Royal Navy Strips Internet Access From K3 Scout Drone Cameras Caught Signaling China
A routine cyber vulnerability assessment found cameras on Royal Navy K3 Scout drones sending heartbeat signals to an IP address in China, prompting the Ministry of Defence to strip the affected...
Cameras fitted to Royal Navy K3 Scout uncrewed surface vessels were found sending automated “heartbeat” signals to an IP address in China, the Telegraph first reported on August 9, in an account confirmed and expanded by The Register. The Ministry of Defence says the transmissions surfaced during a routine cyber vulnerability assessment of the drone boats, which entered service with the Royal Marines in March, and that it has since stripped internet connectivity from the affected cameras.
Table Of Content
“A routine cyber vulnerability assessment identified an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy,” an MoD spokesperson told The Register. “A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally.” Investigators have described the outbound traffic as a “heartbeat” signal, a routine ping confirming a device is powered on and connected, rather than a transfer of operational data.
A Compliance Label That Didn’t Catch the Problem
The K3 Scout is an 8.4-meter uncrewed surface vessel built by Kraken Technology Group and acquired by the Royal Navy under Project Beehive, a £12.3 million contract for 20 boats assigned to the Coastal Forces Squadron and 47 Commando Royal Marines, according to DroneXL. A Kraken spokesperson told the Telegraph that some of its third-party, NDAA-compliant cameras contained “a small number of components originating from outside the UK.” The Telegraph’s reporting identified those components as Chinese-made and the destination of the heartbeat traffic as a device located in China.
NDAA compliance, in defense procurement, certifies that hardware contains no parts from the Chinese manufacturers named in Section 889 of the 2019 National Defense Authorization Act, and the label has become a default trust signal for government buyers on both sides of the Atlantic. DroneXL reported that the naval affairs site Navy Lookout has unofficially identified the camera involved as a Night Navigator 3000 series unit from Current Scientific Corporation, a Canadian manufacturer, though neither the Telegraph nor the MoD has named the supplier publicly, and DroneXL cautions that identification should be treated as context rather than confirmation. Kraken says a full audit with the Royal Navy found no evidence that sensitive information left intended channels and that the vulnerabilities have been closed.
The Timing Complicates a Fast-Moving Drone Program
The discovery lands awkwardly for a program the Royal Navy has been racing to expand. Defence Blog reported, citing Telegraph defense sources, that the affected K3 Scouts had been earmarked for a planned British deployment to the Strait of Hormuz to help protect freedom of navigation for commercial shipping, and that the discovery reportedly happened at the Special Boat Service’s headquarters in Poole, Dorset. One defense source told the Telegraph, as relayed by DroneXL, “we have lost confidence in the platform.”
The K3 Scout is not a UK-only program, and it is not just a camera platform. Army Recognition notes the vessel can be configured for surveillance, force protection, C4ISR, logistics, and strike-support missions. Defence Blog reported that U.S. Special Operations Command awarded Kraken a $49 million contract in November 2025 to accelerate the same platform for American forces, and that Anduril Industries said in April it would build Kraken-designed vessels at its own U.S. facilities. Concern about Chinese-linked cyber activity against UK targets has been building for months: the National Cyber Security Centre warned in April about covert networks built from compromised routers and edge devices, and a China-linked group was accused in January of spying on the phones of aides to UK prime ministers, per the Register. An MoD spokesperson said security assurance work is continuous: “Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment.”








No Comment! Be the first one.