Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address — Threadlinqs Intelligence
As of 2026-08-10, Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address is a medium-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1975 · Severity: MEDIUM · Status: TRACKING · Category: SUPPLY_CHAIN
A routine Ministry of Defence cyber vulnerability assessment found that third-party cameras fitted to Royal Navy Kraken K3 Scout unmanned surface vessels (USVs) — used by 47 Commando and the Special
On 2026-08-09 The Telegraph reported, and The Register and multiple outlets corroborated on 2026-08-10, that a routine cyber vulnerability sweep of Royal Navy unmanned surface vessels identified third-party electro-optical (EO) camera components transmitting automated 'heartbeat' signals — basic online/functioning-normally status pings, not operational imagery or sensor data — to an IP address located in China. The affected platform is the Kraken Technology Group K3 Scout USV: an 8.4m composite-hulled autonomous vessel with a 1.93m beam, 0.8m draft, 2,500kg maximum displacement, 600kg payload capacity, inboard diesel powertrain with stern drive, 55-knot top speed, 650nm range at 25 knots, up to 30-day mission endurance, Auterion-based autonomy stack, and operating modes spanning supervised autonomous navigation to remote piloting. A 20-vessel, roughly £12.3 million K3 Scout fleet was acquired under the Royal Navy's Project Beehive programme as an open-architecture testbed combining autonomous units with conventional warships, and has been in service with the Coastal Forces Squadron and 47 Commando Royal Marines, including the Special Boat Service at Poole, since around March 2026, used for ISR, surveillance, training, and NATO trials. Reporting also notes the platform was included in a proposed UK defense package for Strait of Hormuz freedom-of-navigation operations, adding operational stakes to the unresolved provenance question.
The cameras were sourced by Kraken from a third-party supplier that had provided assurances of US National Defense Authorization Act (NDAA) compliance; Kraken subsequently confirmed the cameras 'had been presented as compliant with US National Defense Authorization Act requirements,' but that 'a small number of components originat[ed] from outside the UK' — i.e. China-origin components embedded in hardware marketed as NDAA-compliant and British-supplied, despite the supplier's assurances. Reporting also noted that some cameras remained network-active and continued to beacon even while the host vessel itself was powered off, indicating the telemetry capability operates independently of the vessel's own power/operating state — consistent with a firmware-level implant in the camera's component firmware rather than a vessel-software-layer issue (Neowin's coverage headlined the finding as 'firmware sending data back to China'; the MoD itself distinguished the issue as 'communications generated by the camera subsystem rather than the vessels themselves').
Following discovery, the MoD removed all internet connectivity from the affected camera subsystem and launched a formal audit. Both the MoD ('a thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally') and Kraken ('after a full audit... we are confident no sensitive information has ever been shared outside intended channels') state no sensitive data or systems were compromised; no platform withdrawal was initiated and the K3 Scout fleet remains in service. The incident has drawn both political and diplomatic reaction: Shadow Security Minister Alicia Kearns said 'if we cannot say with confidence what is inside our own military equipment, we cannot say it is ours,' and Conservative MPs called for an urgent audit of UK defense equipment for 'hidden Chinese footprints'; the Chinese Embassy in the UK publicly disputed the reporting, stating that unnamed parties in the UK 'had always tried to distort the facts and create a so-called spying case to tarnish China's reputation.' No CVE has been assigned; this is a hardware/firmware supply-chain provenance issue rather than a disclosed, exploitable software vulnerability, and the exact China-based destination IP address, its ASN/hosting provider, and the underlying camera chipset/OEM have not been publicly disclosed by any outlet as of this writing.
Target sectors: defense, government administration, maritime, military
Target regions: united kingdom
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, MEDIUM, threat intelligence, cybersecurity, T1195.003, T1199, T1542.005, T1036, T1082, T1119, T1071, T1583.004, T1587.001