28 Jul 2026, Tue

Norway Went Hunting for a Chinese Kill Switch in a Bus. It Found Out Every Connected Vehicle Already Has One

white and black bus running near the mountain

Norway spent months trying to prove that a Chinese-built city bus could be remotely disabled by its manufacturer. It found that proof. What nobody expected is that the same capability has been sitting inside American cars for nearly two decades, sold back to drivers as a safety feature.

Ruter, the transit authority that runs public buses across Oslo and Akershus, parked two electric buses inside an isolated facility built into a mountain, the kind of shielded space normally used to keep radio signals from leaking in or out, and let its own security engineers take them apart. One bus came from Yutong, the Chinese manufacturer that has quietly become one of Europe’s largest electric bus suppliers. The other was a three-year-old unit from VDL, a Dutch manufacturer. Ruter chose that pairing deliberately: the two buses sit at opposite ends of how connected a modern transit vehicle can be.

The Boring Bus Turned Out to Be the Safer One

Ruter’s own published findings are blunt about the VDL bus: it has no capability for over-the-air software updates at all. Every change to its systems requires a technician to physically connect a cable. That makes it a hassle to service. It also makes it nearly impossible to hijack remotely, which is exactly why Ruter’s engineers moved past it quickly.

The Yutong bus is the opposite. It receives software and diagnostic updates automatically, the same way a phone downloads a firmware patch overnight, except this particular phone weighs roughly 30,000 pounds and carries dozens of passengers through Oslo traffic. That connection routes through a Romanian SIM card, which gives Yutong direct digital access to the bus’s battery and power management systems. Ruter’s engineers concluded that, in theory, this access could be used to stop the bus or render it inoperable, not through some elaborate hack, but simply because the manufacturer already has a standing door into those systems for legitimate diagnostic and update purposes.

Here’s the detail that should unsettle European regulators just as much as Norwegian ones: the foreign server with a hand on a Chinese bus’s power systems sits in Romania, not China. The nationality of the access point and the nationality of the manufacturer aren’t even the same country. Connectivity supply chains don’t respect the borders most people assume they do.

What actually limited the risk wasn’t intent, it was architecture. Ruter found a low degree of integration between the Yutong bus’s various systems, with only a single route in and out of its critical functions. That single pathway is exactly what let engineers isolate it, inspect updates before they ever reached the bus, and build a local firewall around it without re-engineering the entire vehicle. Ruter CEO Bernt Reitan Jenssen said the testing “moves from concern to concrete knowledge,” and the useful lesson has nothing to do with where a bus happens to be built: fewer connected systems talking to each other is easier to defend than many, regardless of manufacturer.

Detroit Already Built This. It Just Called It OnStar.

None of what Ruter found is exotic. It’s the standard architecture of any modern connected vehicle, and American drivers have been living with a version of it for nearly two decades. General Motors’ OnStar system can, at the company’s discretion, send a cellular command to a stolen vehicle that blocks the ignition from restarting once it’s parked, or gradually slows a moving vehicle so police can recover it safely. That is functionally the same category of access Ruter found in the Yutong bus: a persistent, manufacturer-controlled cellular link with authority over propulsion-adjacent systems, built into the vehicle before it ever reaches a customer’s driveway.

GM has leaned into that connectivity as a business, not only a safety feature. The company has separately had to pay 12.75 million dollars to settle claims that OnStar quietly collected and sold driver data without clear consent, a reminder that this pipe gets used commercially, not just during theft-recovery emergencies.

The distinction that actually matters here isn’t whether a manufacturer can reach into a vehicle remotely. Almost every connected car sold today allows that, by design, for updates, diagnostics, and theft recovery. What matters is who holds the authority to use that access, under what legal process, and how many vehicles go dark at once if that access is ever misused, subpoenaed, or compromised. A single stolen sedan getting slowed to a stop by its own manufacturer is a feature working as intended. An entire transit authority’s bus fleet answering to a remote command from a foreign supplier’s server is a different order of risk entirely, which is exactly why Ruter escalated this to Norway’s national government instead of treating it as an IT ticket.

Washington Is Already Trying to Draw This Exact Line

The US government is having its own version of this argument right now, and it’s moving faster than most car buyers realize. On July 22, the Senate Commerce Committee advanced the Connected Vehicle Security Act of 2026 out of committee with bipartisan support. Under the bill’s text, starting January 1, 2027, connected vehicles are barred from import, manufacture, or sale in the US if their country of origin is China, Russia, North Korea, or Iran, or if more than 15 percent of the manufacturer is owned or controlled by an entity from one of those countries. Software carries a stricter 25 percent ownership threshold. The hardware itself, the modems, control modules, and battery management electronics that give a vehicle its always-on link to the outside world, gets a longer runway: manufacturers have until January 1, 2030 before that hardware is banned outright, and even then, replacement parts for repairs and warranty work on older models are exempted.

Read the ownership math closely and this isn’t purely a China rule, even though China is clearly the target. Geely, based in China, holds a controlling stake in Volvo and owns Polestar and Lotus outright. On paper, those ownership thresholds are strict enough to sweep in legacy European nameplates that plenty of American buyers would never think to associate with Beijing, which tells you the actual concern driving this bill is the ownership and control chain sitting behind a badge, not the badge itself.

What Owners and Fleet Buyers Should Actually Take From This

For an individual car buyer, the practical risk here is low, and it’s worth understanding rather than panicking over. Software-defined vehicles mean recalls and repairs increasingly happen through a data connection instead of a service bay, which can be genuinely convenient. No more waiting weeks for a dealer appointment to fix a software bug. But it also means a vehicle’s warranty, insurance, and repair relationships now run through code the owner never sees and only nominally consents to at delivery.

For fleet buyers, municipal transit agencies, school districts, delivery operators, the calculus is heavier, and Ruter’s test doubles as a usable template regardless of which government eventually writes the rules: demand to know exactly what data path a vehicle uses to phone home, who controls it, whether that access can be isolated or delayed for inspection, and what happens contractually if it’s ever used without consent.

The bus was never the vulnerability. Not knowing who held the key to it was.

By Shawn Henry

Shawn Henry has been writing about cars long enough that it's less a job than a habit he can't shake. He covers a little of everything—classic machines, the newest tech, and wherever the industry happens to be heading—and he's the type who actually understands what's going on under the hood, not just how to describe it. Mostly, he just likes telling a good car story.

Join the conversation

No comments yet — be the first to share your take.

Your email address will not be published. Required fields are marked *