Norwegian cybersecurity researchers had a simple question: what does a Chinese-built electric car do when it cannot see the outside world? So they drove a NIO ES8 SUV into a decommissioned underground mine near Sandvika, outside Oslo, where radio and cellular signals barely penetrate. The car kept trying to reach servers anyway. Project Lion Cage, the multi-year investigation behind the test, reports that roughly ninety percent of those outbound connections pointed to servers in China.
Project Lion Cage began in twenty twenty-two when Tor Indstøy, vice president of risk management and threat intelligence at Telenor Group, bought the NIO ES8 as a dedicated research platform, GadgetReview reported. He and a team of around ten experts, including special adviser Arild Tjomsland of the University of Southeast Norway, monitored the car's network traffic for about two and a half years. The rest of the traffic reached infrastructure in Germany, the United States, the Netherlands and Switzerland. Encryption prevented the researchers from reading the contents of the packets. Destinations and volume, yes. Contents, no.
What the mine test actually proves
The mine was chosen to strip away background noise, according to HypeFresh's account of the investigation. Deep below Sandvika, with near-total isolation from ordinary signals, spectrum analyzers and traffic-interception gear picked up persistent outbound attempts even when the car appeared powered down. Project Lion Cage also scanned for satellite links, including frequencies used by China's BeiDou navigation system, which supports two-way messaging unlike one-way networks like GPS. The team saw patterns on those frequencies but could not say with certainty the car was using BeiDou to send data up.
The caveat matters as much as the finding. GadgetReview's writeup stresses that no evidence of specific personal data exfiltration turned up, and the tests do not prove that NIO is transmitting sensitive information to Chinese authorities. NIO has told European customers their data is processed in Europe, according to GadgetReview, a claim the observed traffic patterns now sit awkwardly against. A company spokesperson, Vijay Sharma, said only the vehicle's user controls its physical movements and activated functions, HypeFresh reported. The Chinese embassy in Norway dismissed the concerns as "unfounded conspiracy."
Why the traffic pattern worries governments anyway
The worry starts with a simple fact: nobody could read the packets. That leaves the question of who could demand to read them. China's National Intelligence Law requires organizations under Chinese jurisdiction to cooperate with state intelligence work when asked. "We find a surprisingly large amount of data traffic between the car and China. That was unexpected. We had not expected it," Project Lion Cage founder Tor Indstøy told Norwegian broadcaster NRK. He has urged Norwegian authorities to keep assessing the societal risks of connected vehicles built by companies subject to that law.
Norway already ran this argument with buses. Public transport operator Ruter tested a Chinese-made Yutong electric bus against a Dutch VDL bus and found the Yutong carried a Romanian SIM card, accepted remote software updates and diagnostics over mobile networks, and gave its maker access to battery and power management systems. Yutong and its platform providers later patched the vulnerabilities, and Norway tightened cybersecurity requirements for public transport procurement, GadgetReview reported. The testers were clear about the limits: the Yutong's cameras were never connected to the internet, and they found no evidence of misuse.
The conspiracy is not the car, it is the architecture
For the Project Lion Cage team, the consumer numbers land as validation. A survey of nearly fifteen thousand EV owners by the Norwegian Electric Vehicle Association, reported by Euronews, found thirty one percent would avoid buying a Chinese brand for political reasons, up from twenty three percent a year earlier. The association's secretary general Christina Bu said that "new cars are effectively computers on wheels," and that data security draws more attention as cars get smarter. Still, Chinese brands including BYD, NIO and Dongfeng, along with Chinese-owned Volvo and Polestar, took roughly a quarter of new EV registrations in Norway in the first half of the year.
GadgetReview's full report on the mine test notes that remote connectivity is standard across the whole industry, not just Chinese makes, a point HypeFresh's independent account of Project Lion Cage reinforces. Data hunger by default is the norm; regulators have had to fine even Google over its location data collection, as this GenZNewZ report on the Google location data fine covered.
Project Lion Cage's central argument is bigger than one brand. Modern software-defined vehicles work like rolling data centers: constant telemetry, cameras, sensors, always-on modems. Tesla and Western brands run the same always-on architecture. The difference is which government can legally compel the manufacturer to cooperate, the same dynamic that drove the fight over fifth-generation wireless and China's appetite for foreign tech in the F-35 parts case. State-level pressure on tech supply chains keeps surfacing, from California's AI kill switch regulation debate to this Norwegian mine. A cheap sticker price buys a sensor package on wheels, and Project Lion Cage is the clearest demonstration yet of where those sensors' first loyalties lie.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.