The UK Ministry of Defence is strengthening its scrutiny of the supply chain after discovering that some naval drones had transmitted signals to China.
According to Bloomberg, the UK Ministry of Defence revealed earlier this week that a routine cybersecurity vulnerability assessment uncovered issues with K3 Scout drones, manufactured by Kraken Technology Group and used by the Royal Navy.
Sources familiar with the matter disclosed that officials are investigating other vulnerabilities within the defense industry, including whether other contractors are using cameras made by the same supplier as those used by Kraken.
The UK Ministry of Defence said in a statement: “Our assurance and testing processes are designed to detect and address potential vulnerabilities at an early stage, and we continue to work to ensure the security of all our systems and equipment… This includes continued projects to assess the risks posed by the supply chain being potentially exposed to adversaries, and to formulate appropriate mitigation measures.”
According to The Telegraph earlier this week, Kraken surveillance drones contained Chinese-made components, which had been secretly transmitting information to a device within China. The UK and France are preparing a minesweeping mission to be launched after a potential peace deal between the US and Iran; if the mission proceeds, some drones may be deployed to the Strait of Hormuz.
The UK Ministry of Defence said that the investigation had not found any evidence of government data or systems being accessed, compromised, or transmitted externally. According to The Telegraph, and as confirmed by UK defence officials, the cameras on these drones sent so-called “heartbeat signals” to a Chinese IP address. These signals could be used to determine the location of the drone and whether it was in use at the time.
A Kraken spokesperson said that some third-party cameras, which are compliant with the US National Defense Authorization Act, contain a small number of components from outside the UK. The spokesperson stated that no sensitive information was shared and that all potential vulnerabilities had been identified and fixed.
Bloomberg reports that this discovery exposes the vulnerability of the defense supply chain, especially the risk of unknowingly using components from certain countries that may exploit such loopholes to gather intelligence on UK military activities.