Britain’s Royal Navy bought a new fleet of small sea drones to help the navy and the Royal Marines. Now we are told some of those drones’ cameras were quietly sending a “heartbeat” signal to an address in China. That is the latest shock from a routine cyber check — and it should make every patriot uneasy.
What the report actually found
Investigative reporting says the Kraken K3 Scout unmanned surface vessels had camera systems that sent routine telemetry — a simple “I’m alive” ping — to an IP address tied to China. The fleet was bought as a quick, modern upgrade for coastal forces and special units. The Ministry of Defence says its probe found no evidence that classified images or MoD systems were breached. Kraken, the supplier, admits some third‑party camera units included a small number of parts from outside the UK and says an audit closed any risks.
Official fixes, official shrug
In practice, the Navy cut internet links to the affected cameras while the audit ran. That is the right immediate fix, but it is also the sort of emergency taping-over-the-wires move you do after a preventable mistake. The company and the MoD say sensitive data was not leaked. Still, unnamed defence sources called the procurement checks a “major failure to check origins of components” and said confidence in the platform was shaken. If you needed proof the system worked, that statement supplied it: confidence is not the same as security.
Supply‑chain sovereignty and the political fallout
This episode is not just a tech glitch. It points to a bigger problem: defence procurement that lets foreign components slip into sensitive gear. Critics rightly say this echoes past fights over foreign vendors in telecoms and critical infrastructure. Opposition MPs have demanded answers. Allies, including the United States, reportedly use or trial similar craft, so this is not only a British embarrassment — it’s a shared wake‑up call. If “Made in Britain” can contain surprise parts from an antagonistic state, then procurement rules and audits need to be rewritten in plain language and enforced with teeth.
We should thank whoever ran the routine cyber check for catching the ping. But catching the ping is only the start. Parliament, defence chiefs and industry must answer who approved the kit, how many vessels were affected, and what exact data ever left British systems. Until they do, trust but verify should become the rule — and perhaps “verify before you buy” should be the new motto. Our forces deserve gear we can trust. The public deserves the truth. Anything less is simply unacceptable.

