Skip to main content
CybersecurityHacking

Royal Navy drones transmit data to China in cyber vulnerability test

Royal Navy drone boat on calm waters with clear sky background.

"A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally," a Ministry of Defence spokesperson told The Register, after cameras on Royal Navy drone boats were observed sending signals to an IP address in China.

Kraken Unmanned Surface Vessel sub-system

The UK Ministry of Defence confirmed a routine cyber vulnerability assessment picked up cameras aboard Royal Navy drone boats phoning home to an IP address in China. The MoD described the matter as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands the data consisted of a "heartbeat" signalling that the camera was online and functioning normally.

Despite the apparently small payload — an "I'm alive!" signal rather than bulk data — the unexpected transmission from military equipment to an IP address in China prompted internal scrutiny and public disclosure. The Register contacted unmanned surface vessel supplier Kraken for more information but, at the time of publication, had "yet to receive a reply."

MoD investigation and public assurances

The MoD spokesperson provided two explicit assurances to The Register. First: "A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally." Second: "Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment."

The same spokesperson emphasized the security priority: "The first duty of government is national security, and we take the security of our equipment, networks, and data extremely seriously." Those statements frame the incident as detected and managed within existing assurance processes rather than as an active compromise of MoD systems.

Third‑party camera supplier and supply‑chain questions

Reports indicate the chatty components were cameras that Kraken had sourced from a third‑party supplier. That detail shifts the technical question from the unmanned vessel platform itself to elements in the equipment supply chain: who designed the cameras, what firmware they run, and what telemetry they are configured to send by default.

Commentators cited by The Register used the episode to underline a broader lesson: "every component in a defense supply chain needs testing rather than relying on a supplier's assurances." The narrow character of the observed transmission does not remove the governance and audit challenges posed when military systems incorporate third‑party hardware that communicates externally.

National Cyber Security Centre advisory and recent China‑linked activity

The timing of the discovery matters because of a broader security backdrop. In April, the National Cyber Security Centre issued a security advisory about covert networks constructed from compromised routers and other edge devices. The Register also noted that "Beijing is also rarely far from the headlines when spying and covert operations are involved," citing a separate report from January in which a China‑linked group was accused of spying on the phones of aides to UK prime ministers.

Those references establish why an unexpected connection from military hardware to an IP address in China is alarming to security watchers, even when the observed packet was a heartbeat rather than substantive MoD data.

What this means for technologists, policymakers, and procurement leaders

  • Technologists and security teams: will need to continue and possibly broaden routine vulnerability sweeps and telemetry monitoring across unmanned platforms, with particular attention to third‑party sensors and their "phone‑home" behavior.
  • Policymakers and regulators: will be watching how supply‑chain assurances are audited in practice; the MoD framed its response around existing assurance processes and routine security activity, but the incident highlights questions about oversight of third‑party components.
  • Procurement leaders within defence: must consider contract requirements and acceptance testing that explicitly address outbound network behaviour for sourced hardware, given the report that the cameras were purchased from a third‑party supplier.

The episode — a heartbeat packet traced to an IP in China, a confirmed MoD investigation that found no evidence of data exfiltration, and unanswered questions about third‑party camera provenance — combines technical detail with procurement and policy implications. Kraken has not responded to requests for comment, and the MoD says its assurance processes are in place and active; the remaining concrete question is whether routine checks will be widened to prevent similar surprises, or whether further disclosures about supplier configurations will be required to satisfy sceptics.

Original story: The Register