CRBC News
Security

Royal Navy Drone Cameras Sent ‘Heartbeat’ Signals To A Chinese IP — What Went Wrong?

Royal Navy Drone Cameras Sent ‘Heartbeat’ Signals To A Chinese IP — What Went Wrong?
Image: Telegraph

The Royal Navy's K3 Scout vessels were found sending “heartbeat” signals to a Chinese IP address during a routine MoD cyber check, though investigators reported no evidence of data exfiltration. Supplier Kraken Technology Group said some third‑party cameras were NDAA‑compliant but contained components originating outside the UK. The case exposes a gap between product-level certification and deep component provenance, and is likely to prompt tighter traceability rules and tougher audits in defence procurement.

Components inside Royal Navy K3 Scout uncrewed surface vessels were discovered quietly sending “heartbeat” signals to an IP address in China during a routine Ministry of Defence cyber assessment. The MoD says investigators found no evidence that sensitive data was accessed, compromised, or transmitted externally, but the incident highlights a worrying gap between product-level certification and the provenance of nested components.

Key Facts

  • Royal Navy K3 Scout uncrewed surface vessels — in Royal Marines service since March 2026 — were found transmitting heartbeat communications to a Chinese IP address.
  • A heartbeat signal indicates a device is online and, according to BBC reporting, can also carry location or status data.
  • The activity was detected during the MoD’s routine cyber vulnerability assessment; internet access to the affected subsystem was removed and a formal investigation followed.
  • The MoD reported no evidence of data exfiltration: “A thorough investigation found no evidence of MoD data or systems being accessed, compromised, or transmitted externally.”
  • Supplier Kraken Technology Group acknowledged that some third-party cameras were NDAA-compliant but contained components “originating outside the UK.” A joint Kraken–Royal Navy audit reportedly found no sensitive information left intended channels.
“A thorough investigation found no evidence of MoD data or systems being accessed, compromised, or transmitted externally.” — Ministry of Defence

What This Means

NDAA certification — and similar product-level checks — verifies the unit named on the label, not every sub-component nested several layers deep. That verification gap is where supply-chain risk can hide: parts sourced through subcontractors may not be individually origin-verified even when the finished product meets a checklist.

This episode sits within a broader UK–China technology and security context: recent moves to remove certain vendors from critical infrastructure, public warnings from intelligence services, and growing scrutiny of foreign technology in sensitive systems. Similar cases involving surveillance apps and other devices show how state-linked or covert data collection can surface from ordinary hardware or software deployments.

Likely Consequences

Procurement and security teams should expect tighter requirements for component traceability, more rigorous audits of subcontractor supply chains, and tougher questions for system integrators. Regulators in Europe have already restricted some cloud providers from handling sensitive government data — a sign that supply-chain scrutiny is intensifying globally. The incident did not result in a confirmed breach, but the underlying vulnerability underscores the limits of current certification practices.

Bottom line: The reported breach apparently did not occur, but the vulnerability did. In defence procurement, that distinction offers little comfort and should prompt more exhaustive supply-chain verification.

Help us improve.

Related Articles

Trending