Royal Navy naval drone cameras secretly sent data to China
Cameras mounted on Royal Navy surveillance drones bound for special forces missions in the Gulf were secretly transmitting signals to an IP address inside China, The Telegraph reported, citing an investigation by the newspaper’s Richard Holmes.
The drones in question are Kraken K3 Scout uncrewed surface vessels, roughly 8.4-meter (28-foot) unmanned speedboats built by the British defense company Kraken Technology Group and used by the Royal Navy’s special forces community, including the Special Boat Service, for surveillance and reconnaissance missions along contested coastlines.
The Telegraph reported that the electro-optical and infrared cameras fitted to the boats, imaging systems that let operators see targets in both visible light and heat signatures, were manufactured by Canadian company Current Scientific Corporation under its Night Navigator 3000 series, but contained components sourced from outside the UK that were found sending what investigators described as “heartbeat communications,” routine signals confirming a device is powered on and connected, to a device located in China. The discovery reportedly happened at the Special Boat Service’s headquarters in Poole, Dorset, after the roughly $16.2 million (£12 million) fleet of K3 Scouts entered service with the Royal Marines in March.
The timing makes the discovery particularly sensitive. Defense sources told The Telegraph the affected drones had been earmarked for a planned British deployment to the Strait of Hormuz, the narrow waterway between Iran and the Arabian Peninsula through which roughly a fifth of the world’s oil supply passes, as part of a mission aimed at protecting freedom of navigation for commercial shipping in the region. The Ministry of Defence, Britain’s equivalent of the Department of War, said the transmissions were uncovered during a routine cyber vulnerability assessment of the K3 fleet, and insisted that a subsequent investigation found no evidence that sensitive information or military systems had actually been accessed or compromised, though the department stripped all internet connectivity from the affected cameras as a precaution once the issue surfaced.
The K3 Scout itself sits at the center of one of the Royal Navy’s most closely watched modernization efforts. The Defence Blog previously reported that the Royal Navy ordered 20 of the vessels from Kraken in March 2026 under a roughly $16.5 million contract as part of Project Beehive, an initiative designed to build what officials call a “Hybrid Navy,” a fleet structure pairing large, conventionally crewed warships like the Type 26 and Type 31 frigates with smaller, disaggregated, autonomous vessels that can be produced and deployed far faster than traditional shipbuilding allows. Capable of reaching speeds up to 55 knots and operating continuously at sea for 30 days, the K3 Scout can be configured to carry troops, cargo, tube-launched loitering munitions known as suicide drones, or explosives for one-way attack missions, and the platform has already drawn interest well beyond Britain’s own military. U.S. Special Operations Command awarded Kraken a $49 million contract in November 2025 to accelerate development of the K3 Scout for American forces, and Anduril Industries announced in April that it would manufacture two new Kraken-designed vessels at its own U.S. facilities to meet Navy requirements for small, fast uncrewed boats, a partnership that framed Kraken’s hull designs as proven and combat-tested.
Kraken Technology Group, the Portsmouth-based company that builds the K3 Scout, said it had received assurances about the cameras’ security before integrating them into the vessels. A company spokesperson addressed the discovery directly.
“We are aware that some third-party, national defence authorisation act-compliant cameras had a small number of components originating from outside the UK. After a full audit by both Kraken and the Royal Navy we are confident no sensitive information has ever been shared outside of intended channels and any potential vulnerabilities have been identified and closed,” a Kraken spokesperson said.
The Ministry of Defence offered its own account of how the issue came to light and what the subsequent review found.
“A routine cyber vulnerability assessment identified an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy. A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally,” an MoD spokesperson said.
The episode lands at an awkward moment for Britain’s broader defense procurement strategy, which has increasingly leaned on smaller, agile domestic startups like Kraken as an alternative to slower-moving industry giants such as BAE Systems, Babcock and Rolls-Royce.
The UK’s Strategic Defence Review, published in June, explicitly called for expanding “dual use” technologies that can serve both civilian and military purposes as a way of making Britain’s defense industrial base more resilient to supply chain shocks, precisely the kind of vulnerability this incident has now exposed in miniature. Even equipment marketed and assembled as British-made, it turns out, can still depend on a global supply chain running through countries Western militaries consider strategic rivals, and a single third-party camera component was apparently enough to create exactly the kind of exposure that a domestic manufacturing push is meant to prevent.
Content preview only. Full article available at source. View Full Article
Cameras on Royal Navy surveillance drones transmitted data to an IP address in China, discovered during a cyber vulnerability assessment. The drones, part of a $16.2 million fleet, were intended for missions in the Strait of Hormuz. The Ministry of Defence confirmed no sensitive information was compromised, but the incident highlights vulnerabilities in military technology supply chains.
- Royal Navy drones were found transmitting signals to China.
- The affected drones are Kraken K3 Scout vessels.
- The issue was discovered during a cyber vulnerability assessment.
- No sensitive information was confirmed to be compromised.
- The incident raises concerns about supply chain vulnerabilities.