September 30, 2026
Norway-found-a-real-cyber-risk-on-buses-He-did.webp

Support CleanTechnica’s work through a Substack subscription, on Patreon, or on Stripe. Help us produce all the original, high-quality content we publish week after week despite the challenges of AI deleting content, anti-social media, inflation and other obstacles.


When Norwegian transit authority Ruter subjected a Chinese Yutong electric bus to cybersecurity tests inside an isolated mine, the investigation began with two very different concerns. A geopolitical era: could the bus act as a visual surveillance platform near sensitive facilities such as Lutvann, headquarters of Norway’s intelligence service? The other technological era: Could a manufacturer with remote diagnostics and wireless software access reach systems important enough to interfere with the bus? Those questions traveled together in public debate, but they were technically distinct and ultimately produced very different answers.

The TFIE Strategy Briefing’s full analysis asks what the Norwegian experiment really isolated and whether its choice of control could distinguish a Chinese security problem from the ordinary risks of modern connected vehicles.

The hypothesis explicitly focused on espionage produced a less dramatic result. Investigators discovered that the Yutong’s exterior camera system was isolated from the manufacturer’s online systems, while the interior surveillance system used operator-side connectivity rather than a covert path back to Yutong. Concern that the bus could function as a visual surveillance dolly around Lutvann was not supported. The question of remote access produced a real finding: Ruter identified an Internet-connected route through the manufacturer’s systems to operationally important parts of the vehicle. With sufficient privileges, that access could potentially interfere with operation and render the bus unusable. The security problem was real; What was left unresolved was whether it had anything to do with the bus being Chinese.

Ruter compared the Yutong 2025 to a VDL 2022 whose critical systems had little external connectivity and could not receive wireless updates autonomously. The manufacturer, country of origin, vehicle age, connectivity, OTA capability and electronic architecture all changed at the same time. The experiment showed that a highly connected bus could be reached remotely while a comparatively disconnected one could not, but that pairing could not isolate nationality as the reason. If the goal was simply to establish whether that particular Yutong had consequent remote access, the test was useful. If evidence was to substantiate claims about Chinese buses presenting a distinct risk of remote control, a contemporary connected European bus would have been much more telling.

Ruter had these types of buses available. Its network included newer European electric buses from MAN and Solaris, both manufacturers with mature digital architectures that support remote diagnostics, backend communications and software-related functions. Putting the Yutong next to one of them would have allowed researchers to ask the same questions under comparable conditions: what could the manufacturer achieve, what could it change, how were updates authenticated, how well were the propulsion and battery systems segmented, what activity was recorded, and could the operator independently cut off external access? The result could have exposed a Yutong-specific weakness, shown that European buses performed similarly, or identified significant differences between manufacturers. In contrast, European control largely lacked the core research technology.

As the Norwegian finds traveled, Lutvann’s negative result received much less attention than the successful remote access find, which often resulted in a story about Chinese buses containing a “remote kill switch.” That compressed two different findings into a much simpler geopolitical narrative. There is nothing unreasonable about transit agencies testing hostile state scenarios, particularly when providers retain remote access to public infrastructure, but country-specific concerns demand good controls. Comparing a highly connected Chinese vehicle to a comparatively disconnected European one makes it easy to attribute a technological difference to nationality, even though the experiment itself does not support that step.

Subsequently, Denmark approached the issue from another direction. Movia commissioned EY to assess cybersecurity maturity at Chinese and European bus manufacturers using the same automotive cybersecurity frameworks. The work was not a penetration test and therefore cannot replace Ruter’s practical exam, but it did make the comparison between manufacturers that the Norwegian public debate implied had already been resolved. Chinese manufacturers were not left behind in cybersecurity, and Movia concluded that there was no basis to consider Chinese buses less cyber-secure than those of other manufacturers. That conclusion does not establish that every Yutong implementation is equivalent to every European implementation. This makes nationality a much weaker explanation than Ruter discovered.

Taken together, the works from Norway and Denmark point to a more useful security problem. Modern buses are networked computers, and transportation agencies need to know who can communicate with them remotely, what systems are exposed, what software can be changed, how updates are authenticated, what activity is logged, and how quickly external access can be cut off if a provider is compromised or becomes hostile. Those requirements pertain to procurement and fleet management, whether the badge says Yutong, MAN, BYD, Solaris, Mercedes-Benz or Volvo. Norway found a good reason to investigate remote access to buses. Your choice of control simply couldn’t tell you whether China was the reason the access existed.


Read the full analysis in TFIE Strategy Briefing.


Sign up for CleanTechnica’s Weekly Substack to get in-depth analysis and high-level recaps from Zach and Scott, subscribe to our daily newsletter, and follow us on Google News.


Advertisement






Do you have any tips for CleanTechnica? Do you want to advertise? Want to suggest a guest for our CleanTech Talk podcast? Contact us here.


Subscribe to our daily newsletter to receive 10-15 new cleantech stories per day. Or sign up to receive our weekly newsletter on the week’s top stories if the daily grind gets too much.



CleanTechnica uses affiliate links. See our policy here.

CleanTechnica Comment Policy


Avatar photo
Written by

Jhon Smith

Info Vitalis is a content writer specializing in creating clear, concise, and engaging articles. With experience in health, lifestyle, technology, and current events, Info Vitalis aims to provide readers with useful and easy-to-understand information.

Leave a Reply

Your email address will not be published. Required fields are marked *