Engineers drove two electric buses into an abandoned mine outside Oslo last year to find out whether a manufacturer could shut one down from thousands of miles away. One of them could. Ruter, the transit authority that runs half of Norway’s public transport, says the access ran straight through the same over-the-air (OTA) software updates that the bus’s manufacturer, Chinese bus maker Yutong, pushes to its vehicles by cellular connection.
A decade earlier, a similar demonstration on a Jeep Cherokee forced Detroit’s first cybersecurity recall and helped write the global rulebook that now governs vehicle software. That rulebook has never reached a Chinese-built bus running through Oslo, a Danish transit fleet, or a fleet in Canberra, and regulators in four countries are now racing to catch up.
A Bus Rolls Into an Abandoned Mine Outside Oslo
The test took place at Franzefoss, an underground facility near Sandvika chosen because its rock walls block outside signals. Ruter and its partners nicknamed the exercise the Lion Cage. Cybersecurity specialists from Telenor Group and the University of South-Eastern Norway ran two buses through it: a brand new Yutong model and a three-year-old bus from Dutch manufacturer VDL, picked because together they represent the range of vehicles in Ruter’s fleet.
The comparison turned up one clear difference. Yutong’s bus carried a cloud-based connection that gave the manufacturer direct digital access to software updates and diagnostics, including the bus’s battery and power management systems. Ruter’s own report put it plainly: “This bus can be stopped or rendered inoperable by the manufacturer.” The VDL bus, which cannot take updates over the air at all, had nothing comparable for anyone to reach. Testers also found hidden Romanian SIM cards inside the vehicles and removed them.
Ruter published its full account of the bus security testing alongside a pledge to tighten future procurement contracts. The company stressed it found no evidence the access had ever been misused, only that it existed.
It’s unlikely these buses would ever be misused, but we must take the risk seriously.
Bernt Reitan Jenssen, Ruter’s chief executive, made that case publicly once the results came out.
Yutong Calls the Scenario Technically Impossible
Yutong pushed back hard. Speaking to a German newspaper, the company called the remote shutdown scenario “technically impossible” and said its telematics unit, the onboard hardware that handles connectivity, has no physical link to steering, propulsion or braking. Vehicle data collected in Europe sits on Amazon Web Services servers in Frankfurt, according to the company, and any update touching comfort or interface features requires the local operator’s explicit approval first.
Alastair MacGibbon, a former head of the Australian Cyber Security Centre, takes a different view. He has argued publicly that the exposure has little to do with which country builds a given bus. Any connected vehicle, electric or not, hands its manufacturer some level of reach into cameras, microphones and location data, in his assessment, and he has urged Canberra to restrict Chinese-made electric vehicles from government sites regardless of who is right about intent.
Ruter’s own investigators land somewhere in between. “The results are better than feared,” the operator told cybersecurity outlet Dark Reading, adding that the buses carried no purpose-built backdoors or hidden surveillance tools. But the underlying openness was real enough to act on. “The most relevant risks we found are linked to digital connectivity for software updates and diagnostics on the newer, more connected bus model, not to the fact that it is electric, and not to any hidden surveillance capability,” Ruter representatives said.
- Ruter – says the update channel gives the manufacturer a real, if untested, ability to disable a bus, and wants stricter rules regardless of who builds the vehicle.
- Yutong – calls a remote takeover technically impossible because its telematics hardware is not wired into steering, propulsion or braking.
- Alastair MacGibbon – argues the exposure applies to any connected or electric vehicle and has nothing to do with the manufacturer’s home country.
Why Was Only One Bus Vulnerable
The difference had nothing to do with where either bus was built. It came down to whether a bus could take software updates over the air at all. Ruter’s newer Yutong model gave its manufacturer a live channel into core vehicle systems. The older VDL bus, without that feature, simply had nothing similar for anyone, manufacturer or hacker, to reach.
Testing turned up four specific gaps:
- The cloud-based update channel reached into battery and power management, not just entertainment or comfort features.
- The Controller Area Network (CAN), the internal wiring that lets a bus’s components talk to each other, carried no authentication or encryption, according to Dark Reading’s review of Ruter’s unpublished full report.
- Hidden Romanian SIM cards, found during the mine tests, offered an extra, unexplained path onto the network.
- A separate flaw in the Chinese software platform Yutong uses to distribute updates turned up during the review; it has since been patched.
These findings do not describe a hidden weapon built for one government’s benefit. They describe an architecture, adopted for cost and convenience, that nobody had stress-tested until a bus rolled into a mine.
The Jeep Hack’s Rulebook
This pattern is not new. In July 2015, security researchers Charlie Miller and Chris Valasek showed Wired magazine how they could reach a 2014 Jeep Cherokee through its cellular connection, seize its entertainment system, and from there send commands to its transmission and brakes, all from a laptop far from the vehicle. Fiat Chrysler recalled roughly 1.4 million vehicles within days, one of the first cybersecurity-driven recalls of its size. The National Highway Traffic Safety Administration (NHTSA) opened its own investigation, and Senator Ed Markey publicly criticized Chrysler for “knowing about this security gap for nearly nine months” before acting.
That episode became the reference case for a new rulebook. UNECE, the United Nations Economic Commission for Europe, adopted Regulations 155 and 156, which entered into force in 2022 and now require any manufacturer selling in the European Union, the United Kingdom, Japan or South Korea to certify both a cybersecurity management system and a software update management system before a vehicle earns type approval. Regulators can also require that owners be told when an update happens and what it changed, both before and after the fact.
Buses fall into a grayer part of that framework than passenger cars do, which is part of why Ruter, Denmark’s Movia and Transport Canberra are each writing their own extra procurement rules instead of leaning on one shared standard.
Denmark, the UK and Australia Follow Norway’s Lead
Norway’s findings did not stay in Norway. Denmark’s civil protection and emergency management authority opened its own review within days. It has not recorded any incidents involving Movia, the country’s largest public transport operator, but it has flagged connected subsystems, cameras, GPS and onboard sensors, as areas worth watching.
In the United Kingdom, the Department for Transport is working with the National Cyber Security Centre to examine the same category of risk across the country’s own connected bus and vehicle fleets.
Australia came next. Transport Canberra placed its own Yutong order in 2023, and the territory government is now working with VDI, the buses’ sole Australian distributor, to check whether the Norwegian and Danish findings apply locally. VDI has said Australian updates are typically installed at service centers rather than pushed remotely, a practical difference from the cloud-based setup Ruter’s testers found in Norway.
| Country / Operator | Yutong Buses Involved | Response So Far |
|---|---|---|
| Norway (Ruter) | About 850 of 1,300 electric buses nationwide | Removed hidden SIM cards; tightening procurement rules |
| Denmark (Movia) | 262 of 469 Chinese-built buses | Civil protection authority reviewing connected subsystems |
| United Kingdom | Fleet size not yet disclosed | Department for Transport and National Cyber Security Centre assessing risk |
| Australia (Transport Canberra) | 90 ordered in 2023, within a 133-bus national fleet | Territory government and distributor VDI evaluating local exposure |
A pattern runs through that spread. Each government moved only after seeing another government’s findings, and none of them has confirmed an actual incident so far.
Washington Takes a Different Road
The United States has taken a narrower approach than Europe’s certification model. Rather than requiring every manufacturer to prove it runs a certified update management system, the Commerce Department’s Bureau of Industry and Security (BIS) finalized a rule on January 16, 2025, restricting Chinese- and Russian-linked hardware and software in the connectivity and automated driving systems of vehicles sold in the country. The prohibitions begin with model year 2027 and apply only to passenger vehicles under 10,001 pounds, a threshold that leaves transit buses like Yutong’s largely outside its reach.
Congress is trying to close that gap. Senators Bernie Moreno and Elissa Slotkin introduced the Connected Vehicle Security Act of 2026 in April, with a companion bill from Representatives John Moolenaar and Debbie Dingell in May, extending the restricted list to Iran and North Korea and directing Commerce to publish a new list of authorized vehicle parts, part of a bipartisan push to limit foreign connected vehicles.
The American Enterprise Institute (AEI), a Washington think tank, argues the country needs to go further still. Its recent report frames modern vehicles as dense sensor platforms that create real risks of espionage and, in a crisis, sabotage, given how much Chinese-made hardware and software already runs through global auto supply chains, and it recommends the government mandate additional disclosures on data collection.
The exposure now reaches well beyond buses and passenger cars. The same wireless update architecture is spreading into commercial trucking fleets, rail systems, ships, industrial robots and drones, and each one inherits the same basic question a mine outside Oslo just answered for buses.
The Window Ruter Says Is Still Open
Ruter wants regulators to use this moment before it closes. “We see this as a window of opportunity to strengthen requirements and protections now, before the next generation of more integrated and autonomous buses becomes harder and more costly to secure,” the operator said.
Congress has already set itself one deadline. Commerce must publish its list of authorized vehicle parts by January 1, 2032. The Jeep hack took seven years to turn into a binding global rule. The bus in Sandvika reached four governments in under a year.








