Elite Royal Navy special forces have discovered that their K3 Scout surveillance drones were sending data to a Chinese IP address. In response to this security breach, the Ministry of Defence has disconnected the cameras from the internet.

Advertisement

The "heartbeat" signals sent from Poole, Dorset

The discovery of unauthorized data transmissions has placed the Special Boat Service headquarters in Poole , Dorset, under heightened security scrutiny. The K3 Scout drones, operated by the Royal Marines, were found sending "heartbeat" communications—signals intended to confirm a device is online—to an IP address located in China.

This breach mirrors previous national security warnings regarding Chinese technological influence and interference.. As the Telegraph reported, there are fears that these signals may have been active during sensitive meetings involving senior special forces personnel, potentially exposing high-level military discussions to foreign intelligence services.

The potential exposure of personnel at the SBS headquarters is considered a serious matter by defense officials. Because the drones were operating in highly sensitive environments, the risk of intelligence gathering by a foreign power remains a primary concern for the Ministry of Defence.

Kraken Technology Group's £12 million procurement gap

The £12 million fleet of K3 Scout drones was supplied by the British defense contractor Kraken Technology Group. Although Kraken had sourced the cameras from a third-party supplier that provided security assurances, an investigation revealed the presence of Chinese-manufactured components within the hardware.

This incident highlights a recurring vulnerability in the UK's military supply chain, reminiscent of the 2020 decision to remove Huawei equipment from the national 5G network. It demonstrates how even "British" systems can harbor hidden vulnerabilities through deep-tier sub-contractors that bypass standard vetting processes.

The failure to identify these components before deployment has led some defense sources to describe the situation as a serious procurement failure. This has resulted in a significant loss of confidence in the platform's ability to operate in secure environments.

A setback for Project Beehive and the Strait of Hormuz mission

Project Beehive, the Royal Navy's strategic program to integrate unmanned vessels with conventional warships, has faced a major setback due to this security failure. The K3 Scout drones are a critical component of this initiative, designed to provide enhanced surveillance while reducing risks to human personnel.

The drones were recently utilized during preparations for a British defense package aimed at protecting navigation through the Strait of Hormuz. These K3 Scout units are highly capable, featuring a 600kg payload capacity and the ability to operate continuously for up to 30 days.

Beyond the Royal Navy, the K3 Scout system has also been acquired by US Special Operations Command and has participated in NATO exercises in the Baltic . This international involvement adds a layer of complexity to the security implications of the Chinese-made components.

The risk of cameras remaining active while drones are powered down

One of the most pressing unanswered questions involves whether the cameras can remain operational even after the drones themselves have been switched off. This specific technical vulnerability has caused significant concern among defense officials regarding the continuous monitoring of sensitive areas.

While the Ministry of Defence has stripped the cameras of their internet connectivity,officials insist there is currently no evidence that sensitive military information or MoD systems were actually accessed. According to the Ministry of Defence, the immediate priority was to sever the link to the Chinese IP address.

However, the question of whether the third-party supplier's security assurances were intentionally misleading remains unaddressed. furthermore, it is still unknown if other components within the wider Royal Navy fleet might share similar vulnerabilities.