Cameras mounted on Royal Navy surveillance drones were quietly checking in with a server in China, and nobody involved in buying, building or fitting them knew it until a routine security scan caught the traffic.
The vessels are Kraken K3 Scout uncrewed surface craft — roughly 28-foot unmanned speedboats built by British defense firm Kraken Technology Group and used by Royal Navy special forces, including the Special Boat Service, for surveillance along contested coastlines. The Navy bought 20 of them for a project called Operation Beehive, and they have been in special forces hands since March. They are expected to be deployed to the Strait of Hormuz as part of Britain’s effort to help protect the waterway.
Here is what the cameras were actually doing. They were sending what security staff call “heartbeat communications” — a short, repeating signal whose only job is to confirm to a remote server that the device is switched on and working. That is standard behavior for connected equipment. The problem is not the content of the message. It is that the message had a destination, and the destination was an IP address inside China that nobody had authorized, documented or expected.
Where the part came from
This is the detail that should worry every procurement officer. The electro-optical and infrared cameras were manufactured by Canadian company Current Scientific Corporation under its Night Navigator 3000 line, but contained components sourced from outside the U.K. that were found sending the heartbeat traffic. Kraken had sourced the cameras from a third party that gave assurances about their security.
So the chain ran: British prime contractor, Canadian camera maker, third-party supplier, Chinese-made part. Two allied-country labels on the box, and the exposure was still there. Nobody in that chain was hiding anything. They simply did not know what was four tiers down.
The Ministry of Defence stripped all internet connectivity from the cameras after the discovery, and a spokesperson said an investigation found “no evidence” of MoD data or systems being accessed or transmitted externally, adding that the issue surfaced in a routine cyber vulnerability assessment. The opposition Conservatives called on the government to urgently audit its equipment for other unknown Chinese components.
The rule already changed in the U.S.
American businesses do not have to wait for their own version of this story, because the regulatory shift it implies has already happened in the energy sector.
In 2025, U.S. experts reported finding rogue communication devices, undocumented in any product paperwork, inside some Chinese-made solar inverters. In January, the Department of Energy inspected roughly 30 units and found no evidence of malicious or intentional differences in communications — while warning that inverter supply chains are complex enough to create openings for breaches and malicious components anyway.
Then regulators moved regardless. The FCC added foreign-produced power inverters to its Covered List, immediately banning equipment authorizations for unapproved foreign models — an action that effectively overrode the January DOE finding. The reasoning was that physical bugs are beside the point: wireless connectivity in modern smart inverters means firmware can be pushed remotely, so foreign-assembled units are treated as an unacceptable grid risk on their own.
That is the standard American buyers now have to plan around. The question is no longer “did investigators find something malicious in this device.” It is “does a path exist, and who is at the other end of it.” A clean forensic report does not clear the equipment.
The structural reason is legal, not technical: Chinese companies are required to cooperate with their government’s intelligence agencies, which is why security specialists treat Chinese-made connected equipment on foreign networks as a control question rather than a product-quality one.
What it costs on the ground
The practical burden lands on anyone buying connected hardware — cameras, sensors, controllers, inverters, batteries, cargo handling equipment, vehicles. It means demanding component-level bills of materials rather than country-of-assembly certificates, testing what devices talk to before they go live, and budgeting for requalifying suppliers when the answer is wrong.
The Ministry of Defence has been living with the awkward version of this for a while. It leased hundreds of electric vehicles, including MG models built by China’s state-owned Shanghai Automotive Industry Corporation, and put stickers on the dashboards instructing personnel not to connect MoD devices to the vehicle and to avoid sensitive conversations inside — with parking restrictions around some defense sites for vehicles containing Chinese components.
A warning sticker is what you are left with when the component is already inside the fence. The cheaper move, and the one boards are now being pushed toward, is finding out what is in the box before it ships.
JBizNews Desk | London
© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.



