UK MoD strips internet from Royal Navy sea drones over Chinese IP links
A routine cyber assessment revealed K3 Scout drone cameras were sending heartbeat signals to a Chinese IP address.
The UK Ministry of Defence (MoD) has stripped internet connectivity from cameras on its new K3 Scout sea drones after discovering the hardware was communicating with a Chinese IP address. The vulnerability was identified during a routine cyber vulnerability assessment, prompting an immediate investigation into the fleet's security.
The affected vessels are K3 Scout sea drones supplied by the company Kraken. According to the MoD, the cameras contained Chinese-made components that transmitted "heartbeat" communications—routine signals used to indicate that equipment is online—to an IP address located in China. In response, the MoD removed all internet connectivity from the affected cameras to neutralize the risk. A spokesperson for the MoD stated that a thorough investigation found no evidence of MoD data or systems being accessed, compromised, or transmitted externally.
Supply chain vulnerabilities
The Royal Navy is currently acquiring 20 K3 Scout vessels under Project Beehive. These drones are intended for a variety of high-stakes roles, including maritime awareness, force protection, logistics, and precision strikes, as well as general training and experimentation. The discovery of Chinese components in these systems comes at a time when the UK and most NATO allies have implemented strict bans on Chinese hardware in military equipment due to persistent espionage concerns.
While the primary contractor, Kraken, had provided security assurances for the platforms, the vulnerability originated further down the supply chain with a third-party camera supplier. This gap highlights the systemic difficulty military organizations face when vetting the deep layers of modern electronics manufacturing, where a single sub-component can introduce a security flaw into an otherwise secure platform.
Strategic implications
This incident is a significant political embarrassment for the MoD, as it reveals a failure in the vetting process for sub-contractors despite an explicit policy against Chinese military hardware. The fact that "heartbeat" signals were reaching a foreign IP address underscores the risk of "hidden" components acting as beacons, potentially signaling the operational status or presence of sensitive naval assets to a foreign power.
Next steps
While the MoD maintains that no data breach occurred, the incident is likely to trigger a more rigorous audit of third-party components across other Project Beehive assets and wider Royal Navy procurement. Defense analysts will be watching to see if the MoD implements stricter certification requirements for sub-tier suppliers to prevent similar vulnerabilities in future autonomous systems.