Shows risks of long supply chains

Image:
A component in the K3 Scout drone was found to be sending a signal back to China. Image: Kraken Technology Group
The Ministry of Defence says there is no evidence that sensitive data or military systems were compromised, after a Chinese-made component was discovered in new Royal Navy surveillance drones.
The issue was identified during a routine cybersecurity assessment of the K3 Scout uncrewed surface vessels, which are operated by the Special Boat Service from its headquarters in Poole.
The £12m fleet of 20 drones has been in operation since March. The vessels can conduct surveillance remotely and are designed to carry out a range of missions, from maritime surveillance and force protection to logistics and precision strikes.
Cameras fitted to the drones were found to send a “squark” – sometimes described as a heartbeat communication – to an IP address in China.
Such signals can indicate that a device has been switched on and is operating correctly. Depending on the system, they can also contain information such as location data.
However, the MoD said an investigation had found no evidence that its data or systems had been accessed, compromised or transmitted outside authorised channels.
“Our assurance and testing processes are designed to identify and address potential vulnerabilities early,” an MoD spokesperson said.
The drones were supplied by British defence company Kraken Technology Group, which obtained the cameras from a third-party supplier.
Kraken said it had carried out a full audit with the Royal Navy and was confident that no sensitive information had been shared.
Security concerns over Chinese technology
The discovery is nevertheless embarrassing for the MoD, particularly because Nato countries have increasingly sought to remove Chinese-made components from sensitive military systems due to concerns over espionage and cybersecurity.
The specific camera used had been approved under the US National Defense Authorization Act (NDAA), which restricts the use of equipment from certain Chinese manufacturers.
NDAA compliance is widely used as a procurement standard across the uncrewed systems industry, including by the US Navy.
Lee Hannaford, director of defence, national security and intelligence at consultancy Larkspur International, said Chinese-made devices could create risks because some were designed to maintain connections with their manufacturers.
“Once established, these channels can be leveraged…for data collection, command-and-control, or pre-positioning for disruption,” he said.
China-linked cyber threats have become an increasing concern in recent years.
In April the National Cyber Security Centre (NCSC) issued a warning about covert networks built using compromised routers and other internet-connected devices.
In January, a group linked to China was accused of targeting the mobile phones of aides to former UK prime ministers.
Supply chains remain a challenge
The episode points to a broader supply-chain challenge for Western defence industries, which are under pressure to reduce Chinese reliance while keeping technology and components affordable.
Even equipment designed for military use can contain components sourced through several layers of suppliers, making it difficult to establish exactly where every part originates.
Alessio Patalano, Professor of War and Strategy in East Asia at King’s College London, said the episode demonstrated the security risks created by highly interconnected supply chains: “This incident does highlight one specific challenge: the downside of deeply interdependent supply chains in which China sits at the core of elements of our everyday life.”
Governments should seek to ensure that vulnerabilities could not easily be exploited by Beijing, Patalano added.
