Skip to main content
CybersecurityVulnerability Management

Royal Navy's Drone Boats Expose Cyber Vulnerabilities

Royal Navy's unmanned surface vessel on calm waters with camera system mounted.

"The first duty of government is national security, and we take the security of our equipment, networks and data extremely seriously," the Ministry of Defense told TWZ after a routine vulnerability check flagged a problem with cameras fitted to Kraken K3 Scout unmanned surface vessels.

Ministry of Defence: routine assessment, immediate mitigation

The U.K. Ministry of Defense (MOD) told TWZ that the issue was discovered during “a routine cyber vulnerability assessment.” After the assessment the MOD said it “identified an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy,” and removed all internet connectivity from the affected cameras. The ministry added that its follow‑up investigation “found no evidence of MOD data or systems being accessed, compromised or transmitted externally.” In public comments the MOD emphasised that its “assurance and testing processes are designed to identify and address potential vulnerabilities early” and that it continues “to undertake routine security activity across our systems and equipment.”

The Telegraph report: cameras reportedly talking to an IP address in China

The Telegraph, citing an unnamed defence source, reported that Chinese‑made components in cameras aboard Kraken K3 Scout USVs “secretly sent data to China,” and said investigators found cameras transmitting “heartbeat communications” to an IP address in China. Heartbeat communications, the report noted, are periodic signals confirming a device is online; the MOD view, as stated to TWZ, was that the wider investigation found no evidence of MOD data being transmitted externally.

Kraken Technology Group, third‑party sourcing, and the camera vendor question

Kraken Technology Group told The Telegraph it was aware “that some third‑party, NDAA‑compliant cameras had a small number of components originating from outside the United Kingdom.” Kraken and the Royal Navy conducted a full audit and, Kraken said, are “confident no sensitive information has ever been shared outside of intended channels, and any potential vulnerabilities have been identified and closed.” The cameras in question were sourced by Kraken from an undisclosed third party, which the reporting says is rumoured to be Canadian; a social media post cited in reporting identified the EO/IR cameras as the Current Scientific Corporation Night Navigator 3000 series.

Operational context: where the K3 Scout is used and what was planned

The K3 Scout USVs were acquired under a deal worth around $16.2 million (approximately £12 million) and entered Royal Navy service in March. They are operated by the Coastal Forces Squadron and 47 Commando Royal Marines. The platform is designed to carry a 1,300‑pound payload and to operate continuously for 30 days. The K3 has been used by U.S. Special Operations Command and has participated in NATO trials in the Baltic Sea. The Telegraph reported that the British‑operated USVs were due for deployment to the Persian Gulf, where U.K. special forces planned to use them to help secure freedom of navigation in the Strait of Hormuz.

Political reaction: Conservative Party calls for urgent audit; Alicia Kearns comments

The opposition Conservative Party said the government should “urgently audit” MOD equipment for evidence of Chinese components that pose cybersecurity risks. Alicia Kearns, the shadow security minister, posted on X that “This is not a procurement blunder, it is the predictable price of our dependence on Chinese components.” Kearns added: “Under Chinese law, every Chinese company is legally bound to assist Beijing’s intelligence services and forbidden from ever telling us. So when cameras built on Chinese parts are found recording our special forces: their faces, training and operations, with data flowing back to Chinese IP addresses, we should not be surprised; we should be furious that we still haven’t woken up to the realities of the threat we face.”

Project Beehive and the Defence Investment Plan: scale, speed, and procurement risk

The discovery comes as the MOD pushes autonomous systems into the centre of future force structure. The U.K. Defence Investment Plan allocates more than £5 billion for drones and related capabilities over four years, and Project Beehive began with the procurement of 20 USVs — the Kraken K3 Scout was the selected platform. TWZ had previously warned that a rapid fielding rhythm and an emphasis on autonomous systems create exposure to supply‑chain and component risks; the MOD’s identification and mitigation of the current camera issue illustrates that dynamic in practice.

The facts in this case are specific: cameras with components originating outside the United Kingdom were found to be emitting heartbeat traffic to an IP address in China according to reporting; MOD teams removed internet access to the cameras and report no evidence that MOD data was exposed; Kraken says audits have closed any vulnerabilities. What remains is a procedural question rooted in procurement and supply‑chain controls: will the audit and removal of connectivity be sufficient to reassure operators that similar component origins will not recur as the Royal Navy pushes more autonomous platforms into service?

Source: https://www.twz.com/sea/chinese-components-in-royal-navys-new-drone-boat-raise-cyber-security-concerns