A £12m fleet of uncrewed patrol boats operated by the Royal Marines and bound for the Strait of Hormuz carried cameras with Chinese made components that sent routine "heartbeat" signals to an IP address in China.
Britain's Royal Marines have been running a £12m (about $15m at recent exchange rates) fleet of K3 Scout uncrewed surface vessels, small autonomous boats, since March, with the boats bound for the Strait of Hormuz and a supplier roster that runs through a British defence contractor. The Ministry of Defence confirmed this week, after the Sunday Telegraph reported it, that the cameras on the boats were sending routine "heartbeat" pings, the online-check signals networked devices send to confirm they are reachable, to an IP address in China. The mechanism that was supposed to stop this was a third party brought in between the British contractor, Kraken Technology Group, and the camera supplier, which gave "security assurances" that the components were clean. The assurance failed.
The MoD's position is narrow and worth stating in full. The cameras' internet connectivity was stripped after the anomalous traffic was observed, and the department says it has no evidence that sensitive information or systems were compromised or sent overseas. That is not the same as saying the cameras were not talking. It is saying the data on the other end of the conversation, if any, has not been verified. The Royal Navy's own newsroom has been running the K3 Scout as a flagship example of what uncrewed surface vessels can do at sea; the gap between that marketing and the supply chain is what this story is about.
The gap is structural and has a name. Third-party self-certification of a component, without a component-level provenance audit and without baseline monitoring of the component's outbound network traffic, is not a supply-chain safeguard. It is a checklist item. The cameras cleared the third party, the third party gave the assurance, the assurance went into a procurement file, and no one looked at the network log of a single camera before the boats went into service. By the time the anomalous traffic was identified, the procurement firewall had failed in the way it was always going to fail.
This is the third public supply-chain finding in UK defence procurement in under two years, and the pattern is consistent. In 2023 the government began the legislative unwind of Huawei's role in 5G networks, a decision driven by exactly the same insight: vendor self-certification, however sincere, does not survive a hostile supply chain. Last year, AOAV documented Chinese-made drone technology being tested at RAF Waddington, a sensitive military site, with the same procurement-by-component pattern: equipment sourced through intermediaries, no provenance audit, no outbound traffic baseline. The Royal United Services Institute's November 2025 paper on decoupling drone supply chains from China is the analytical anchor for what is now a documented procurement problem, not a one-off.
The Conservative shadow security minister, Alicia Kearns, put the sovereignty point cleanly: "If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign." That point is the constructive part of the story. The current firewall does not fail because someone broke the rules. It fails because the rules did not require a component-level audit or a network-log baseline. A firewall that only catches the failure after the equipment is in service is a forensic tool, not a safeguard.
The fix is unglamorous and does not require new legislation. It requires the Ministry of Defence to require, for any component sourced through an intermediary, a documented bill of materials at the part-number level and a baseline of the component's normal network behaviour, recorded before deployment, against which any future outbound traffic can be compared. The RUSI paper makes the same case from a different angle: the UK cannot continue to treat Chinese component exposure as a Huawei-shaped problem when the procurement is now component-shaped, with cameras, sensors, and flight controllers arriving through layers of distributors. The K3 Scout fleet is the cleanest example yet of what that gap costs in the time it takes to identify what the assurance was supposed to have caught.
The MoD's confirmation of the cameras, the order to strip their connectivity, and the "no evidence" line amount to a procurement audit that should have run before the boats left the dock. The same audit now has to run, in advance, on every uncrewed platform the Royal Navy brings into service.