Last summer, engineers working for Oslo’s public transit agency drove two electric buses into an abandoned mine and started trying to hack their own fleet. They weren’t hunting for foreign spies. They were testing something far more basic: whether the same digital channel that lets a manufacturer beam a software fix to a bus could also work as a kill switch. The answer, they found, was yes.
Garage Deals: Nowell Leather’s Hand-Stitched EDC Gear Belongs in Every Gearhead’s Glovebox
That finding has since been flattened into a scarier, simpler headline about China. It shouldn’t be. The real story isn’t who built the bus. It’s what every automaker had to engineer to make over-the-air updates work at all, and what that architecture quietly costs the rest of us in control we didn’t realize we’d handed over.
A Mine, Two Buses, and a Romanian SIM Card
The transit operator, Ruter, runs about 850 Yutong electric buses on Oslo-area routes. In its own account of the testing, published on its site, Ruter said the Chinese manufacturer has digital access to the control systems for software updates and diagnostics, delivered through a mobile SIM card registered in Romania. In theory, Ruter said, that access could be used to influence the bus, including its battery and power systems.
Two details in Ruter’s own report matter more than the panic that followed it. First, the bus’s cameras were never connected to the internet, so the espionage angle that dominated a lot of coverage wasn’t actually part of what was found. Second, the access point wasn’t a sophisticated hidden backdoor. Ruter described the integration as “barely integrated,” meaning it wasn’t disguised at all. It was just how the update system had been wired.
That’s the detail worth sitting with. A remote path into a bus’s power system wasn’t a clever exploit. It was the update system functioning as designed.
The ‘Safe’ Bus Was Safe Because It Was Frozen in Time
Ruter didn’t just test the Yutong. It ran the same probe against a three-year-old electric bus built by Dutch manufacturer VDL. That bus came back clean, with no external access points a hacker or a hostile government could use.
Here’s the part almost nobody reported: the VDL bus was clean because it can’t receive wireless software updates at all. There’s nothing to secure because there’s no channel to secure. It’s not a more defensible design. It’s a bus stuck running whatever code it shipped with, forever, unless a technician physically plugs into it.
That’s the trade-off nobody wants to say out loud: right now, at scale, there is no version of a connected vehicle that is both remotely patchable and remotely unreachable. Patchability and reachability are the same wire. Automakers chose reachability because recalls are expensive and bad press, and because Tesla proved in 2012 that a Model S bug could be squashed overnight instead of at a service bay. That decision, not espionage, is the actual foundation of this story.
Your Car Runs the Exact Same Pipeline
Strip away the SIM card’s country of origin and the Yutong architecture looks like nearly every connected vehicle on American roads. A telematics control unit talks to the cloud. A gateway module decides what that unit is allowed to touch. Whoever controls the update server can, in principle, push code to anything wired behind that gateway, whether it’s an infotainment screen or a brake controller, the same gateway that could just as easily function as a kill switch.
We watched that exact duality play out this month. Volvo pushed Apple Music to roughly two million cars in a single overnight update, the kind of convenience rollout that makes OTA feel harmless. But the same delivery pipeline is the one Volvo used last year to address a brake-related issue, the sort of fix that used to mean a recall notice in your mailbox instead of a silent download. One pipe, two very different kinds of cargo.
That’s not a criticism of Volvo specifically. It’s the whole industry’s model now, and it’s why the Ruter test generalizes far beyond one Chinese bus builder.
Washington Already Answered a Version of This Question
Here’s a detail that undercuts the idea that Ruter uncovered some brand-new threat: the U.S. government finalized a rule addressing this exact scenario back in January 2025, months before anyone drove a bus into a Norwegian mine. The Commerce Department’s Bureau of Industry and Security issued a final rule restricting Chinese and Russian hardware and software in connected vehicle systems sold in the United States. Software tied to those countries is barred starting with model year 2027. Hardware follows in model year 2030. That timeline is unfolding alongside a broader trade fight, as Chinese EV exports keep climbing globally even as connectivity and tariff rules tighten in the U.S.
In other words, regulators already concluded that letting an adversary government hold a de facto kill switch over a moving vehicle’s control systems was a risk worth writing federal rules over, well before Oslo had proof of concept.
But notice what that rule doesn’t do. It’s sorted by the nationality of the company, not by the architecture of the system. A remote-access gateway built by a company headquartered in Michigan, Germany, or Japan raises none of the same flags, even though the technical capability, a manufacturer’s ability to reach into a vehicle’s control systems from a server somewhere, is identical. We’ve written before about how domestic remote-shutdown capability is handled with far less urgency than its imported version, including a House vote that left the door open on kill-switch tech without so much as a debate about foreign ownership.
Buses Are Running Software From 2016, and That’s the Real Warning
Ruter offered one more line in its statement that deserves more attention than the SIM card did. The company said current buses have roughly the same level of onboard functionality as passenger cars from 2016. Commercial and fleet vehicles are running years behind the software sophistication of the family SUV in your driveway, even as manufacturers push more driver-assistance and autonomous features into buses and trucks. NHTSA has published non-binding cybersecurity guidance for the industry for years, but compliance remains voluntary, and gaps like this tend to surface first in commercial fleets.
That’s a widening gap, not a shrinking one. Passenger vehicle software has spent the past decade absorbing lessons from exactly this kind of failure. Hyundai halted Palisade sales after a power-seat system tied to software controls was linked to a child’s death, a case that showed how quickly a digital convenience feature can become a liability when the fallback is thinner than the mechanical switch it replaced. Commercial fleets are heading into the same software complexity with less regulatory scrutiny and, per Ruter’s own comparison, roughly a decade less maturity.
Who Actually Holds the Kill Switch to Your Car
None of this requires a foreign government to matter to you personally. If a manufacturer can push a fix to your brakes without you doing anything, it can also push a mistake, or simply decide your vehicle no longer qualifies for support. Owners have already discovered what that looks like on a smaller scale: software-gated features that vanish after a recall, instrument clusters that reboot mid-drive, dashboards that go dark because of a firmware fault rather than a broken part. Repair increasingly means a server-side decision as much as a wrench turn, and insurers are only beginning to figure out how to price a risk that lives in code instead of steel.
Used car buyers should take particular note. A vehicle’s OTA dependency doesn’t disappear at trade-in. Whoever controls the update servers years from now, through a merger, a bankruptcy, or a geopolitical dispute, still controls that pathway into the car you bought secondhand.
The Bottom Line
An over-the-air update and a kill switch travel down the exact same wire. The only difference is what’s inside the package the manufacturer decides to send.
Norway didn’t discover that a Chinese company has unusual power over its buses. It discovered, and then proved with an isolated mine and a fair amount of nerve, that every automaker building connected vehicles has built the same kind of power over its customers, and that the only real safeguard so far is trust in whoever holds the login. Betting on nationality to sort the trustworthy manufacturers from the untrustworthy ones is easy politics. It isn’t engineering. And it leaves the actual question, who should be allowed to hold that kind of remote authority over a moving vehicle at all, sitting unanswered while the fleet keeps growing.

