Chinese Components Found in Royal Navy Special Forces Vessels

4 Min Read
A Ministry of Defence review found camera components on Royal Navy K3 Scout unmanned surface vessels sending routine network signals to an IP address in China. Source: Kraken

A Ministry of Defence cybersecurity review has found that cameras fitted to Royal Navy K3 Scout unmanned surface vessels were transmitting routine “heartbeat” signals to an IP address in China, according to an investigation by The Telegraph, later corroborated by The Times. The security review reportedly took place at the Special Boat Service’s headquarters in Poole, Dorset. The vessels had also been earmarked for a British mission to help secure freedom of navigation in the Strait of Hormuz, raising the stakes of a supply-chain security incident involving platforms associated with one of the UK’s elite maritime units rather than routine patrol craft.

The £12.3 million fleet comprises 20 vessels built by Kraken Technology Group under the Royal Navy’s Project Beehive programme. According to the Royal Navy’s procurement announcement, the vessels are intended for operations, training and development with the Coastal Forces Squadron and 47 Commando Royal Marines as part of the service’s transition to a hybrid fleet of crewed and uncrewed platforms. The Telegraph reported that the vessels operated in proximity to sensitive meetings involving senior Special Boat Service personnel. It also said investigators were examining whether the cameras could remain operational even when switched off, although the Ministry of Defence has not publicly confirmed that assessment.

Kraken said the cameras met U.S. National Defense Authorization Act (NDAA) procurement requirements but acknowledged that the certified camera assemblies contained a small number of third-party components sourced from outside the United Kingdom. The company said that, following a joint audit with the Royal Navy, it was confident no sensitive information had been transmitted and that any identified vulnerabilities had been addressed.

Routine heartbeat signals are not necessarily harmless. Cybersecurity specialists note that such communications can reveal a device’s live IP address, network architecture, firmware version, uptime patterns and other technical metadata. While this information does not amount to classified operational data, it can provide valuable intelligence about the configuration and activity of military systems if collected over time.

The episode highlights a broader challenge confronting Western defence industries. Prime contractors increasingly depend on complex international supply chains spanning multiple subcontractors, making it difficult to verify the origin of every electronic component incorporated into military equipment. The K3 Scout programme itself has become a flagship element of the Royal Navy’s push toward autonomous maritime systems, with the service announcing more than £12 million in procurement under Project Beehive and wider government plans to invest billions in drones and autonomous technologies.

The Ministry of Defence maintains that its investigation found no evidence that classified or sensitive information was accessed or transmitted outside government networks. That assurance addresses confirmed data loss. The broader concern exposed by the incident is that equipment cleared through national security procurement standards still contained components capable of communicating with an IP address in China, underscoring the growing importance of supply-chain security alongside traditional cyber defence.

Share This Article