UK DEFENCE INDUSTRY TECH NEWS

Newsletter>

UK DEFENCE INDUSTRY TECH NEWS

UK Defence Tech logo

The fear of Chinese components phoning home

by | Aug 19, 2026 | Insights, Cyber & Electronics

The peculiar situation that Chinese electronics and components, in defence and civilian projects, are potentially sending data back to China. And how that is exacerbated by China's National Intelligence Law

News broke recently that components installed in some Royal Navy unmanned vessels were transmitting data to China, prompting headlines such as “Royal Navy Faces Security Questions After £12M Drones Sent Data to China'”and “UK MoD plays down leak fears over China-linked K3 USV cameras”. It was The Telegraph that broke the story with the headline “Spy cameras on Navy drones secretly sent data to China”. Grand headlines from an excited press desperate for click-bait, are Chinese components phoning home, or is the reality a bit more mundane? Yet we all know that mundane data is the bread and butter of intelligence gathering.

It’s not the first time that fears have been raised over Chinese components essentially phoning home, sensitive conversations being listened to, or video from the multitude of cameras on modern vehicles being sent somewhere it shouldn’t. Fears that have prompted precautions, bans on vehicles and in some instances removal of cameras completely. As part of our focus on technology and electronics in the UK defence environment it’s worth looking at some of these cases in more detail. We also show just what that Chinese Intelligence Law is and why it matters.

What exactly is going on?

The most recent issue was reported earlier in August 2026 concerning the Kraken Technology K3 Scout, an Uncrewed Surface Vessel designed to support surveillance, coastal operations and warfare development. The main operators of the craft were said to be the Coastal Forces Squadron and 47 Commando Royal Marines, the media reports of “Britain’s elite special forces” using them could just be The Telegraph getting over excited about the whole thing (something we would never do obviously). Project Beehive as it has been named is all about testing and evaluating, so these vehicles are not deployed operationally yet.

The Kraken K3 Scout Drone

The story says that investigators found cameras on the vessels that were sending automated “heartbeat” pings to a Chinese IP address. These ‘pings’ were coming from components of Chinese-origin embedded in third-party NDAA compliant cameras. The MoD cut internet access to the cameras and says no sensitive data was transferred. The MoD stated that it has found “no evidence of MoD data or systems being accessed, compromised or transmitted externally”. It seems to be just a case of a potential vulnerability being detected and fixed that has been puffed up into a dramatic read.

Naval Technology contacted Kraken Technologies who assured them that “After a full audit by both Kraken and the Royal Navy we are confident no sensitive information has ever been shared outside of intended channels and any potential vulnerabilities have been identified and closed.”

The K3 Scout looks like a very well designed piece of kit, hence them winning the contract with the MoD. What the story highlights is the labyrinthine world of component supply chains that stretches back through all of the suppliers that were involved in the technology within the craft. Fundamentally the weakness was discovered in testing and has been rectified, but these are the ones we know about, is it the tip of an iceberg?

The SBS ban Chinese EVs from Poole headquarters

Again the press get excited if they can mention the Special Forces in a headline, this was just one story from a slew of issues around Chinese vehicles plus ones containing components made in China (what ones don’t?), so as well as Chinese brands like BYD you also have Volvo, VW and BMW EVs with a lot of Chinese electronics within them – actually every vehicle on the road today, electric, petrol or diesel has a lot of electronics, the bulk of which will have been sourced from China.

The concern is onboard cameras, radar, and sensors could map the base or track personnel. We know that this is a very simple thing to do, eight years ago the US military realised its personnel were sharing workout and run data from their bases on the Strava app. Incredibly it is still happening with military personnel posting their swims, runs, bike and walking routes from the Gulf states in the front line of the current US – Iranian war. The data can be used to construct the daily routines in the bases and give some picture of deployment patterns across all of these military bases. The immediate concern is for the individuals as they post under their real names and effectively make a target of themselves for coercion or attack.

The security and espionage risk posed by Electric Vehicles

A modern car, whether EV or traditional combustion technology, is basically a mobile surveillance platform. Kitted out with onboard cameras, audio, radar, and sensors, they have rapidly become a security headache. The M0D has committed to reducing its reliance on fossil fuels so has hundreds of electric and hybrid cars and vans in its vehicle fleet, they are playing safe and issuing advice and restrictions on what can be connected to and talked about in these vehicles.

RAF Wyton

Entrance to the Pathfinder Building, RAF Wyton. Not an Electric Vehicle in sight. Image: UK MOD © Crown copyright 2025

Electric vehicle manufacturers are aggressively pursuing ‘software as a service’ (SaaS) on a subscription model – so your nice new BMW comes with a host of features, very few are available on the base models, you enable them by paying a bit more each month. It is cheaper to manufacture a platform with a host of features that can be turned on and off than it is to run production lines building customised versions for each order. So the vast proportion of vehicles on the road are packed with sensors, navigation equipment, ultrasonics and video to support driver-assistance functions.

Advice by the MoD is that no military devices are connected or conversations above the level of ‘official’ are conducted in fleet or hire vehicles. Individual base commanders are allowed to introduce security measures to deal with these challenges. At RAF Wyton, personnel have reportedly been told to park two miles away from the base if their vehicle has Chinese components. RAF Wyton is an intelligence gathering base so it’s not surprising, but the threat is being taken very seriously. It should be stressed that there is no evidence that any intel has been passed to third parties in this way.

Let’s use Chinese drones to survey critical infrastructure

Hopefully those exact words have never been said out loud but that is exactly what happened. In April 2025 UK officials raised alarm that DJI drones were being used to survey sensitive sites including Hinkley Point C nuclear plant, Thames Water reservoirs, and solar energy facilities, despite a 2023 MI5/NPSA warning to avoid drones from “countries with coercive data sharing practices.” The US had already blacklisted DJI.

What is China’s National Intelligence Law?

There’s a clear pattern emerging here across various categories; surveillance cameras, drones, uncrewed vessels, vehicles, all involving Chinese components with network or sensor capabilities that could ‘phone home’. The K3 drone story is just the latest in this ongoing concern around data transmission; most are precautionary bans based on the theoretical risk under China’s National Intelligence Law.

China’s National Intelligence Law was passed in June 2017 and amended in 2018. It’s a relatively short piece of legislation just 32 articles, but Article 7 is the one that concerns Western governments. In full, it reads:

“All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law, and shall protect national intelligence work secrets they are aware of.”

The word “all” is critical. It applies to Chinese citizens, Chinese companies, and any organisation with a physical or operational presence in China, including foreign-invested businesses.

Does it apply to Chinese companies or citizens outside of China?

There’s a lot of argument about this as it’s not referenced explicitly in the text. A 2019 analysis by Swedish law firm Mannheimer Swartling concluded the law does apply to overseas subsidiaries of Chinese companies and to Chinese citizens working abroad. Western security agencies have broadly taken the same view. China disputes this, arguing the law is purely domestic and that Western critics are misreading it, though Beijing also points out that the US, UK, and other Five Eyes nations have their own laws compelling domestic companies to cooperate with intelligence services, which is true, but sidesteps the foreign-hardware question. Western governments do have similar powers in principle, but with judicial oversight and narrower scope. China’s critics argue Article 7 is broader, vaguer, and has no independent check on when or why it’s invoked.

It’s a problem for hardware procurement

This law applies to any Chinese manufacturer, camera makers like Hikvision and Dahua, drone makers like DJI, EV manufacturers like BYD. If Chinese intelligence services request data collected by their products, those companies are legally obligated to hand it over and, crucially, to keep the request secret. There is no need for a court order, no transparency mechanism, and no way for the company to warn its customers that a request has been made.

This is why the concern isn’t hypothetical. It’s not that anyone has necessarily proven Hikvision cameras have been actively used to spy on UK government buildings, or that DJI drones are streaming footage to Beijing in real time. It’s that the legal architecture to enable that requires cooperation if asked, with no recourse.

The laws it sits alongside

The 2017 National Intelligence Law doesn’t stand alone. It works in concert with:

  • 2015 National Security Law, which has similarly broad “support the state” obligations
  • 2021 Data Security Law, which governs how data must be classified and handled, with government access provisions
  • 2021 Personal Information Protection Law, which paradoxically restricts data flows out of China, except when the state requests them

Together, these create what critics describe as a legal framework designed to give the Chinese state access to any data it wants while restricting anyone else’s access to Chinese data.

What Western governments have done about it

The UK government specifically cited the National Intelligence Law when it ordered the removal of Hikvision and Dahua cameras from sensitive sites in 2022. The same logic underpins the SBS EV ban, the RAF Wyton parking restrictions, and the MoD’s response to the K3 drone incident. The argument is consistent: if a device collects data and contains Chinese components, the manufacturer is potentially obligated to provide that data to Beijing on demand.

This is going to be an ongoing issue that requires awareness and proactive steps, a gift for headline writers in the press, but without that constant vigilance we are dealing with a major security failure.

Written by Iain Hazlewood

Latest on UK DEFTECH

Apex Europe Preview: Voyant, Seeing the Unseen

One of the companies attending APEX Europe in London this October is Voyant, a University of Liverpool spin-out that is dedicated to developing software designed to make every military platform and sensor smarter, without replacing the hardware underneath.

Read More

Newsletter

Keep in the loop with breaking UK defence tech industry news, insights and features

Sign Up Now >

LAND

AIR

SEA

CYBER & electronics

More Posts