Surveillance drones of the British Royal Navy, used by the country’s elite special forces and equipped with cameras containing Chinese-made components, were sending data to an IP address in China, according to a revelation by the Telegraph, raising concerns about security levels within the armed forces of Britain.
Specifically, it was discovered that the K3 Scout unmanned vessels, which are used by the Royal Marines, were transmitting so-called “heartbeat” communications to an IP address in China. These signals are designed to notify a remote device that the cameras are connected and operating normally.
The discovery raised national-security concerns and prompted the British Ministry of Defence to disconnect the cameras from the Internet.
Officials insist that there is no evidence indicating that sensitive military information or Ministry of Defence systems were compromised, or that data was transmitted abroad.
The revelation, however, raises new questions about the security of the British armed forces’ supply chains and, above all, about the extent to which Chinese technology has managed to penetrate highly sensitive systems used by special forces.
The fleet of K3 Scouts, worth £12 million, has been in operational use since March and was supplied with equipment by the British defence company Kraken Technology Group. Kraken, for its part, had obtained the cameras from a third-party supplier, which had provided assurances regarding their security.
A subsequent investigation revealed that the cameras contained components manufactured in China and were communicating with an IP address in the country. The incident was considered serious enough to raise concerns about the potential exposure of personnel at the Special Boat Service (SBS) facilities in Poole, Dorset.
There are also fears that the cameras may have been operating near sensitive meetings attended by senior special-forces personnel.
Particular concern has been caused by information indicating that the cameras could remain active even when the drones themselves had been switched off.
A source familiar with the case told the Telegraph that the unmanned vessels had been used during preparations for a possible British defence package that was being planned to protect freedom of navigation through the Strait of Hormuz. The same source described the revelation as a serious failure in the procurement process, arguing that confidence in the system in question has now been lost.
Blow to the Royal Navy’s Project Beehive
The incident represents a significant blow to Project Beehive, the Royal Navy programme aimed at integrating unmanned vessels into operations alongside conventional warships.
The K3 Scouts form part of the Navy’s surface fleet and are used by the Coastal Forces Squadron and the Royal Marines of 47 Commando.
The unmanned vessels have been designed to provide British forces with enhanced surveillance and operational capabilities while simultaneously reducing the risk to personnel.
The K3 Scout can carry a payload of up to 600 kilograms and operate continuously for up to 30 days.
The system has also been acquired by US Special Operations Command and has participated in NATO exercises and trials in the Baltic.
What the Ministry of Defence and Kraken Say
The British Ministry of Defence, meanwhile, announced that the vulnerability was identified during a routine cybersecurity inspection.
According to the ministry, the investigation found no evidence that Ministry of Defence information or systems had been accessed or compromised, nor that data had been transmitted outside approved channels.
“The assurance and control processes we have in place are designed to identify and address potential vulnerabilities promptly, and we continue to conduct regular security checks on our systems and equipment,” a ministry spokesperson said.
Kraken Technology Group announced that it was aware that some of the cameras used in its systems contained a small number of components originating from countries outside Britain.
The company said that it had conducted a full investigation jointly with the Royal Navy and that it had been established that no sensitive information had been disclosed outside approved channels. It added that all potential vulnerabilities had been identified and addressed.
The specific cameras had been classified as NDAA-compliant, an American defence-procurement standard intended to ensure that equipment does not contain components from prohibited manufacturers.
Ask me anything
Explore related questions