Fearing vulnerability to China, Europe has a new worry: Electric buses

Europe’s Growing Concern: China and Electric Buses

Growing concerns about technological dependence are reshaping Europe’s approach to public transportation and cybersecurity. What was once a quiet and efficient sector in Scandinavia is now at the center of a heated debate about national security and digital sovereignty.

Growing concerns regarding Chinese-manufactured buses

Public transportation operators in Denmark and Norway are confronting a potential security flaw in their electric bus fleets, specifically in vehicles produced by Yutong, the world’s largest bus manufacturer based in Zhengzhou, China. The issue stems from the buses’ ability to receive remote software updates and diagnostic checks — a feature that, while technologically advanced, also raises concerns that the vehicles could be immobilized or manipulated from afar.

Movia, the premier public transportation authority in Denmark, has conceded that this wireless capability could enable an external entity—be it the producer or a cybercriminal—to remotely incapacitate a bus. Jeppe Gaard, Movia’s chief operating officer, clarified that this issue isn’t exclusive to Chinese manufacturers but represents a wider concern linked to the growing digital integration in contemporary vehicles. Both electric cars and buses, he pointed out, are heavily dependent on networked systems that are, theoretically, susceptible to remote access and deactivation.

Since 2019, Movia has incorporated more than 260 Yutong buses into its fleet serving Copenhagen and eastern Denmark. Similar concerns were echoed in Norway, where Ruter, a major public transportation provider, conducted its own investigation. The company carried out controlled tests on both Yutong and Dutch-made VDL buses in secure, underground facilities. The findings showed that while the Dutch models lacked remote update capabilities, Yutong maintained direct digital access to its vehicles for software updates and diagnostics — meaning that, at least theoretically, the buses could be rendered inoperable remotely, even though they could not be remotely driven.

China’s reaction and data security guarantees

Yutong has responded to these claims by affirming its compliance with international regulations and emphasizing its commitment to data privacy and cybersecurity. The company stated that all vehicle data within the European Union is securely housed in an Amazon Web Services data center located in Frankfurt, Germany. Yutong further assured that all stored information is encrypted, protected by strict access controls, and inaccessible without explicit customer authorization.

Despite these reassurances, European authorities and transit companies remain cautious. The incident has intensified discussions about Europe’s growing dependency on Chinese technology — a relationship characterized by mutual economic benefits but shadowed by deep geopolitical mistrust. Beijing’s alleged involvement in cyber espionage, intellectual property theft, and surveillance activities has led many European leaders to reconsider the long-term implications of their reliance on Chinese suppliers for critical infrastructure.

A wider European predicament

The examination of Yutong’s buses represents just one recent chapter in Europe’s intricate technological ties with China. Throughout the continent, political leaders are striving to achieve a careful equilibrium: harnessing China’s sophisticated production prowess while simultaneously safeguarding national interests. Recent occurrences, such as the Netherlands’ move to take over the Chinese-owned chip manufacturer Nexperia, have intensified worries that Europe’s automotive and tech industries might encounter significant disturbances should diplomatic or commercial disputes arise.

Many governments have already taken steps to limit exposure to potential vulnerabilities. Several European nations, following the example of the United States, have removed Huawei and ZTE equipment from their 5G networks, citing risks of espionage and data manipulation. Now, attention has shifted to the rapidly growing market for Chinese electric vehicles. According to consultancy JATO Dynamics, Chinese EVs doubled their market share in Europe in early 2025, reaching over 5% — a figure that highlights both consumer interest and regulatory unease.

China, for its part, has dismissed Western fears as unfounded and politically motivated. Earlier this year, a spokesperson for China’s Foreign Ministry criticized U.S. restrictions on Chinese automotive technology, arguing that such measures “overstretch the concept of national security.” Chinese officials maintain that their companies operate transparently and pose no threat to foreign nations.

Western intelligence concerns

Security experts across Europe, however, remain skeptical. Former MI6 chief Richard Dearlove warned that Western governments are facing a challenge similar to the one posed by Huawei during the 5G rollout. In his view, the increasing prevalence of connected vehicles built by Chinese manufacturers could create new vulnerabilities. He suggested that, in a worst-case scenario, China could theoretically disable fleets of electric vehicles in major cities — a scenario that could disrupt transportation networks during a crisis.

Still, some cybersecurity professionals argue that such a scenario, while technically feasible, is unlikely. Ken Munro, founder of the British-American firm Pen Test Partners, noted that any internet-connected vehicle — whether produced by a Western or Chinese company — carries inherent risks of remote interference. Even well-known brands like Tesla, he explained, depend on software connectivity that could be exploited under specific conditions.

In light of these worries, Ruter has put in place several safeguards, such as improved cybersecurity measures, firewalls, and more rigorous scrutiny of upcoming vehicle purchases. The organization is also collaborating with national agencies to define more precise cybersecurity guidelines for public transportation networks. Nevertheless, specialists are still split on the adequacy of these preventative steps. Munro warned that the sole guaranteed way to eradicate the danger would be to entirely disconnect vehicles from the internet — an action that would simultaneously impede the capacity to carry out essential updates and remote upkeep.

Where groundbreaking ideas meet susceptibility

The discussion emerging in Scandinavia highlights a wider contradiction of the digital era: the very technologies that facilitate efficiency and progress can simultaneously expose systems to novel types of hazards. As urban centers endeavor to update public transit and decrease carbon output via electrification, they are also compelled to confront issues concerning technological autonomy, information confidentiality, and national defense.

Europe’s dependence on Chinese-manufactured parts and programs reaches well beyond its public transportation systems. From its communication grids to its green energy facilities, the continent’s advancement is profoundly linked to China’s industrial framework. As international conflicts escalate, the task for European countries will involve safeguarding their technological autonomy while continuing their journey towards ecological balance and pioneering development.

The debate over Yutong’s bus fleet highlights a critical point: cybersecurity is now as vital as sustainable power in defining the trajectory of city transportation. This challenge extends beyond a single nation or producer, marking a pivotal moment for the subsequent stage of Europe’s digital evolution.

In the end, as Ken Munro aptly summarized, the debate boils down to one word — trust. And in an increasingly interconnected world, trust may prove to be the most valuable and fragile asset of all.

By Anna Edwards

You May Also Like