Transit operator Ruter tested two electric buses and found one had a live path into its battery and power-supply controls, reachable over the mobile network through a foreign SIM card. In theory, the manufacturer could stop or disable the bus from the outside.
The finding pushed the U.K. and Denmark to open their own investigations. Over-the-air technology has been standard since Tesla began pushing updates in 2012, and it now runs quietly across buses, cars, rail, maritime, and industrial machinery. Every one of those channels is a live line into the system.
VikingCloud's 2025 Cyber Threat Landscape Report found that nearly 80% of cybersecurity leaders were concerned about a nation-state attack in the next 12 months. A public bus fleet running on foreign hardware is that concern made physical, with critical transportation infrastructure sitting on the other end of an open channel.
If someone can reach the vehicle to update it, they can reach it to control it. The companies securing that access now will be the ones still trusted to run these fleets long term. Read more on CNBC:
cnb.cx/4pSbAxU.
VikingCloud's Thomas Patterson shared his thoughts: OTA technology is here to stay. The question teams need to ask: *where* is the trust boundary? If your vendor can update the device remotely, they can compromise it remotely. That's not a feature gap, that's a security architecture question you need answered before deployment, not after a breach.
While this story focuses on transport, we are seeing growing OTA updating in critical infrastructure like energy, water, and waste.
#Cybersecurity #NationStateThreats #CriticalInfrastructure #OTA