Belgian army dumps China-built DS 9 over spying fears

The Belgian army will stop buying Chinese-built service cars for its top brass from September, citing growing concerns over espionage and cybersecurity. The decision means the DS 9, a French-branded luxury saloon built exclusively in China, will no longer be procured for the general staff.

The case illustrates how quickly the security debate around connected cars is shifting in Europe. Belgium is not the first country to act. Poland has already barred Chinese-made vehicles from protected military installations. At the same time, the British Ministry of Defense imposes restrictions on sensitive sites and warns personnel not to discuss classified matters in connected vehicles.

Lieutenant-General Frédéric Goetynck confirmed to VTM Nieuws that the Belgian Defense organization now assesses the threat differently from when the current fleet was ordered.

The DS 9 remains technically reliable, he said, but today’s security environment makes the vehicle’s origin and digital architecture more important.

The Belgian military intelligence service ADIV has already examined part of the fleet and issued internal security guidelines. A new procurement contract is now being prepared in which security risks will carry considerably more weight.

The awkward detail is that the DS 9 is not a Chinese-brand car. DS Automobiles, a brand of Stellantis, is headquartered in France, but its flagship saloon is manufactured in China. That makes the Belgian decision more complex than a straightforward ban on brands such as BYD, MG, or NIO.

The car has become a sensor platform

The main concern is not the battery or even the GPS receiver itself. Modern connected cars continuously collect and process information through cameras, microphones, navigation systems, mobile-network connections, smartphone integration, and over-the-air software updates.

For a senior military officer, location history alone can reveal potentially sensitive patterns: visits to bases, meetings, homes, and operational locations.

Cabin microphones and paired smartphones introduce another potential attack surface, while exterior cameras and sensors could, in theory, gather information about restricted sites.

Remote software access is an even more fundamental issue. Connected vehicles communicate with manufacturer servers for diagnostics, updates, and app functions. That creates legitimate digital pathways into the car, but pathways that also need to be protected from abuse, compromised suppliers, or state interference.

There is no public evidence that the Belgian DS 9s have actually been used for espionage, nor has Defense said that ADIV discovered a Chinese backdoor. The decision, therefore, appears to be precautionary rather than a response to a confirmed spying incident.

Poland has already gone further

Belgium is not alone. Earlier this year, Poland’s General Staff prohibited the entry of Chinese-manufactured vehicles into protected military facilities. Polish military personnel are also forbidden from connecting official phones to the infotainment systems of such cars.

Britain takes a broader risk-based approach. The Ministry of Defense has introduced restrictions at some sensitive locations and warned that the issue concerns not only Chinese vehicles. Its security policies increasingly focus on what a vehicle can record, transmit, and receive.

Norway has provided one of Europe’s clearest demonstrations of the underlying technology risk. Oslo public transport operator Ruter tested a Chinese Yutong electric bus and found that the manufacturer had remote access through the mobile network for software updates and diagnostics.

In theory, Ruter concluded, this access could be used to stop the bus or make it inoperable. At the same time, its tests found no evidence that the bus cameras were transmitting images.

That distinction matters. Connectivity itself is the vulnerability. Nationality determines how governments assess the geopolitical risk attached to it.

The EU also raises the alarm

The issue has now reached the EU level. In February, the European Commission and the NIS Cooperation Group warned that connected and automated vehicles create new cybersecurity risks because they process large amounts of sensitive data and can potentially be weaponized.

Brussels wants member states to reduce dependence on high-risk suppliers in critical vehicle systems, particularly connectivity, software, data processing, and remote vehicle control.

For the Belgian army, however, eliminating every Chinese component will be practically impossible. Goetynck acknowledged as much, saying that a modern car without a single Chinese part probably does not exist.

That may ultimately be the bigger challenge. A car assembled in Europe can contain components from China, including batteries, chips, cameras, and communications hardware. In contrast, a French-branded car built in China may still run software and cloud services controlled from Europe.

The question for Defense procurement is therefore becoming less about where the badge or even the factory comes from and more about who controls the car’s data, software, and remote access. In today’s connected vehicle, that may prove far more important than where the body was welded together.

You Might Also Like

Create a free account, or log in.

Gain access to read this article, plus limited free content.

Yes! I would like to receive new content and updates.