Drooid Logo
Back to story perspectives

Full Breakdown

Security Concerns Over Chinese Electric Buses in Europe

12/5/2025, 9:55:10 PM

Discovery of Vulnerabilities in Electric Buses

Recent investigations have revealed significant security vulnerabilities in electric buses manufactured by the Chinese company Yutong, which are currently operating in the UK, Denmark, and Norway. Engineers from Ruter, the transit authority for Oslo, conducted tests in a controlled environment at the Franzefoss Mine, where they discovered that a newly delivered Yutong bus was attempting to communicate with external networks. This communication was facilitated by a pre-installed SIM card roaming on a Romanian network, which allowed for Over-the-Air (OTA) updates. However, the connection extended beyond standard software updates, linking directly to the vehicle's Battery Management System (BMS). This access raises concerns that the manufacturer could theoretically disable the bus remotely.

Implications of Remote Access

Ruter's CEO, Bernt Reitan Jenssen, emphasized the gravity of the situation, stating, “There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer.” While proponents argue that such technology is standard in modern vehicles, critics highlight the potential risks associated with foreign control over critical infrastructure.

Diverging Perspectives on Security

The situation has sparked a debate over the safety of these buses. Ian Downie, head of sales at Pelican Bus and Coach, the importer of Yutong buses in the UK, denied the existence of similar vulnerabilities in the UK fleet, asserting that “all software updates are controlled by Pelican with manual physical access only.” This claim raises questions about the consistency of Yutong's manufacturing practices. If the UK buses are indeed different, it would suggest a significant deviation in product specifications. Conversely, if they share the same vulnerabilities as those in Norway, it would expose a critical gap in Western procurement practices regarding foreign-manufactured infrastructure.

Responses from Other Countries

In response to the findings, operators in Norway removed the SIM cards from their buses, sacrificing advanced features for enhanced security. Meanwhile, Movia, the Danish operator, opted to retain the SIM cards, weighing the economic benefits of data collection against the potential national security risks. This decision reflects a broader uncertainty among European operators regarding how to balance technological advancement with security concerns.

Ongoing Investigations and Future Considerations

Multiple investigations are currently underway across various European countries to assess the implications of these vulnerabilities. Security experts are advocating for a shift to an "Operator-Held Keys" system, which would allow manufacturers to upload software updates while requiring operators to authorize them. This approach could enhance security and ensure that operators maintain control over critical infrastructure.

Verbatim Quotes

  • “There is access to the control system for battery and power supply via mobile network through a Romanian sim card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer,” — Bernt Reitan Jenssen, CEO of Ruter
  • “all software updates are controlled by Pelican with manual physical access only.” — Ian Downie, Head of Sales, Pelican Bus and Coach

The ongoing discourse surrounding the security of Chinese electric buses in Europe underscores the complexities of integrating advanced technology into public transport systems while safeguarding national interests.