Ruter, the public transit authority that runs buses across Oslo and Akershus, didn’t settle for a paperwork audit when it wanted to know whether its electric buses could be hijacked by remote control. It parked two of them inside an isolated facility built into a mountain — the kind of shielded environment normally used to keep radio signals from leaking in or out — and let security engineers dig into the electronics for real. One bus was a three-year-old unit from the Dutch manufacturer VDL. The other was fresh off the line from Yutong, the Chinese company that has quietly become one of the largest electric bus suppliers in Europe.
What Ruter Actually Tested Inside That Mountain
The agency wasn’t chasing conspiracy theories. It ran two specific scenarios: whether the buses’ onboard cameras could be tapped for surveillance, and whether their connectivity systems could be exploited to affect how the bus itself operated. The camera question came back clean — Ruter confirmed the cameras aren’t networked to the internet, so there’s no path for footage to leave the vehicle. The connectivity question is where things got interesting, and where the two buses turned out to be built on completely different philosophies.
The VDL bus has no capability for over-the-air software updates at all. Every change to its systems has to happen through a physical connection, which is precisely why Ruter’s report treats it as a comparatively low priority. The Yutong bus is the opposite. It’s built to receive software updates and diagnostics remotely, the same way a smartphone downloads a firmware patch overnight — except the “phone” in this case weighs roughly 30,000 pounds and carries dozens of passengers.
The Romanian SIM Card and What a “Kill Switch” Actually Means
Here’s the detail that should matter more to fleet buyers than the manufacturer’s nationality: the Yutong bus reaches its maker through a mobile data connection routed through a Romanian SIM card, giving Yutong direct digital access to the vehicle’s control systems for battery and power management. Ruter’s engineers concluded that, in theory, this pathway could be used to stop the bus or render it inoperable — not through some elaborate hack, but simply because the manufacturer already has a standing door into those systems for legitimate diagnostic and update purposes.
What actually limits the risk is architecture, not intent. Ruter found a low degree of integration between the bus’s various systems, with only a single route in and out to the vehicle’s critical functions. That’s a genuinely useful design trait from a security standpoint — it means Oslo’s engineers can isolate that one pathway, inspect software updates before they ever reach the bus, and build a local firewall around it without re-engineering the entire vehicle. Separately, researchers also found vulnerabilities in a Chinese software platform that handles updates for Yutong and other clients; those were reported and patched before Ruter published its findings. Yutong itself received the report in advance and submitted clarifying comments that, according to Ruter, didn’t change the substance of what its engineers found.
CEO Bernt Reitan Jenssen framed the outcome as a shift from theory to leverage, saying the testing “moves from concern to concrete knowledge” about how to secure the fleet against exactly this kind of exposure. Ruter is now writing stricter cybersecurity requirements into future bus contracts, building firewalls that keep control local, and working with Norway’s Ministry of Transport on national rules — timed deliberately, since Ruter’s own experts note that today’s buses operate with roughly the sophistication of a 2016 car, a gap that shrinks fast as more driver-assist and autonomous features get added.
Your Car Already Has This Same Wiring
None of this is exotic. It’s the standard architecture of any modern connected vehicle, and American drivers have been living with a version of it for close to two decades. General Motors’ OnStar system can, at the company’s discretion, send a cellular command to a stolen vehicle that blocks the ignition from restarting once it’s parked, or gradually bring a moving vehicle down to idle speed so police can safely recover it. Functionally, that’s the identical category of access Ruter found in the Yutong bus: a persistent, manufacturer-controlled cellular link that includes authority over propulsion-adjacent systems, built into the car before it ever reaches a customer’s driveway. GM has leaned into that connectivity as a business, not just a safety feature — OnStar and its related services now generate billions in recurring revenue for the company — which is a reminder that this pipe exists on purpose and gets used commercially, not just in theft-recovery emergencies.
The distinction that actually matters isn’t whether a manufacturer can reach into a vehicle remotely. Almost every connected car sold today allows that, by design, for updates, diagnostics, and theft recovery. What matters is who holds the authority to use that access, under what legal process, with what oversight, and how many vehicles go dark at once if that access is ever misused, subpoenaed, or compromised. A single stolen sedan getting slowed to a stop by its own manufacturer is a feature working as intended. An entire transit authority’s bus fleet answering to a remote command from a foreign supplier’s server is a different order of risk, which is exactly why Ruter escalated this to Norway’s national government instead of treating it as an IT ticket.
Washington Is Already Trying to Draw This Exact Line
The U.S. government is having a version of this argument right now, and it’s moving faster than most car buyers realize. On July 22, the Senate Commerce Committee advanced the Connected Vehicle Security Act of 2026 out of committee with unanimous support, and the bill’s language goes well beyond banning cars physically assembled in China. It caps foreign ownership of a vehicle’s software at 25 percent and its telematics hardware — the cellular modems and control modules that give any car its always-on link to the outside world — at that same 25 percent, with compliance required by 2030. That’s the exact hardware category Ruter’s engineers just spent months stress-testing in a Norwegian mountain: the physical box that lets a manufacturer talk to a vehicle from anywhere on Earth. The bill isn’t only aimed at Chinese brands, either — its ownership thresholds are strict enough to catch legacy European manufacturers with the wrong shareholders, which tells you the underlying concern is the connection itself, not the badge on the grille.
What Owners and Fleet Buyers Should Actually Take From This
For an individual car buyer, the practical risk here is low but not zero, and it’s worth understanding rather than panicking over. Software-defined vehicles mean recalls and repairs increasingly happen through a data connection instead of a service bay, which can be genuinely convenient — no more waiting three weeks for a dealer appointment to fix a software bug. But it also means the vehicle’s warranty, insurance, and repair relationships now run through code the owner never sees and rarely consents to in any meaningful way beyond a checkbox at delivery. That’s the same fight playing out in farm equipment right-to-repair battles, where manufacturers used locked-down software to control who could fix a machine long after it was sold; regulators are increasingly deciding that owning the hardware should mean something even when the manufacturer owns the code.
For fleet buyers — municipal transit agencies, school districts, delivery operators — the calculus is heavier. Ruter’s test is a usable template: demand to know exactly what data path a vehicle uses to phone home, who controls it, whether that access can be isolated or delayed for inspection, and what happens contractually if that access is ever used without consent. That’s a procurement question now, not an afterthought, and it’s one that’s going to get asked of every manufacturer selling connected vehicles into public fleets, regardless of where they’re built.
