The UK Ministry of Defense is stepping-up scrutiny of its supply chain after discovering some of its naval drones transmitted signals to China. The department revealed earlier this week that a routine cyber vulnerability assessment identified an issue affecting K3 Scout drones made by Kraken Technology Group and used by the Royal Navy.
Officials are looking for other vulnerabilities in its defense industry, including if any other contractors use cameras made by the same supplier that Kraken sourced from, according to people familiar with the matter who asked not to be identified discussing private conversations.
“Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake security activity across our systems and equipment,” the ministry said in a statement. “These include active program which review risks of potential adversarial exposure within our supply base and design appropriate mitigations.”
The Kraken surveillance drones had components made in China that were secretly transmitting information to a device in the country, the Telegraph reported earlier this week. Some of the drones could be sent to the Strait of Hormuz if the UK and France proceed with a de-mining mission that’s being prepared for after a US-Iran peace deal.
The ministry said its investigation found no evidence of the government’s data or systems being accessed, compromised or transmitted externally. Instead, the drones’ cameras sent what are known as “heartbeat communications” to an IP address in China that could identify their location and whether they were in use at the time, the Telegraph reported and defense officials confirmed.
A Kraken spokesperson said some third-party cameras, compliant with the US National Defense Authorization Act, had a small number of components originating from outside the UK. The spokesperson said no sensitive information was shared and any potential vulnerabilities were identified and closed.
The discovery exposes the fragility of defense supply chains, particularly in ensuring against components unknowingly being used from countries which may seek to exploit such vulnerabilities to spy on Britain’s military activities.
The department is keeping its processes under review to ensure their effectiveness against evolving threats, the people said, though have so far chosen not to conduct a full audit across the industry.
The risk is that the UK got lucky in identifying the issue, some officials told Bloomberg. The ministry has warned its suppliers that they should meet both contractual security requirements and internationally recognized security standards, one of the people said.
This report is auto generated from the Bloomberg news service. ThePrint holds no responsibility for its content.

