Copisito bonito, Wikimedia Commons, CC BY-SA 4.0
Pollar Originals·Published August 11, 2026 at 06:15 PM·14 min read

Nobody had to open the camera

The cameras on the Royal Navy's drone boats travelled with a compliance claim that everyone above them relied on. The standard behind it names companies rather than a country, and defines diligence as an inquiry that never requires anyone to look inside.

The cameras on the Royal Navy's drone boats travelled with a compliance claim that everyone above them relied on. The standard behind that claim names companies rather than a country, has no legal force in a British purchase, and defines diligence, in its own text, as an inquiry that never requires anyone to look inside. The heartbeat found its way to China through paperwork that may never have been wrong.

Two words did the work here: NDAA compliant.

In the security camera trade the phrase points at one law. Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 is the provision the United States wrote to keep Chinese surveillance equipment out of its government systems, and the industry has organised itself around it: manufacturers publish NDAA compliance statements at model level and buyers write the term into procurement checklists. When Kraken Technology Group described the cameras on the Royal Navy's K3 Scouts as "third-party, NDAA-compliant", that is the standard the phrase invokes. Kraken's statement does not specify a clause, and nothing published since has, but in this market the shorthand has only one referent.

What the standard actually says is narrower than the shorthand implies, and stranger.

Five names and a signature

The prohibition sits in the American Federal Acquisition Regulation, at clause 52.204-25. "Covered" equipment means telecommunications equipment produced by Huawei or ZTE; video surveillance and telecommunications equipment produced by Hytera, Hangzhou Hikvision or Dahua, where bought for security purposes; any subsidiary or affiliate of those five; and, as a final category, equipment from any entity the US defence secretary "reasonably believes" to be owned or controlled by, or otherwise connected to, the Chinese government. Five named companies, and a designation power that has to be exercised name by name.

Nowhere in that definition is country of origin the test. A camera assembled in Shenzhen by a firm that appears on no list is compliant. So is every module inside it, wherever the parts were made, so long as no listed or designated entity produced them. Kraken's statement that its NDAA-compliant cameras "had a small number of components originating from outside the UK" reads at first like a contradiction. It is an accurate account of how the standard works.

There is a second property of Section 889 that no coverage of this story has mentioned. It is United States federal procurement law. The prohibition binds "the head of an executive agency" of the American government; the clause is inserted into American federal contracts. Nothing in it governs what the British Ministry of Defence may buy, and nothing in it obliged anyone in this supply chain to do anything at all. Attached to a Royal Navy purchase, "NDAA compliant" is not a regulatory status. It is a product description, borrowed from someone else's rulebook.

Diligence, as defined

Then there is the question of how a company establishes that it complies, and here the regulation is explicit about its own limits. Clause 52.204-25 defines the standard of care it expects:

Reasonable inquiry means an inquiry designed to uncover any information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity that excludes the need to include an internal or third-party audit.

An inquiry that excludes the need for an audit. The rule anticipates the question of whether anyone must take the equipment apart, and answers it in the definition: no.

The mechanism that produces a compliance claim follows from that. The companion clause, FAR 52.204-24, is a representation. The seller ticks a box, offer by offer, stating whether it will provide covered equipment, and a second box stating whether, "after conducting a reasonable inquiry", it uses any. The first box does not even carry the inquiry requirement; the only procedure the clause prescribes is a search of an American database of excluded companies. What travels down a supply chain under this regime is not a test result. It is the seller's declaration about itself.

A defence source told the Telegraph the affair was a "major failure to check origins of components". Under the standard whose name was on the cameras, checking origins was never anyone's job. The certificate is the diligence.

How a compliant camera phones home

None of the published accounts explain the mechanism by which a camera with clean paperwork ends up contacting China. A documented one exists, and it is seven years old.

In April 2019 the security researcher Paul Marrapese published an analysis of iLnkP2P, peer-to-peer software written by the Chinese firm Shenzhen Yunni Technology and built into millions of internet-connected cameras, video recorders and baby monitors. His scanning identified more than two million such devices online. The behaviour he described maps onto the Royal Navy story almost word for word: "Upon being connected to a network, iLnkP2P devices will regularly send a heartbeat or 'here I am' message to their preconfigured P2P servers and await further instructions."

Three properties of that arrangement carry over. The signalling is deliberate: the keepalive exists so that a customer can watch a camera from a phone without configuring a router, a selling point written into the firmware on purpose. It is invisible to branding: one Chinese vendor, HiChip, accounted for nearly half the affected devices, sold under a list of other names, and Marrapese described Shenzhen Yunni as "an upstream vendor with inestimable sub-vendors due to the practice of white-labeling and reselling". And it resists being switched off: there is no practical way to disable it, the software slips past router controls by UDP hole punching, and the mitigation Marrapese identified for devices already installed was a firewall rule blocking the traffic at the network edge. Taking the network away from the camera, in substance, which is what the Ministry of Defence did.

Neither Shenzhen Yunni nor HiChip is named in Section 889.

Ours is not the only reading. Writing in the Telegraph on 10 August, the former Royal Navy officer Tom Sharpe put the question to Lee Hannaford, director of defence, national security and intelligence at the consultancy Larkspur International. Hannaford said that many Chinese devices and subsystems, among them cameras, batteries and cellular internet-of-things modules, "are designed to require ongoing digital connectivity to their parent organisations". Once those channels exist, he said, they "can be leveraged" for "data collection, command-and-control, or pre-positioning for disruption", and "encryption of payload data does not eliminate the risk".

That is the same mechanism described from the other end. Marrapese found it in the firmware of consumer cameras in 2019; Hannaford describes it in 2026 as a design property of a class of components that includes the one on this mast. Neither of them is talking about a hack. They are talking about a feature.

None of this identifies the K3's cameras. No manufacturer has been named in any published account, and this piece will not name one: Pollar holds photographs of the unit, a white marine electro-optical camera with paired day and thermal apertures, a class of device sold by many companies, and identifying a commercial product from visual resemblance, in a story about equipment signalling China, would be defamatory if wrong and unverifiable if right. What the 2019 research establishes is not the culprit but the route: an ordinary, mass-market, entirely legal way for a camera carrying a truthful compliance claim to tell a server in China, at intervals, that it is alive.

Two readings, one root

Because the vendor is unknown, the published record supports two accounts of the certificate, and nothing in it allows a choice between them.

In the first, the certificate was accurate. The cameras contained parts from Chinese manufacturers that Section 889 does not name, the attestation was true when it was made, and the boats signalled China anyway, because the standard was never designed to prevent that.

In the second, the certificate was wrong. The cameras were white-labelled equipment from a listed entity, and nobody caught it, because the diligence standard excludes the step that would have. Industry compliance guidance treats this as routine: "A camera sold under a U.S. or European-sounding brand may still be Hikvision or Dahua at the hardware layer," notes a May 2026 compliance briefing by IntelliSee, which records white-label inventory audits as the most common source of Section 889 findings in 2025 and 2026. The instrument doing the finding in those cases is an audit, the step the definition of reasonable inquiry excuses.

The two accounts share a root. In one, the paperwork was true and insufficient. In the other, it was false and unexamined. Either way, the assurance the Royal Navy's supply chain ran on was a declaration nobody was obliged to test, and either way the declaration still stands: nobody has withdrawn it, and nothing published contradicts it.

The British instruments are also declarations

It would be comfortable to read this as an American standard failing a British buyer. Britain's own instruments follow the same design.

The Ministry of Defence builds cyber security into its supply chain through the Cyber Security Model, imposed contractually by Defence Condition 658. A delivery team assesses an activity and sets a risk profile; then, in the department's published wording, "suppliers self-assess against the CSM requirements using a Supplier Assurance Questionnaire". The questionnaire is scored automatically and the supplier is told at once whether it has passed. Prime contractors run the same process on their subcontractors, and those on theirs, "onwards down the sub-contracting tiers to the end of the supply chain". That regime governs a supplier's cyber posture rather than the provenance of hardware inside a delivered product, and the published guidance does not establish that it reaches this camera. The pattern is the point: at every tier of a British defence supply chain, the instrument of assurance is a questionnaire the supplier completes about itself.

Britain also has its own rule about Chinese surveillance equipment, older than this story and broader than Section 889. In November 2022, Oliver Dowden told Parliament that departments had been instructed "to cease deployment of such equipment onto sensitive sites, where it is produced by companies subject to the National Intelligence Law of the People's Republic of China". That is a jurisdiction test rather than a list of names, and on its face it catches companies the American clause misses. The same statement advised that no such equipment "should be connected to departmental core networks". The vector this camera used was named in Whitehall four years ago. But the instruction attaches to sites. Departments were also told to consider whether to remove and replace such equipment where it was already deployed. Nothing published says anyone applied any of it to boats.

What the record does not contain

As of 11 August 2026, no published account states how often the cameras signalled, which company made them, which third party sold them to Kraken, how many of the twenty hulls were affected, when the vulnerability assessment took place or what prompted it, whether the cameras have been replaced or only cut off, whether the same units sit on other Ministry of Defence equipment, or what was at the other end of the connection.

The Ministry's position has not moved: a routine assessment found the issue, and a thorough investigation "found no evidence of MoD data or systems being accessed, compromised or transmitted externally". Nothing published gives a reason to doubt that, and the argument here does not need one.

Take the denial entirely at its word and the question survives it. A signal carrying no content still tells whoever receives it that a device exists, that it is powered, that it has a route out, and that at the moment it stops, something about it has changed. Sharpe reaches for the case that made this public: in 2018, he writes, Strava's fitness heat maps "revealed supposedly secret Western bases by publishing soldiers' jogging routes". Nothing was hacked there either. What was published was where people had been and when, aggregated, and that was the base. His own comparison is to phone handshakes, which give away almost nothing one at a time and, in their millions, "reveal locations, patterns of life and tempo".

Which is why he does not dismiss it. "Knowing when and possibly where a camera on a special forces vessel wakes up," he writes, "is not nothing."

Geography is the one place the record contradicts itself, and it is worth setting out rather than smoothing over. The Telegraph photographed a K3 in Portsmouth harbour, and the King's Harbour Master's own notice has K3 trials running in the Solent until December. But on 10 August the Telegraph also wrote that the fleet has been "operated from the Special Boat Service's Poole headquarters since March", while the Royal Navy's announcement in March assigned the boats to the Coastal Forces Squadron and to 47 Commando Royal Marines, formations based at Portsmouth and at RM Tamar in Devonport. Both accounts are published, neither has been withdrawn, and they cannot both be the whole picture. What the original report claims more narrowly is that special forces used the drones and that security-cleared staff at their headquarters may have appeared on camera.

In May, the MoD said the drones would form part of a potential deployment to protect shipping in the Strait of Hormuz, in the event of a lasting ceasefire. No K3 has been reported there. The stakes attached to a camera's field of view were not hypothetical.

The audit arrived late

None of this equipment was bought carelessly, which is what gives the story its shape. The contract went through a competitive tender with twelve bidders, among them BAE Systems, Kongsberg and L3Harris. It was decided on 5 March and announced on the 11th, at £10.25m excluding VAT, and won by a company founded in 2020 whose investors include the NATO Innovation Fund and the UK's own National Security Strategic Investment Fund, whose customers include US Special Operations Command, and which builds alongside Rheinmetall's naval division. The Government had pledged £5bn for drone technology and promised procurement would be "unashamedly pro-Britain". This was the best-credentialed chain British defence technology could assemble, and its assurance still consisted of declarations.

Kraken's response to the story deserves quoting in full: "We are aware that some third-party, NDAA-compliant cameras had a small number of components originating from outside the UK. After a full audit by both Kraken and the Royal Navy we are confident no sensitive information has ever been shared outside of intended channels and any potential vulnerabilities have been identified and closed." The statement names no country. It does name an audit, by builder and Navy together, which is the one form of diligence the compliance standard's own definition excuses. It took place after the heartbeat was found.

The political response points the same way. Alicia Kearns, the shadow security minister: "If we cannot say with confidence what is inside our own military equipment, we cannot say it is ours, or that we are sovereign." Her party has called on the Government to "urgently audit" its equipment for Chinese components. An audit would answer the question. It is also precisely the step that the standard being audited against says nobody ever had to take.

The internet came off the cameras. The published record does not say the cameras came off the boats. And the two words that travelled with them, from an unnamed third party to the builder to the Navy, remain, so far as anything published shows, true.


Sources: The Telegraph, 9 and 10 August 2026 (the second by Tom Sharpe, carrying the Hannaford and Strava material); The Register, 10 August 2026; The Wall Street Journal, 10 August 2026; The Independent, 10 August 2026; Navy Lookout, 11 March 2026, for the tender, the bidders, Kraken's founding, its investors, its US Special Operations Command work and the Rheinmetall joint venture; the Royal Navy's own award announcement, 11 March 2026; the MoD award notice on Find a Tender, 2026/S 000-021405, for the 5 March decision date and both contract figures; Kraken Technology Group; FAR 52.204-24 and 52.204-25, acquisition.gov; KrebsOnSecurity, 2 April 2019, on research by Paul Marrapese; IntelliSee compliance briefing, May 2026; gov.uk, Cyber Security Model; written ministerial statement HCWS386, 24 November 2022. Pollar did not approach the Ministry of Defence or Kraken Technology Group for comment before publication.