Threat reportSupply ChainTL-2026-1975

Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address

mediumTRACKING

Royal Navy K3 Scout Drone Cameras Found Transmitting (TL-2026-1975) is a medium-severity supply-chain compromise, first published 2026-08-10. It has no confirmed attribution, affects Kraken Technology Group K3 Scout Unmanned Surface Vessel — third-party, maps to 9 MITRE ATT&CK techniques (T1036, T1071, T1082), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-1975

Threat ID
TL-2026-1975
Severity
MEDIUM
Status
TRACKING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
defense, government administration, maritime, military
Target regions
united kingdom
Detection rules
9
Indicators of compromise
15

How Royal Navy K3 Scout Drone Cameras Found Transmitting works

A routine Ministry of Defence cyber vulnerability assessment found that third-party cameras fitted to Royal Navy Kraken K3 Scout unmanned surface vessels (USVs) — used by 47 Commando and the Special Boat Service since March 2026 under Project Beehive — were sending periodic 'heartbeat' status pings to an IP address located in China. The MoD and manufacturer Kraken Technology Group say an investigation found no evidence that sensitive data or systems were accessed, compromised, or transmitted externally, and internet connectivity to the affected cameras has since been removed.

On 2026-08-09 The Telegraph reported, and The Register and multiple outlets corroborated on 2026-08-10, that a routine cyber vulnerability sweep of Royal Navy unmanned surface vessels identified third-party electro-optical (EO) camera components transmitting automated 'heartbeat' signals — basic online/functioning-normally status pings, not operational imagery or sensor data — to an IP address located in China. The affected platform is the Kraken Technology Group K3 Scout USV: an 8.4m composite-hulled autonomous vessel with a 1.93m beam, 0.8m draft, 2,500kg maximum displacement, 600kg payload capacity, inboard diesel powertrain with stern drive, 55-knot top speed, 650nm range at 25 knots, up to 30-day mission endurance, Auterion-based autonomy stack, and operating modes spanning supervised autonomous navigation to remote piloting. A 20-vessel, roughly £12.3 million K3 Scout fleet was acquired under the Royal Navy's Project Beehive programme as an open-architecture testbed combining autonomous units with conventional warships, and has been in service with the Coastal Forces Squadron and 47 Commando Royal Marines, including the Special Boat Service at Poole, since around March 2026, used for ISR, surveillance, training, and NATO trials. Reporting also notes the platform was included in a proposed UK defense package for Strait of Hormuz freedom-of-navigation operations, adding operational stakes to the unresolved provenance question.

The cameras were sourced by Kraken from a third-party supplier that had provided assurances of US National Defense Authorization Act (NDAA) compliance; Kraken subsequently confirmed the cameras 'had been presented as compliant with US National Defense Authorization Act requirements,' but that 'a small number of components originat[ed] from outside the UK' — i.e. China-origin components embedded in hardware marketed as NDAA-compliant and British-supplied, despite the supplier's assurances. Reporting also noted that some cameras remained network-active and continued to beacon even while the host vessel itself was powered off, indicating the telemetry capability operates independently of the vessel's own power/operating state — consistent with a firmware-level implant in the camera's component firmware rather than a vessel-software-layer issue (Neowin's coverage headlined the finding as 'firmware sending data back to China'; the MoD itself distinguished the issue as 'communications generated by the camera subsystem rather than the vessels themselves').

Following discovery, the MoD removed all internet connectivity from the affected camera subsystem and launched a formal audit. Both the MoD ('a thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally') and Kraken ('after a full audit... we are confident no sensitive information has ever been shared outside intended channels') state no sensitive data or systems were compromised; no platform withdrawal was initiated and the K3 Scout fleet remains in service. The incident has drawn both political and diplomatic reaction: Shadow Security Minister Alicia Kearns said 'if we cannot say with confidence what is inside our own military equipment, we cannot say it is ours,' and Conservative MPs called for an urgent audit of UK defense equipment for 'hidden Chinese footprints'; the Chinese Embassy in the UK publicly disputed the reporting, stating that unnamed parties in the UK 'had always tried to distort the facts and create a so-called spying case to tarnish China's reputation.' No CVE has been assigned; this is a hardware/firmware supply-chain provenance issue rather than a disclosed, exploitable software vulnerability, and the exact China-based destination IP address, its ASN/hosting provider, and the underlying camera chipset/OEM have not been publicly disclosed by any outlet as of this writing.

MITRE ATT&CK techniques used in TL-2026-1975

Defense Evasion

T1036 Masquerading

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery

Collection

T1119 Automated Collection

Initial Access

T1195.003 Compromise Hardware Supply Chain; T1199 Trusted Relationship

Persistence

T1542.005 TFTP Boot

Resource Development

T1583.004 Server; T1587.001 Malware

Affected products and versions in Royal Navy K3 Scout Drone Cameras Found Transmitting

  • Kraken Technology Group — K3 Scout Unmanned Surface Vessel — third-party electro-optical (EO) camera subsystem
    Vulnerable versions: K3 Scout fleet (20 vessels, ~£12.3M) fielded with Royal Navy Coastal Forces Squadron / 47 Commando Royal Marines / Special Boat Service since approximately March 2026 (Project Beehive), reportedly also proposed for Strait of Hormuz freedom-of-navigation operations
    Fixed in: Internet connectivity removed from affected camera components as of 2026-08-10; formal MoD/Kraken audit ongoing, no component replacement confirmed yet

Remediation for Royal Navy K3 Scout Drone Cameras Found Transmitting

Patches

  • No vendor firmware patch has been published; remediation to date is physical/logical disconnection of the affected cameras' network connectivity pending component replacement or re-sourcing

Immediate actions

  • Remove/disable internet and outbound network connectivity for third-party camera and EO sensor subsystems on unmanned surface vessel platforms
  • Conduct full hardware and firmware provenance audit of all third-party-sourced components on fielded K3 Scout vessels
  • Network-segment embedded IoT/sensor subsystems (cameras, EO/radar/sonar modules) from vessel command, navigation, and autonomy (Auterion) networks

Workarounds

  • Disable or physically remove network/internet connectivity from the affected camera components
  • Restrict camera subsystem to closed-loop, non-internet-routable vessel network segments

Longer-term hardening

  • Require independent hardware/firmware supply-chain verification (not vendor self-attestation) for all NDAA-compliance claims on defense procurement contracts
  • Establish a defense-wide inventory and audit programme for China-origin components embedded in third-party-sourced subsystems across fielded military equipment
  • Mandate egress-traffic monitoring/allow-listing for all network-capable peripherals on autonomous and uncrewed defense platforms
  • Build component-level provenance tracking (bill-of-materials attestation) into procurement contracts rather than relying on supplier self-certification

Weaknesses (CWE) in Royal Navy K3 Scout Drone Cameras Found Transmitting

CWE-1357

Timeline of Royal Navy K3 Scout Drone Cameras Found Transmitting

  • Kraken K3 Scout USV fleet (20 vessels, ~£12.3M) enters service with the Royal Navy Coastal Forces Squadron and 47 Commando Royal Marines (including Special Boat Service use) under Project Beehive, approximate deployment month per reporting.
  • A routine MoD cyber vulnerability assessment of Royal Navy unmanned surface vessels identifies third-party K3 Scout camera components sending heartbeat status signals to an IP address in China.
  • The Ministry of Defence removes internet connectivity from the affected camera equipment following discovery.
  • The Telegraph is first to publicly report the finding, identifying the affected components as third-party cameras on the K3 Scout vessels and noting some cameras remained active while host vessels were powered off.
  • Threadlinqs opens tracking (TL-2026-1975) for the incident as a defense-sector hardware supply-chain exposure pending further disclosure of technical details (destination IP/ASN, camera OEM/chipset).
  • Reporting notes the K3 Scout platform had also been proposed for inclusion in a UK defense package supporting Strait of Hormuz freedom-of-navigation operations, raising the operational stakes of the unresolved component-provenance question.
  • The Chinese Embassy in the United Kingdom publicly disputes the reporting, stating that unnamed parties in the UK 'had always tried to distort the facts and create a so-called spying case to tarnish China's reputation.'
  • Shadow Security Minister Alicia Kearns publicly criticizes the finding, stating 'if we cannot say with confidence what is inside our own military equipment, we cannot say it is ours,' and Conservative MPs call for an urgent defense equipment supply-chain audit.
  • The Ministry of Defence states a thorough investigation found no evidence of MoD data or systems being accessed, compromised, or transmitted externally, and characterizes the issue as originating in the camera subsystem rather than the vessels themselves.
  • Kraken Technology Group confirms that some third-party cameras, presented by the supplier as NDAA-compliant, contained a small number of components originating from outside the UK, and states a full audit found no sensitive information shared outside intended channels.
  • The Register, ArmyRecognition, IBTimes UK, AOL, Yahoo News, Neowin, Tom's Hardware, ssbcrack, Voi.id, and ChinaTechNews.com publish corroborating coverage citing The Telegraph's reporting.

Sources cited for Royal Navy K3 Scout Drone Cameras Found Transmitting

Detection coverage for TL-2026-1975

As of 2026-08-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1975 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats