Cameras on Royal Navy K3 Scout drone boats sent automated signals to a Chinese internet address for five months before connectivity was cut.
Cameras on Royal Navy K3 Scout drone boats sent automated signals to a Chinese internet address for five months before connectivity was cut.

Cameras on Royal Navy K3 Scout drone boats sent automated signals to a Chinese internet address for five months before connectivity was cut.
Cameras on Royal Navy K3 Scout drone boats transmitted automated status signals to a Chinese internet address for five months, exposing a supply-chain gap that Western defense procurement has yet to close.
"A routine cyber vulnerability assessment identified an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy. A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally," a Ministry of Defence spokesperson said.
The affected cameras, part of the Night Navigator 3000 series made by Canadian firm Current Scientific Corporation, were fitted to the 8.4-meter K3 Scout, a £12 million fleet of 20 uncrewed vessels that entered service with 47 Commando Royal Marines in March under Project Beehive. The signals, known as heartbeat communications, confirmed the devices were online and carried device identifiers, network addresses and timestamps — metadata that, aggregated over weeks, can map a vessel's operational pattern of life. The MoD stripped internet connectivity from the cameras after the discovery at the Special Boat Service's headquarters in Poole, Dorset.
The episode lands as the K3 Scout — which Kraken has sold to US Special Operations Command under a $49 million contract and which took part in NATO's Baltic Task Force X exercise in June — was being prepared for a deployment to the Strait of Hormuz, the waterway carrying about a fifth of global oil trade. It also sharpens a debate over whether "NDAA-compliant" labels, which ban five named Chinese manufacturers, can catch sub-components from unlisted suppliers whose firmware phones home.
The cameras carried an NDAA-compliant designation, referring to Section 889 of the 2019 US National Defense Authorization Act, which bars federal agencies from buying surveillance equipment produced by five named Chinese companies — Hikvision, Dahua, Huawei, ZTE and Hytera. The ban operates at the level of primary manufacturers, not the chips, firmware or wireless modules inside a finished product. A camera assembled in a factory outside China can truthfully carry the label even if its system-on-chip or communications module comes from an unlisted Chinese supplier whose firmware establishes outbound connections to Chinese-operated servers. The Intercept documented in 2021 that US military branches had purchased white-label cameras containing Hikvision or Dahua hardware, a gap hardware researchers and CISA have flagged as the next frontier of supply-chain risk.
China's National Intelligence Law of 2017 requires all Chinese organizations and citizens to support state intelligence efforts, while its Data Security Law of 2021 and Cybersecurity Law of 2017 impose data-localization and government-access provisions on companies under Chinese jurisdiction. That legal framework means the operator of the IP address that received the K3 Scout heartbeats could be compelled to make the connection available to Beijing, regardless of whether the signals carried intelligence value.
The K3 Scout is central to the Royal Navy's Project Beehive, an initiative to pair crewed warships such as the Type 26 and Type 31 frigates with smaller autonomous vessels. The 8.4-meter boat reaches 55 knots, operates continuously for 30 days and carries a 600-kilogram payload bay that can be reconfigured for surveillance, electronic warfare, logistics or tube-launched loitering munitions. That modular, open-architecture design is a strategic asset — and the source of the vulnerability, since every third-party payload brings its own processors, firmware and network interfaces.
The incident also lands at a delicate diplomatic moment. Prime Minister Keir Starmer visited China in January, the first British premier to do so since 2018, under a Labour strategy of cooperating where possible while competing where necessary. The UK's Strategic Defence Review, published in June, called for expanding dual-use technologies to make the defense industrial base more resilient to supply-chain shocks — the exact kind of exposure this episode revealed in miniature.
The structural fix is a Hardware Bill of Materials, a standardized format CISA released in 2023 that documents every component, chip, firmware version and supplier down to the sub-assembly level. On July 20, the White House signed an executive order requiring US defense contractors to submit complete indentured bills of materials tracing all components back to raw-material origin. Britain has no equivalent domestic requirement in force.
Conservative shadow security minister Alicia Kearns called for an urgent audit of all military equipment for hidden Chinese components. "If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign," she said. A defense official told The Telegraph the episode was "a major failure to check origins of components and we have lost confidence in the platform."
The broader lesson extends beyond the UK. Ukraine burns through roughly 10,000 drones a month, and Chinese parts remain far cheaper than Western alternatives — a German electric engine costs five to 10 times more than a Chinese one, said Marc Wietfeld, chief executive of German land-drone maker Arx Robotics, which has rooted its supply chain in Europe. The K3 Scout episode shows that even equipment marketed as British-made can depend on a global supply chain running through strategic rivals, and that a single third-party camera component was enough to create the exposure a domestic manufacturing push is meant to prevent.
This article is for informational purposes only and does not constitute investment advice.