Experts: British Unmanned Vessels Unveil Vulnerabilities, Advocating Zero Trust in Chinese Supply Chain.

The British Royal Navy found that a batch of unmanned surface vessels contained Chinese-made components in their cameras and had been sending heartbeat communication data to IP addresses within China. The Ministry of Defense stated that the connection had been severed, and no sensitive data breach was found in the investigation. However, scholars and commentators warned that such vulnerabilities could lead to intelligence leaks and system intrusions, potentially undermining allied trust.

The Royal Navy began using the K3 Scout unmanned surface vessels provided by the UK’s Kraken Technology Group in March of this year. These vessels are primarily operated by the Royal Marines’ coastal units and the 47th Assault Troop.

According to a report in the British Telegraph on August 9, during a routine network security vulnerability assessment, the Ministry of Defense discovered abnormal network communication from the camera systems of the unmanned vessels. Further investigation revealed that the cameras were sending “heartbeat communications” to an IP address in China to confirm the devices were online and functioning normally.

After identifying the issue, the UK Ministry of Defense immediately severed all internet connections related to the cameras and initiated a comprehensive investigation. They stated, “Our protection and testing processes are designed to identify and address potential vulnerabilities as early as possible, and we will continue to conduct routine security checks on all systems and equipment.”

Like most NATO countries, the UK Ministry of Defense has banned the use of Chinese components in military equipment due to concerns about espionage.

The K3 Scout unmanned surface vessels are capable of conducting remote reconnaissance, supporting various mission requirements such as maritime awareness, force protection, logistics support, and precision strikes, according to its supplier.

Kraken Technology Group responded that they had undergone a comprehensive review with the Royal Navy and confirmed that no sensitive information had flowed to unauthorized channels, and any potential security vulnerabilities had been addressed.

Several scholars and commentators analyzed the risks exposed by this incident from the perspectives of intelligence value and network security.

Taiwan’s Defense Security Research Institute researcher Shen Mingshi pointed out that this type of event typically involves typical network security vulnerabilities, including “unauthorized data leakage,” and the possibility of backdoors in the supply chain cannot be ruled out.

He said, “Even if the data transmitted is just the status of the ships and personnel activities, it involves the location and the nature of the missions. This data is high-value raw data for intelligence agencies.”

Shen Mingshi noted that special forces often carry out secret missions, and if the equipment’s dynamics and geographic locations continue to be transmitted externally, “it would be important intelligence for the CCP.”

American commentator Tang Jingyuan expressed a similar view, indicating that if similar equipment were deployed in hotspots like the Strait of Hormuz near Iran, the real-time location, activation time, and operational status of the devices could affect operational secrecy.

He believed that due to close ties between the CCP and Iran, there could be a possibility of relevant information being further transmitted to Iran. This could pose potential threats and risks to military operations among allies.

The K3 Scout was initially one of the key equipment for the UK’s future deployment in the Persian Gulf and the protection of the Strait of Hormuz’s freedom of navigation. Some preliminary preparation work related to this unmanned vessel has already begun.

The involved unmanned vessels had approached the headquarters of the UK’s Special Boat Service and sensitive military meeting places, raising concerns about potential security risks to military personnel and facilities.

The two interviewees further analyzed the chain reactions that this vulnerability could bring.

Shen Mingshi pointed out that if the equipment could bypass the military network’s existing firewalls and security restrictions to transmit data externally, the risks would no longer be limited to being “visible”.

More seriously, if attackers could use the same communication channel to issue malicious commands to the equipment, information theft could evolve into a system attack.

Shen Mingshi stated, “Attackers can use this channel to issue malicious commands, or possibly disable your camera during wartime, causing it to go blank or causing your data to become distorted, rendering the UK’s unmanned vessels instantly devoid of reconnaissance capabilities.”

Tang Jingyuan also shared the same perspective, stating that such a data leak channel could potentially become an entry point for remote access, leading to the risk of reverse attacks.

He said, “The CCP could potentially penetrate the UK military system through this technical method, sending remote commands to this equipment through this entry – equivalent to a backdoor – implanting viruses or trojans. It’s all possible.”

This incident has not only exposed a single equipment vulnerability but also involved long-standing supply chain concerns within the UK’s defense equipment system.

Apart from the UK, the US Special Operations Command has also procured such equipment and participated in NATO’s Baltic Sea tests.

Shen Mingshi believed that if similar vulnerabilities were to occur in future military conflicts in the Taiwan Strait or the South China Sea, the consequences could be more severe.

He emphasized that oceanic operations place higher demands on concealment or surprise attacks. Unmanned vessels often play roles in frontline reconnaissance or ambushes. If their locations are compromised, the distributed maritime operations advantage of the US and UK allies would be completely transparent, thus losing its edge.

Additionally, continuous real-time coordinate leaks could be utilized for weapon strikes or electronic warfare. A third impact would be a decrease in military deception capability. Shen Mingshi pointed out that if the adversary could long-term monitor the unmanned vessel’s positions and operational patterns, they could discern true military deployments from camouflage deployments through data analysis.

Therefore, he concluded, “Transmitting data means that your dynamics, actions, and intentions all become transparent, thereby significantly impacting your operational mission.”

This incident is also believed to potentially affect the advancement of the UK Royal Navy’s “Project Beehive,” which aims to enhance the UK military’s future maritime operational capabilities by integrating unmanned combat platforms with traditional warships for joint operations.

After the exposure of this incident, the opposition Conservative Party demanded a comprehensive review of military equipment by the government to identify if there are still security vulnerabilities involving Chinese components.

Regarding the risks exposed in the aforementioned procurement process, Shen Mingshi believed that Western countries’ supply chain security reviews need to change their approach. He stated, “Western countries’ risk assessment of China’s dual-use military and civilian items should not be merely random inspections; there should be zero trust in the Chinese supply chain because all Chinese enterprises must adhere to the political needs of the CCP.”

On the technical front, it is necessary to inspect whether there are backdoors or other potential risks in the chips. Additionally, he pointed out that the supply chain itself also needs to undergo security evaluations, including whether China could militarize the supply chain and cut off component supplies in case of conflict.

In recent years, the UK government has been continuously strengthening its security review of Chinese-related technology and equipment. In 2020, the UK decided to progressively exclude Huawei equipment from its 5G communication network on national security grounds. In recent years, the UK military has also been removing Chinese-made surveillance equipment and some hardware from sensitive locations. It was reported by the Telegraph that the UK’s Special Boat Service recently banned Chinese-made electric vehicles from entering its base.

Tang Jingyuan believed that the CCP’s “civil-military fusion” strategy and the National Intelligence Law are two crucial factors to consider when assessing security risks of Chinese-manufactured products.

Specifically in the fields of communication equipment, semiconductors, networks, and artificial intelligence. He mentioned that although these components or products may seem to be produced by ordinary Chinese private enterprises on the surface, they could have backdoors implanted or remote access channels reserved under the CCP’s military or intelligence requirements.

However, he also pointed out that it does not imply that every product manufactured by Chinese companies has been confirmed to have backdoors. Instead, from the perspective of national security review, systemic risks behind the CCP need to be considered.