Royal Navy drones and Chinese cameras: the ever-present supply-chain blind spot

On 10 August 2026, The Telegraph [1] revealed that the cameras fitted to the Royal Navy’s K3 Scout surface drones contained components of Chinese origin, and that those components were quietly emitting, towards an IP address in China, presence signals: simple messages confirming the device was online, not images or captured data. The story was quickly picked up in France, notably by Le Figaro [2]. Behind the headline, deliberately eye-catching, the technical and regulatory reality is, to my mind, more subtle and more interesting than the “spy drone” framing.
What the investigation found
The K3 Scout is an 8.4-metre uncrewed surface vessel (USV), capable of speed bursts up to 55 knots, built by the British defence contractor Kraken Technology Group. The Royal Navy ordered around twenty of them for roughly twelve million pounds under Project Beehive [3], assigning them to the Coastal Forces Squadron and to 47 Commando Royal Marines. The fleet entered service in March 2026, and part of the batch was earmarked for the Gulf, on freedom-of-navigation tasks in the Strait of Hormuz.
The anomaly surfaced during a routine vulnerability assessment, one with a cyber component, run from the Special Boat Service (SBS) headquarters in Poole. That is exactly where the value of the exercise lies: a regular check that examines an equipment’s actual behaviour, right down to its network communications, rather than trusting what its datasheet promises. The cameras were sending what are known as heartbeats: small, regular network packets, like a heartbeat, confirming that a device is online and working normally. Nothing could look more innocuous. Except that these beats were heading for China.
A heartbeat is not an exfiltration
The words matter here, because the nuance changes everything. A heartbeat does not prove data was stolen. The Ministry of Defence (MoD) stripped all internet connectivity from the cameras the moment the issue was found, and says it has no evidence that any data or system was accessed, compromised or transmitted externally [4]. Kraken Technology Group, for its part, explains that the cameras in question were third-party modules presented as compliant with the US National Defense Authorization Act (NDAA), the law whose Section 889 bars federal agencies from buying video-surveillance or telecommunications equipment from certain Chinese manufacturers. The label was therefore meant to guarantee the absence of sensitive Chinese components; yet the firm acknowledges “a small number of components originating from outside the UK”, bought from a supplier that had given security assurances. After a joint audit with the navy, Kraken says it is confident no sensitive information ever left its intended channels [5].
One reflex is worth noting: when questioned, the manufacturer foregrounds an American compliance label and a third-party supplier’s assurances, rather than its own responsibility as integrator. The move is understandable in crisis communication; the principle nonetheless remains that whoever assembles a system and places it on the market answers for it, and that a sub-assembly’s advertised compliance grants no exemption.
At this stage, then, no theft of data has been demonstrated. But stopping there would be an analytical mistake. What was discovered is an unmanaged outbound channel, embedded unknowingly in equipment used by special forces, at one of the most sensitive sites in the country. A channel able to send a presence signal to a remote server could, in theory, carry others, even if nothing, in this specific case, allows us to assert it. Risk is measured not only by what actually transited, but by what that channel made possible. Strict network separation would probably have rendered it harmless: a drone’s camera has no legitimate reason to reach the internet directly, still less a distant address. Segmenting sensors and filtering their outbound flows deprives this kind of behaviour of its destination from the outset. That is, in effect, what the navy did by cutting the cameras’ internet connectivity: the right reflex, but after discovery rather than by design.
The real issue: knowing what is inside our machines
The sharpest line in the whole affair comes from Alicia Kearns, a Conservative MP and the opposition’s shadow security minister: “If we cannot say with confidence what is inside our military equipment, we cannot say it is ours.” The problem is not that a Chinese camera ended up on a British drone. The problem is that, for want of a cybersecurity audit, no actor in the chain, from designer to integrator to military operator, knew precisely the component’s real bill of materials or its network behaviour.
This is a structural blind spot in the acquisition of autonomous platforms. These craft are not hulls: they are cyber-physical systems, made up of a multitude of sub-systems, cameras, radios, data links, navigation receivers, bought from third parties who in turn buy from others. Every sensor is a door. I have dug into this fragility before, in the context of autonomous maritime vehicles and cybersecurity risks, and I saw it very concretely in my report on an autonomous ferry in Finland: the more a platform delegates to its sensors, the more the trust placed in them becomes an asset to protect in its own right.
That the signal’s destination was a Chinese IP address is not neutral either, and it should be said without overplaying attribution. Nothing in the public record establishes that a state service was at the controls; a mundane vendor-telemetry explanation cannot be ruled out on paper. But the context, special-forces kit meant to operate in a Strait of Hormuz whose very navigation environment is already contested, makes the espionage hypothesis a legitimate operational concern, one not unlike the case of the ZPMC cranes.
But a drone is meant to be lost, isn’t it?
Manufacturers have a ready answer, and it is not absurd. A surface craft is built to be exposed, worn down, sometimes sacrificed. In the doctrine of attritable drones, you accept losing some: to swamp the adversary with numbers, to have them explode on contact like loitering munitions, or simply because you accept the risk of them falling into enemy hands. Hence the deliberate choice of low-cost drones: why not fit cheap, off-the-shelf gear, a consumer Starlink antenna, commercial cameras, electronic boards whose supply chain has not been vetted. On cost, the reasoning holds: why harden a sensor that will end up on the seabed?
Except it conflates two things. An expendable hull is neither expendable data nor an expendable channel. For as long as it floats, a cheap drone sees, hears and transmits, and if it carries a component that talks to the outside, it becomes, for its whole working life, a sensor working for whoever is listening at the far end. The purchase price of the craft has nothing to do with the value of what it captures, or with the sensitivity of the site it operates from. The K3 Scout did not talk because it was cheap or expensive; it talked because no one had looked at what its camera was doing on the network. Being expendable, or being under operational time pressure, is no reason to abandon sound cybersecurity principles.
What the framework already anticipated
None of this is a surprise to anyone following the field. In 2023 I contributed to France Cyber Maritime’s white paper on the cybersecurity of maritime drones and autonomous ships [6], which set out the strategic threat scenarios specific to these craft. Two of them describe the K3 Scout affair almost to the letter: a state actor pre-positioning through the supply chain (scenario SS3), and the theft of data for strategic espionage by going after equipment makers and integrators (SS5). A third-party component that opens a quiet channel from a drone in service is exactly the pre-positioning framed at the time as a hypothesis. The paper also recommended, without ambiguity, an exhaustive hardware and software mapping of every digital component on the craft (recommendation ORG7). That is precisely what was missing at Poole.
On the European side, that reflex is becoming an obligation. The Cyber Resilience Act (CRA) [7] requires, for any “product with digital elements” sold in the Union, security by design, vulnerability handling and a bill of materials (SBOM), with full application on 11 December 2027 and the first reporting duties from September 2026. For the growing fleet of civil and dual-use European maritime drones, hydrography, port surveillance, offshore inspection, that is a real shift: in time, you will no longer be able to place on the market a craft whose contents you cannot account for.
Two caveats, though, and they matter. First, the CRA explicitly excludes products designed exclusively for defence or national-security purposes. A military craft like the K3 Scout falls outside its scope, and its assurance rests on defence-procurement processes, the very ones that here failed to spot the component. Second, the CRA’s bill of materials is above all a software one, whereas the K3 Scout problem is hardware in origin. Even if it applied, the regulation would not necessarily have caught a camera whose chip came from elsewhere. This is why the hardware mapping called for by the white paper goes, on this particular point, further than the European text.
Audits, once again
One detail deserves a pause, because it carries the real positive lesson of the affair. It was neither a whistle-blower, nor luck, nor the adversary betraying its own presence that brought the problem to light: it was a routine security check. A methodical vulnerability assessment, applied to equipment already in service, at a sensitive site. Without it, the camera would probably still be beating.
We say it after every incident, and this one proves it once more: an audit is not a compliance box to tick, it is the only moment when you actually look at what a machine does, instead of believing what its datasheet says. Auditing once, on delivery, on the strength of the supplier’s assurances, is not enough. It has to be done over time, on real behaviour, network traffic included, even for equipment reputed to be compliant. The K3 Scout had written security assurances; it was the outbound packets, not the assurances, that eventually told the truth.
In France, this is precisely the aim of the security accreditation process (homologation) promoted by ANSSI, the national cybersecurity agency: before a system enters service, an authority must rule, on the basis of a risk assessment, on the security level actually achieved, and not on the supplier’s assurances alone. Such a safeguard is meant to raise the question of an equipment’s behaviour, network flows included, before deployment and not once it is operating in the field.
Who benefits from the disclosure?
There is a question we too rarely ask in front of this kind of story: why is this information coming out, and why now? A routine vulnerability assessment is an internal document. Its arrival on the front page of a national daily is a choice, not an accident.
Several readings coexist, none of them exclusive. The “spy drones” narrative sells better than “a poorly controlled presence signal”, and the framing already steers perception before anyone gets to the technical detail. Timing matters too: since Keir Starmer’s visit to China in January 2026, Britain’s defence dependence on components exposed to Beijing has been politically flammable, and a leak like this feeds that critical line directly. The ministry, by confirming quickly and playing the issue down, takes back control of the narrative and shows in passing that its checks worked. The opposition, meanwhile, gets a ready-made line of attack, as Alicia Kearns’s intervention illustrates.
None of this is illegitimate. A taxpayer who funded a twelve-million-pound fleet is entitled to know what was bought. But it is worth keeping in mind that the affair also works as an object of communication: a story about a Chinese component inside British kit feeds a narrative regardless of the real materiality of the risk. The very fact that it is published tells us as much about the state of the strategic debate as about the state of the cameras.
Expendable or capable: a choice will have to be made
This affair will not be remembered for the data it leaked, of which there was probably none. It matters because it shows, on a clean case, what assurance of autonomous naval platforms still lacks: real visibility over second- and third-tier suppliers, a characterisation of each payload’s network behaviour before it ever touches an operational site, and a demand for sovereignty that reaches all the way down to the bill of materials, not just the logo on the hull. The good news is that the routine check worked: the flaw was caught before deployment to the Gulf. The less good news is that it took a camera starting to beat for someone to notice we did not know what we had bought.
One last point, and not the least: let us not reduce the affair to a story about a Chinese component. Our own equipment, Western and even European, is not immune to the same failing, often in more presentable clothes: product telemetry, network “optimisation” or monitoring, remote maintenance. The mechanism is identical, an outbound flow that was neither explicitly intended nor characterised, and it can do worse than a mere heartbeat, because a trusted vendor never has to force the door: it is already inside. So the least you can do, when you regularly emit the position of a client’s terminal, is to warn them so they are aware. A word to the wise…
Which leaves the real underlying question, the one this affair poses without answering: can you hold in the same hand a drone you are willing to lose and a drone you entrust with intelligence? I tend to think not, and that we will have to accept two distinct families. On one side, genuinely expendable craft, mass-produced and cheap, confined to missions where compromising their data costs little, and cut off from anything sensitive. That does not exempt them from being robust: an expendable drone must still complete its mission, and resist anyone trying to neutralise it or turn it against us. If an adversary nation can take control of an expendable craft or disable it remotely, it has already won, and the money saved on the hardware is paid back dearly. For this family, cybersecurity therefore aims first at the availability and integrity of the mission. On the other side, capable craft, fewer and dearer, whose every component and every flow is known, where the protection of intelligence is added, reserved for sensitive waters. The K3 Scout’s sin, in the end, was wanting to be both at once: special-forces kit assembled with the casualness of a consumable.
Sources
- [1] The Telegraph, report of the investigation (10 August 2026)
- [2] Le Figaro, “Royaume-Uni : des drones de la Royal Navy ont secrètement transmis des données à la Chine” (in French, 10 August 2026)
- [3] Navy Lookout, order of 20 K3 Scout USVs under Project Beehive
- [4] GB News, MoD response and denial
- [5] PA Media via AOL, details of the affair and Kraken Technology Group statements
- [6] France Cyber Maritime, white paper “Cybersecurity of maritime drones and autonomous ships” (2023, in French)
- [7] Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex
Olivier JACQ, President and founder of CYBERMOOV Consulting.