On the Dash:
- Cybersecurity concerns grow as a Norwegian transit operator’s SIM card test confirms a real OTA risk
- The finding prompted new cybersecurity investigations in the U.K. and Denmark
- It reinforces the security case behind U.S. bills targeting Chinese vehicle technology
There are new concerns over potential cybersecurity vulnerabilities in vehicles equipped with over-the-air (OTA) software updates.
Officials in the U.K. and Denmark have opened investigations after a Norwegian transit operator found that a Chinese manufacturer could theoretically disable one of its buses through a SIM card built into the vehicle. Cybersecurity analysts warn that the same wireless update technology runs through much of the auto industry.
The operator, Ruter, says it found a Romanian SIM card linked to the battery and power supply system of one of its buses made by Chinese company Yutong. “There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer,” the company said in a statement.
The rise of OTA technology
OTA updates let manufacturers push new software, firmware and fixes to connected vehicles without a dealership visit. Tesla started using the technology on the Model S in 2012. It has since spread across the industry.
The technology cuts costs and speeds up fixes that once required a recall or a service appointment, but that same connectivity gives outside parties a potential path into a vehicle’s control systems.
In May, the American Enterprise Institute urged the U.S. to add security reviews, restrict certain foreign-made vehicle hardware and software, and require automakers to disclose more about the data they collect.
Cybersecurity and the Chinese vehicle debate
The Ruter findings come as U.S. lawmakers are moving to keep Chinese vehicles and vehicle technology out of the country. The Commerce Department finalized rules in January 2025 restricting Chinese-linked software and hardware in connected vehicles, citing the same kind of remote-access risk Ruter’s tests demonstrated.
Congress is working to make those protections permanent. Sen. Bernie Moreno (R-Ohio) and Sen. Elissa Slotkin (D-Mich.) introduced the Connected Vehicle Security Act of 2026, which would ban Chinese vehicles and connected technology from U.S. roads outright. Slotkin has described Chinese-connected vehicles as “surveillance packages on wheels.”
The legislation has drawn backing from labor and industry groups. UAW President Shawn Fain called the bill a step toward “common sense guardrails” on the risk, and General Motors has said it supports policies protecting American manufacturing from the same threat.



