European public transport operators in the UK, Norway, and Denmark are investigating cybersecurity vulnerabilities in Chinese-made Yutong electric buses, following concerns that the manufacturer could remotely access and potentially disable vehicles. The UK government, in coordination with the National Cyber Security Centre, is assessing the risk after Norwegian operator Ruter identified that Yutong has direct digital access to each bus for software updates and diagnostics, including critical systems like battery and power management. Operators have implemented measures such as disconnecting buses from the internet to retain local control, while the UK Department for Transport has acknowledged the seriousness of the issue and is working with intelligence agencies to mitigate potential risks.
Simultaneously, Danish and Norwegian transport providers are urgently probing the same security flaw, highlighting broader European fears about reliance on Chinese technology and the risk of remote tampering or control amid geopolitical tensions. Yutong, the world’s largest bus manufacturer, has stated that it complies with all safety and data privacy standards, storing EU vehicle data securely and requiring customer authorization for system access. The investigations underscore the potential for remote deactivation of connected vehicles and the need for robust cybersecurity measures in critical public infrastructure.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
The UK moved to have its cyber and intelligence services investigate claims that Chinese-made buses could potentially be switched off remotely. The step expanded official scrutiny of the Yutong bus security issue beyond Denmark and Norway.
Operators and authorities in Norway and Denmark began testing the affected buses and putting fixes in place to reduce the risk associated with the remote-access functionality. These actions were reported as part of the response to the disclosed security concern.
Authorities in Denmark and Norway launched investigations into a vulnerability in Chinese-made Yutong electric buses that could allow remote diagnostics and software updates to be abused to interfere with or disable vehicles. The issue raised concerns about the use of connected Chinese technology in critical transport infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.