AI News Feed
Market watch
Cybersecurity

Cyber Test Finds Royal Navy Drone Camera Parts Sending Heartbeat Signals to China

TechRadar reports that third-party camera components intended for Royal Navy drones sent automated heartbeat signals to an IP address in China. No evidence of data theft has been found, and the affected links were cut after routine testing.

TechRadar described the episode as less dramatic than the initial reports suggested but more useful as a warning. A heartbeat signal is a device announcing that it is alive, and on its own appears to carry little meaning. The report noted that basic telemetry can still disclose device presence, uptime and temporal patterns, showing when equipment comes online, how long it stays active and whether its use follows a routine.

That kind of data rarely delivers intelligence by itself, the outlet wrote. It becomes relevant when combined with open-source information, signals intelligence, routing metadata or knowledge of exercises and deployments. The report stated there is no public evidence that the incident exposed Royal Navy locations, personnel or operational movements, and no confirmed data theft.

The analysis, written by a partner at Avella Security, argued that the more useful question is not only whether sensitive information left the system but what someone could infer from the information that did. Where an unexpected external communications path is discovered, the report said, an organization also needs to establish what a component could potentially transmit, not merely what has already travelled across it.

The report took issue with calls to simply buy British. It said pulling apart a supposedly trusted product often reveals processors, cameras, communications modules, microcontrollers and firmware from suppliers scattered worldwide, making modern defence capability a systems-integration exercise conducted across global supply chains. Defence organizations may understand their Tier One suppliers well, but visibility can deteriorate at Tier Two, Tier Three and beyond, exactly where specialist manufacturers, smaller technology providers and software dependencies enter.

Assurance can be performed in depth, but doing so for every component of every system without slowing innovation and raising costs is difficult, particularly for startups. Switching from a commercial component to a sovereign or trusted alternative can mean higher costs and longer lead times as well as hardware redesign, software changes, testing and recertification, according to the report.

The article pointed to Ukraine as evidence that relatively inexpensive unmanned systems which can be produced, modified and replaced quickly now carry military value, without removing the need for sophisticated missiles or high-end platforms. Future forces will need both high-end capability and technology that can be manufactured at scale and adapted as battlefield conditions change, which commercial off-the-shelf components help make possible. That creates a tension at the centre of strategic autonomy: the global technology ecosystem that lets defence companies innovate quickly and cheaply can generate the dependencies governments are trying to reduce.

The report concluded that risk should be determined by what a component can actually do rather than by the country on its label. The questions it proposed are what a component can see, what it can do, whether it can communicate independently and whether its behaviour can be changed, with a connected, programmable camera warranting considerably greater scrutiny.

Editor's Summary

Routine cyber testing reportedly found third-party camera components intended for Royal Navy drones sending automated heartbeat signals to an IP address in China, after which the affected connectivity was removed and the vulnerabilities closed. No evidence has been made public that classified systems, data or imagery were accessed. The episode has drawn attention to how little defence organizations can know about components several tiers down their technology supply chains.