Growing concerns about technological dependence are reshaping Europe’s approach to public transportation and cybersecurity. What was once a quiet and efficient sector in Scandinavia is now at the center of a heated debate about national security and digital sovereignty.
Growing concerns regarding Chinese-manufactured buses
Public transport providers in Denmark and Norway are facing a possible security vulnerability within their electric bus fleets, particularly in vehicles manufactured by Yutong, the globe’s leading bus producer headquartered in Zhengzhou, China. The problem arises from the buses’ capacity to accept remote software updates and perform diagnostic assessments – a functionality that, despite its technological sophistication, also sparks worries that the vehicles could be disabled or controlled remotely.
Movia, the premier public transportation authority in Denmark, has conceded that this wireless capability could enable an external entity—be it the producer or a cybercriminal—to remotely incapacitate a bus. Jeppe Gaard, Movia’s chief operating officer, clarified that this issue isn’t exclusive to Chinese manufacturers but represents a wider concern linked to the growing digital integration in contemporary vehicles. Both electric cars and buses, he pointed out, are heavily dependent on networked systems that are, theoretically, susceptible to remote access and deactivation.
Since 2019, Movia has integrated over 260 Yutong buses into its operational fleet for Copenhagen and eastern Denmark. Comparable worries were voiced in Norway, where Ruter, a prominent public transport operator, conducted an independent inquiry. The firm executed controlled evaluations of both Yutong and Dutch-manufactured VDL buses within protected, subterranean facilities. The results indicated that while the Dutch models lacked the functionality for remote updates, Yutong retained direct digital connectivity to its vehicles for software enhancements and diagnostics — implying that, at least hypothetically, the buses could be disabled remotely, despite not being capable of remote driving.
China’s response and data protection assurances
Yutong has responded to these claims by affirming its compliance with international regulations and emphasizing its commitment to data privacy and cybersecurity. The company stated that all vehicle data within the European Union is securely housed in an Amazon Web Services data center located in Frankfurt, Germany. Yutong further assured that all stored information is encrypted, protected by strict access controls, and inaccessible without explicit customer authorization.
Despite these assurances, European officials and transportation firms maintain a wary stance. This event has amplified conversations regarding Europe’s increasing reliance on Chinese technology—a connection marked by reciprocal economic advantages yet overshadowed by profound geopolitical suspicion. Beijing’s purported participation in cyber espionage, intellectual property theft, and surveillance operations has prompted numerous European leaders to reevaluate the enduring consequences of their dependence on Chinese providers for essential infrastructure.
A wider European predicament
The scrutiny surrounding Yutong’s buses is only the latest episode in Europe’s complex technological relationship with China. Across the continent, policymakers are attempting to strike a delicate balance between leveraging China’s advanced manufacturing capabilities and protecting national interests. Recent events — including the Netherlands’ decision to seize control of the Chinese-owned chipmaker Nexperia — have fueled concerns that Europe’s automotive and technology sectors could face major disruptions in the event of diplomatic or trade tensions.
Many governments have already taken steps to limit exposure to potential vulnerabilities. Several European nations, following the example of the United States, have removed Huawei and ZTE equipment from their 5G networks, citing risks of espionage and data manipulation. Now, attention has shifted to the rapidly growing market for Chinese electric vehicles. According to consultancy JATO Dynamics, Chinese EVs doubled their market share in Europe in early 2025, reaching over 5% — a figure that highlights both consumer interest and regulatory unease.
China, for its part, has dismissed Western fears as unfounded and politically motivated. Earlier this year, a spokesperson for China’s Foreign Ministry criticized U.S. restrictions on Chinese automotive technology, arguing that such measures “overstretch the concept of national security.” Chinese officials maintain that their companies operate transparently and pose no threat to foreign nations.
Western Intelligence Worries
Security specialists throughout Europe, however, maintain a degree of skepticism. Richard Dearlove, the former head of MI6, cautioned that Western administrations are confronting a predicament akin to the one presented by Huawei during the deployment of 5G technology. From his perspective, the growing ubiquity of internet-connected automobiles produced by Chinese companies might introduce novel points of weakness. He posited that, under the most dire circumstances, China could hypothetically incapacitate numerous electric vehicle fleets in prominent urban centers — a situation capable of paralyzing transit systems during an emergency.
Still, some cybersecurity professionals argue that such a scenario, while technically feasible, is unlikely. Ken Munro, founder of the British-American firm Pen Test Partners, noted that any internet-connected vehicle — whether produced by a Western or Chinese company — carries inherent risks of remote interference. Even well-known brands like Tesla, he explained, depend on software connectivity that could be exploited under specific conditions.
In light of these worries, Ruter has put in place several safeguards, such as improved cybersecurity measures, firewalls, and more rigorous scrutiny of upcoming vehicle purchases. The organization is also collaborating with national agencies to define more precise cybersecurity guidelines for public transportation networks. Nevertheless, specialists are still split on the adequacy of these preventative steps. Munro warned that the sole guaranteed way to eradicate the danger would be to entirely disconnect vehicles from the internet — an action that would simultaneously impede the capacity to carry out essential updates and remote upkeep.
The intersection of innovation and vulnerability
The debate unfolding in Scandinavia underscores a broader paradox of the digital age: the same technologies that enable efficiency and innovation can also expose systems to new forms of risk. As cities strive to modernize public transport and reduce carbon emissions through electrification, they must also grapple with questions of technological sovereignty, data privacy, and national security.
Europe’s dependence on Chinese-manufactured parts and programs reaches well beyond its public transportation systems. From its communication grids to its green energy facilities, the continent’s advancement is profoundly linked to China’s industrial framework. As international conflicts escalate, the task for European countries will involve safeguarding their technological autonomy while continuing their journey towards ecological balance and pioneering development.
The controversy surrounding Yutong’s buses has made one thing clear: cybersecurity is now as crucial as clean energy in shaping the future of urban mobility. The issue is not confined to any one country or manufacturer — it represents a defining test for the next phase of Europe’s digital transformation.
In the end, as Ken Munro aptly summarized, the debate boils down to one word — trust. And in an increasingly interconnected world, trust may prove to be the most valuable and fragile asset of all.
