The UK Ministry of Defence identified Chinese-made components in Royal Navy drones that were transmitting automated "heartbeat" signals to an IP address located in China.
Key Points
- Routine cyber testing discovered unauthorized heartbeat communications originating from third-party camera components within Royal Navy drone systems.
- There is currently no evidence that classified Ministry of Defence data, imagery, or sensitive systems were accessed or exfiltrated during the incident.
- Officials responded by removing internet connectivity from the affected camera subsystems and closing the identified security vulnerabilities.
- The incident highlights the difficulty of maintaining visibility into deep-tier technology supply chains where components are sourced from global manufacturers.
- Experts suggest using architectural controls like network segmentation and air-gapping to mitigate risks from components that do not require internet access.