Royal Navy Spy Drones Transmitted to China for Months Before Discovery
A £12 million Royal Navy fleet marketed as NATO-standard and built by a UK contractor concealed Chinese camera components that transmitted to Beijing — even when switched off.
The Royal Navy’s new fleet of spy drones—purchased for elite special forces operations in the Strait of Hormuz—spent months transmitting data to an IP address in China before UK defense officials discovered the breach. The £12.3 million contract for 20 K3 Scout uncrewed surface vessels, awarded in March 2026 to British firm Kraken Technology Group, was supposed to deliver cutting-edge maritime capability for operations against Iran. Instead, it delivered a case study in how Beijing penetrates Western military supply chains—even in equipment explicitly designed to exclude Chinese components.
The Discovery
The cameras on the K3 Scout surveillance drones contained Chinese-made parts that were secretly transmitting “heartbeat communications”—status signals confirming the devices were online and functioning—to a Chinese IP address. The Ministry of Defence discovered the issue during a routine cyber vulnerability assessment and immediately removed all internet connectivity from the cameras.
The compromise extended beyond the drones’ operational deployments. The cameras remained active even when the drones were switched off, and the vessels had been positioned near “highly sensitive” meetings between senior Special Boat Service staff at the unit’s Poole headquarters. A defense source told The Telegraph the drones were part of Britain’s planned defense package to secure freedom of navigation in the Strait of Hormuz, and that preparations for Gulf operations “had been conducted on the drones.”
“This is major failure to check origins of components,” the source said, “and we have lost confidence in the platform.”
The Supply Chain Illusion
Kraken Technology Group—a UK startup founded in 2020 by former speedboat racer Mal Crease—markets itself as a British defence innovator. The company’s K3 Scout, which sells for roughly £250,000 per unit, has become popular with NATO customers: Kraken sold over 100 units in 2025 alone and secured a $49 million contract with US Special Operations Command in November 2025.
The cameras at the center of the breach were supplied by a third party that provided what Kraken described as “NDAA-compliant” equipment—a designation meaning the hardware supposedly complies with U.S. National Defense Authorization Act standards by excluding components from restricted Chinese manufacturers. Kraken said it received “assurances about their security.”
Those assurances did not capture the full picture. A Kraken spokesman acknowledged that “some third-party, NDAA-compliant cameras had a small number of components originating from outside the UK,” though the company insisted that “after a full audit by both Kraken and the Royal Navy we are confident no sensitive information has ever been shared outside of intended channels.”
The MoD maintained that “a thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally.” But the ministry’s own response—severing internet access to the cameras entirely—suggests officials recognized the risk was more than theoretical, despite its insistence no data was compromised.
The Wider Picture
The K3 Scout compromise is not an isolated incident but the latest in a series of Chinese supply chain intrusions into UK defence infrastructure. Last month, The Telegraph reported that the SBS banned Chinese-made electric vehicles from its headquarters over espionage concerns. In 2020, the Conservative government was forced to reverse course and ban Huawei from the UK’s 5G network after U.S. security officials warned that access came with a spy risk under China’s national security laws.
Shadow Security Minister Alicia Kearns called the K3 incident a sovereignty failure. “If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign,” she said. “When cameras built on Chinese parts are found recording our special forces—their faces, training and operations—we should not be surprised, we should be furious that we still haven’t woken up to the realities of the threat we face.”
The breach comes as the Labour government pursues a diplomatic reset with Beijing. Earlier this year, the UK approved plans for a Chinese super-embassy in London despite concerns about the site’s proximity to sensitive communication infrastructure. Prime Minister Keir Starmer and then-Business Secretary Peter Kyle visited Shanghai in January to explore trade agreements. Weeks later, British national Jimmy Lai was sentenced to 20 years in a Hong Kong prison under the city’s national security laws.
The American Connection
The K3 Scout’s compromise carries implications beyond Britain. US Special Operations Command awarded Kraken a $49 million contract in November 2025 to develop and prototype “novel uncrewed surface and subsurface vessel technologies” for American special operations forces. The agreement gives Kraken access to USSOCOM requirements and integration pathways across the U.S. military. There is no public reporting on whether American forces have audited their Kraken equipment for similar vulnerabilities.
Kraken’s investor base includes the NATO Innovation Fund and the UK National Security Strategic Investment Fund. The company recently added former U.S. Secretary of State Mike Pompeo to its advisory board and has partnerships with German shipbuilder Rheinmetall, L3Harris, and Applied Intuition.
What Heartbeat Communications Reveal
The specific content of the transmissions to China remains unclear. The MoD and Kraken both describe the data as “heartbeat communications”—simple status pings confirming a device is online. But even basic telemetry can reveal operational patterns: device locations through network metadata, operational tempo through timing, and mission profiles through activation sequences.
The fact that cameras remained active when drones were powered down suggests the components operated independently of the vessel’s primary systems—a design feature that would facilitate covert data collection. Whether the heartbeat signals included timestamps, geolocation data, or device identifiers has not been disclosed.
The third-party camera supplier has not been publicly identified, nor has the specific Chinese IP address that received the transmissions. Without answers to those questions, it remains impossible to assess whether the breach was an inadvertent supply chain compromise or something more deliberate—a distinction that matters significantly when evaluating China’s strategy for accessing Western defence capabilities.
The Standard That Wasn’t
The K3 Scout case exposes the limits of compliance regimes designed to keep Chinese components out of Western military systems. NDAA compliance is supposed to guarantee that equipment excludes parts from manufacturers designated as security risks. But when third-party suppliers assemble “compliant” systems using subcomponents sourced from opaque global supply chains, the compliance label becomes meaningless.
China dominates global electronics manufacturing—not just final assembly but the production of individual components that flow into systems assembled elsewhere and marketed as Western-made. A British defence contractor can genuinely believe it is sourcing secure equipment, only to discover that cameras assembled in one country contain sensors, chips, or firmware elements produced in China and designed to transmit home.
The Royal Navy’s loss of confidence in the K3 platform reflects that reality. Even if no classified data was transmitted, the episode demonstrates that Western militaries cannot reliably know what is inside their own equipment—or where that equipment is sending information.










