What the Ministry of Defence found
The Telegraph's defence correspondent Richard Holmes reported on 9 August 2026 that surveillance cameras fitted to Royal Navy K3 Scout drone boats, used by the Royal Marines and closely linked to Special Boat Service operations out of Poole, contained Chinese-made components that were sending "heartbeat communications" to a device in China. A Ministry of Defence spokesperson confirmed the substance of the story, stating the transmissions were identified during a "routine cyber vulnerability assessment" of the K3 fleet and that the information exchanged amounted to confirmation the camera was online and functioning, not any operational data. Following the discovery, the MoD stripped all internet connectivity from the affected cameras.
The MoD's official position, repeated to multiple outlets, is that a subsequent investigation found no evidence any MoD data or systems were accessed, compromised or transmitted externally. That is a narrower claim than saying the components were safe: it confirms no known exfiltration, not that the phone-home behaviour was intended, disclosed, or ever meant to be there.
The GBP 12 million fleet behind Project Beehive
The K3 Scout is an 8.4-metre uncrewed surface vessel built by Kraken Technology Group, a British defence contractor based in Fareham, Hampshire. The Royal Navy contracted Kraken to supply 20 K3 Scouts and their ground control systems under Project Beehive, a programme to integrate high-speed uncrewed vessels into fleet operations; the boats can carry sensor, cargo or weapons payloads and have separately been used in trials such as an airdrop from an RAF A400M. The GBP 12 million fleet has been in service with the Royal Marines since March 2026, with some vessels reportedly earmarked for a Gulf deployment protecting shipping in the Strait of Hormuz.
Kraken Technology Group told reporters the cameras were NDAA-compliant - meeting the US defence procurement standard that bars certain Chinese suppliers - but acknowledged the units contained "a small number of components from outside the UK", which it said it sourced from a third-party supplier that had provided security assurances. Kraken maintained no sensitive information had been shared.
Where the assurance chain actually broke
The chain of custody here has three links: Kraken built and sold the K3 Scout to the Royal Navy; Kraken bought the camera module from a third-party supplier; that supplier gave Kraken assurances about the component's security. None of those assurances caught the heartbeat traffic before the boats were deployed. It surfaced only once, roughly five months into operational use, when the MoD ran a routine cyber vulnerability assessment - the kind of check that happens periodically, not the kind built into onboarding a new supplier's part.
Shadow security minister Alicia Kearns said the episode showed how supply-chain vulnerabilities can undermine sovereign defence capability even when a prime contractor is British and a compliance standard (NDAA) has formally been met. That is the part of the story compliance paperwork does not capture: a component can pass a named standard and a supplier's written assurance and still behave, in production, in a way nobody upstream tested for or disclosed.
What this means for EU and UK businesses beyond defence
This is not only a Ministry of Defence problem. Chinese-made camera and sensor modules sit inside a huge range of commercial hardware bought by ordinary EU and UK businesses: security cameras, access-control systems, smart building sensors, industrial monitoring equipment, even consumer-facing kiosks. The K3 Scout case shows that a documentary assurance from a supplier - "NDAA-compliant", "no sensitive data shared", a signed security questionnaire - is not the same claim as "we tested what this device actually does on a network," and the two can diverge without anyone in the chain noticing until an unrelated audit catches it.
Under NIS2, essential and important entities across the EU (utilities, healthcare, digital infrastructure, manufacturing of critical products, and more) carry an explicit supply-chain risk-management obligation: Article 21(2)(d) requires assessing the security practices of direct suppliers and service providers, not just their paperwork. The Royal Navy episode is a concrete illustration of why that obligation should translate into a technical step, not only a contractual one. A procurement team that wants to avoid discovering its own "heartbeat" problem five months after go-live should require, before deployment, an independent network-traffic capture of any third-party camera, sensor or IoT module - checking what it actually calls out to, not just what its supplier says it does not do. The UK sits outside NIS2's jurisdiction but faces the same practical exposure, and its own NCSC has pushed similar supply-chain assurance guidance for exactly this reason.
Read next: Rotate Every CI Credential You Used on 4 August | The Fix Signs New Files, Not Your Archive



