OSLO , Norwegian cybersecurity researchers drove a Chinese-made NIO ES8 electric SUV deep into a decommissioned underground mine near Sandvika outside Oslo to cut it off from external networks, finding the vehicle continued attempting outbound connections with roughly 90 percent directed toward servers in China, according to an independent investigation published this week.
The test formed part of Project Lion Cage, a multi-year inquiry begun in 2022 by Tor Indstøy, vice president of risk management and threat intelligence at Telenor Group. Indstøy purchased the NIO ES8 as a dedicated research platform and monitored its data traffic with a team of about 10 experts, including Arild Tjomsland, a special adviser at the University of Southeast Norway, GadgetReview reported.
Over approximately 2.5 years of continuous observation, the team logged network activity from the SUV. About 90 percent of the outbound connections went to Chinese servers. The rest reached infrastructure in Germany, the United States, the Netherlands and Switzerland. Encryption prevented the researchers from reading the content of the packets.
Indstøy has described the volume of traffic to China as a surprise.
“We find a surprisingly large amount of data traffic between the car and China. That was unexpected. We had not expected it,”
he told Norwegian broadcaster NRK, Deutsche Wirtschafts Nachrichten noted.
The mine test, conducted in a location deep below Sandvika that offered near-total isolation from ordinary radio and cellular signals, aimed to eliminate background noise and confirm whether the vehicle maintained persistent communication attempts. Spectrum analyzers and traffic-interception equipment captured the activity even when the car appeared powered down.
Researchers also examined possible satellite links, including frequencies associated with China’s BeiDou system, which supports two-way messaging unlike traditional one-way GNSS networks such as GPS. Patterns appeared on relevant frequencies, though the team said it could not confirm with certainty that the car was actively using BeiDou for data uplink.
NIO has told European customers that vehicle data is processed, anonymized and encrypted inside the car and is not shared with the company’s cloud services without user consent. A company spokesperson, Vijay Sharma, stated that only the vehicle’s user controls its physical movements and activated functions. The Chinese embassy in Norway has dismissed related concerns as “unfounded conspiracy.”
Indstøy, who previously led security for Norway’s sovereign wealth fund at the Central Bank and worked in finance and consulting, has urged Norwegian authorities to continuously assess the societal risks posed by connected vehicles from manufacturers subject to China’s National Intelligence Law, paralleling debates over AI model governance and state access. That law requires organizations under Chinese jurisdiction to cooperate with state intelligence work when called upon, highlighting supply-chain risks in critical digital infrastructure.
The findings come as Chinese electric-vehicle brands expand in European markets, including Norway, where Chinese models have captured a significant share of new-car sales. Parallel testing by public-transport operator Ruter on Chinese-made Yutong electric buses identified remote-access capabilities to battery and power systems that were later patched, prompting tighter cybersecurity rules for public-fleet procurement, CleanTechnica reported.
Project Lion Cage continues to publish technical details through Indstøy’s LinkedIn series. The researchers emphasize that modern software-defined vehicles function as rolling data centers with constant telemetry, cameras and sensors, raising questions about data destinations, remote access and resilience that extend beyond any single brand, echoing broader concerns about device-level surveillance.


