Cybersecurity concerns grow as OTA vehicle technology spreads | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A hidden SIM card found in a Chinese-made bus has triggered new investigations in the U.K. and Denmark.

On the Dash:

  • Cybersecurity concerns grow as a Norwegian transit operator’s SIM card test confirms a real OTA risk
  • The finding prompted new cybersecurity investigations in the U.K. and Denmark
  • It reinforces the security case behind U.S. bills targeting Chinese vehicle technology

There are new concerns over potential cybersecurity vulnerabilities in vehicles equipped with over-the-air (OTA) software updates. 

Officials in the U.K. and Denmark have opened investigations after a Norwegian transit operator found that a Chinese manufacturer could theoretically disable one of its buses through a SIM card built into the vehicle. Cybersecurity analysts warn that the same wireless update technology runs through much of the auto industry.

Sign up for CBT News’ daily newsletter and get the latest industry stories delivered straight to your inbox.

The operator, Ruter, says it found a Romanian SIM card linked to the battery and power supply system of one of its buses made by Chinese company Yutong. “There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer,” the company said in a statement. 

The rise of OTA technology

OTA updates let manufacturers push new software, firmware and fixes to connected vehicles without a dealership visit. Tesla started using the technology on the Model S in 2012. It has since spread across the industry.

The technology cuts costs and speeds up fixes that once required a recall or a service appointment, but that same connectivity gives outside parties a potential path into a vehicle’s control systems.

In May, the American Enterprise Institute urged the U.S. to add security reviews, restrict certain foreign-made vehicle hardware and software, and require automakers to disclose more about the data they collect.

Cybersecurity and the Chinese vehicle debate

The Ruter findings come as U.S. lawmakers are moving to keep Chinese vehicles and vehicle technology out of the country. The Commerce Department finalized rules in January 2025 restricting Chinese-linked software and hardware in connected vehicles, citing the same kind of remote-access risk Ruter’s tests demonstrated. 

Congress is working to make those protections permanent. Sen. Bernie Moreno (R-Ohio) and Sen. Elissa Slotkin (D-Mich.) introduced the Connected Vehicle Security Act of 2026, which would ban Chinese vehicles and connected technology from U.S. roads outright. Slotkin has described Chinese-connected vehicles as “surveillance packages on wheels.” 

The legislation has drawn backing from labor and industry groups. UAW President Shawn Fain called the bill a step toward “common sense guardrails” on the risk, and General Motors has said it supports policies protecting American manufacturing from the same threat.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW