support page to confirm it’s legitimate before accepting it, particularly if the prompt appears unexpectedly or asks for unusual permissions.

The Bigger Picture for Fleet Operators and Regulators

Fleet managers and procurement officials face a harder task than individual drivers. Movia in Denmark is collaborating with national cyber agencies to review procurement practices, software-update pathways, and strategies for firewalling or SIM-lock removal – though authorities have noted that such actions may terminate important vehicle functions. That trade-off, between convenience and control, is exactly the kind of decision that needs to happen before a bus is purchased, not after it’s already on the road.

The underground mine test in Norway didn’t find a smoking gun. No bus had been shut down maliciously. But it confirmed something the cybersecurity community has been saying for years: protecting a car increasingly means protecting the code running inside it. The remote kill switch cars story isn’t about one manufacturer or one country. It’s about what happens when software-defined vehicles become critical infrastructure, and the rules governing access to them haven’t kept pace with the technology.

AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.

Read More: China Just Photographed Earth’s Mysterious ‘Second Moon’ for the Very First Time