Royal Navy Drone Boats’ Cameras Found Transmitting to China in Cybersecurity Scare
During a routine cyber vulnerability assessment, the UK Ministry of Defence (MoD) discovered that cameras aboard Royal Navy Kraken unmanned surface vessels (USVs) were transmitting data to an IP address in China. The MoD confirmed the issue involved a sub-system of the drone boats but clarified that no sensitive data or systems were compromised.
The transmissions were described as a "heartbeat" signal basic telemetry indicating the cameras were operational rather than malicious exfiltration. However, the unexpected connection to China raised concerns, particularly given rising tensions over state-linked cyber activity. The MoD stated that its security protocols detected the anomaly early and that no evidence of unauthorized access or data loss was found.
The cameras in question were sourced by Kraken, the USV supplier, from a third-party vendor, highlighting vulnerabilities in defense supply chains. While the MoD emphasized its commitment to rigorous security testing, the incident underscores the risks of relying on supplier assurances without independent verification.
China has been frequently linked to cyber espionage, including recent allegations of targeting UK political figures. Though this case appears to involve a benign technical oversight, it serves as a reminder of the need for stringent oversight in military procurement and cybersecurity.
UK Ministry of Defence cybersecurity rating report: https://www.rankiteo.com/company/uk-ministry-of-defence
Kraken Technology Group cybersecurity rating report: https://www.rankiteo.com/company/kraken-technology-group
"id": "UK-KRA1786368391",
"linkid": "uk-ministry-of-defence, kraken-technology-group",
"type": "Vulnerability",
"date": "4/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Defense',
'location': 'United Kingdom',
'name': 'UK Ministry of Defence (MoD)',
'size': 'Large',
'type': 'Government/Military'}],
'attack_vector': 'Supply Chain Compromise',
'data_breach': {'data_exfiltration': 'No (transmission was benign)',
'personally_identifiable_information': 'No',
'sensitivity_of_data': 'Low',
'type_of_data_compromised': 'Basic telemetry (non-sensitive)'},
'description': 'During a routine cyber vulnerability assessment, the UK '
'Ministry of Defence (MoD) discovered that cameras aboard '
'Royal Navy *Kraken* unmanned surface vessels (USVs) were '
'transmitting data to an IP address in China. The '
"transmissions were described as a 'heartbeat' signal (basic "
'telemetry) rather than malicious exfiltration. The MoD '
'confirmed no sensitive data or systems were compromised, but '
'the incident raised concerns due to rising tensions over '
'state-linked cyber activity.',
'impact': {'brand_reputation_impact': 'Moderate (supply chain scrutiny)',
'data_compromised': 'Basic telemetry (non-sensitive)',
'operational_impact': 'None confirmed (early detection)',
'systems_affected': 'Cameras aboard Royal Navy *Kraken* USVs'},
'investigation_status': 'Ongoing (no evidence of malicious activity)',
'lessons_learned': 'Need for stringent oversight in military procurement and '
'independent verification of third-party vendor security '
'assurances.',
'motivation': 'Unknown (potential espionage concerns)',
'post_incident_analysis': {'corrective_actions': 'Review and strengthen '
'supply chain security '
'protocols.',
'root_causes': 'Third-party vendor sub-system '
'transmitting data to an '
'unauthorized IP address (China).'},
'recommendations': 'Enhance supply chain security, conduct independent '
'security assessments of third-party components, and '
'improve monitoring of data transmissions.',
'references': [{'source': 'UK Ministry of Defence (MoD)'}],
'response': {'communication_strategy': 'Public disclosure (MoD statement)',
'containment_measures': 'Anomaly detected via security protocols',
'incident_response_plan_activated': 'Yes (early detection)'},
'stakeholder_advisories': 'Defense contractors and suppliers advised to '
'review sub-system security.',
'title': 'Royal Navy Drone Boats’ Cameras Found Transmitting to China in '
'Cybersecurity Scare',
'type': 'Data Transmission Anomaly',
'vulnerability_exploited': 'Third-party vendor sub-system'}