chicago subway

Lawmakers Warn Cities to Stop Contracting Chinese Companies To Build Transit Systems

Despite concerns about Chinese manufacturers having access to U.S. transportation data, cities continue to move ahead with plans to partner with state-owned companies.

Both Republican and Democratic lawmakers are concerned about the continued partnerships between American cities and Chinese companies to build transit systems, including rail cars and buses.

Those anxieties were aired at a Thursday Senate Banking Committee hearing on the threats posed by state-owned and operated transportation services. Two Chinese companies in particular, the railcar manufacturer China Railway Rolling Stock Corporation (CRRC) and bus and electric battery manufacturer Build Your Dreams (BYD), were the focus of much criticism about the potential security threats to transportation system data.

“The potential for an adversarial state actor to monitor the movements of American citizens, hack personal or government-issued devices, and collect intelligence on our military is a major security concern,” Sen. John Cornyn (R-Texas) said at the hearing, according to The Hill.

Last December, Cornyn was at the center of an effort to ban states or cities from using federal funds to buy passenger rail cars or buses from state-owned or controlled manufacturers. While the bill was signed into law as part of the 2020 National Defense Authorization Act, the law will not go into effect for two years, The Hill reported.

“Unfortunately, special interests were able to demand a two-year enforcement delay of some of this legislation’s critical components,” Cornyn said. “I am here today to ask for your help in ensuring this delay does not turn into a window the Chinese Communist Party and its state-controlled companies can further exploit.”

Cybersecurity and national security officials have expressed similar concerns about Huawei, TikTok and other Chinese companies, which are required by a Chinese law to participate in the country’s intelligence work and disclose sensitive data if asked.

However, many cities -- including Los Angeles, Chicago, Boston and Philadelphia -- are moving ahead with plans to buy from CRRC, the world’s largest manufacturer of metro rail cars. New York’s transit authority said in 2018 that the company had won its bid to build new railcars, offering $50 million of its own money.

A similarly low bid allowed CRRC to win the contest to build railcars for Chicago’s transit system. Sen. Sherrod Brown (D-Ohio) said Chinese subsidies give CRRC and BYD an unfair advantage.

“CRRC and BYD are two in a long line of examples of how China cheats its way ... into being a global leader into industry after industry,” Brown said. “Congress still needs to fully assess the risk associated with data of our transportation system being exposed to foreign actors.”

The two-year delay is not in effect for the Washington Metropolitan Area Transit Authority (WMATA), which is banned from accepting bids from CRRC to build its railcars.

 

For its part, CRRC has said that once the railcars are built and delivered to the transit agencies, the company does not have control over the transportation data. “CRRC is very dedicated and very supportive of the fact that there will be security measures, safety measures and transit agencies will want to be satisfied before they accept a car,” chief legal counsel Marina Popovic told The Hill last year.

Cities must be aware of the potential threats posed by Chinese technology and that the low-balling bids are not worth the security challenges, lawmakers said on Thursday.

“Allowing American trains and buses to become Trojan horses for these technologies on American soil is unacceptable,” Cornyn said.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.