By Carla O

Key takeaways

  • A camera component on a UK naval drone was found transmitting to a Chinese IP address, despite the drone passing every conventional procurement check, including NDAA compliance.
  • NDAA compliance only screens for specific listed Chinese military companies. It doesn’t address components sourced through unlisted suppliers or data exposure under China’s National Intelligence Law.
  • FOCI includes fourth-party risk: it hides in subcontractors, shell companies, and ownership changes that happen after a contractor has already cleared review. It requires continuous monitoring, not a one-time check.
  • Thorough risk management in government supply chains requires that contracting teams are supported by purpose-built AI/ML tools. 

A routine cyber-vulnerability assessment on a British naval drone found a camera component transmitting a signal to an internet address in China this month, according to UK officials. The drone, a K3 Scout built by a UK company, had passed every conventional procurement check.

The UK Ministry of Defense says no sensitive data or systems were compromised and that the vulnerability has been closed. But the finding raises a harder question: are defense procurement teams adequately equipped for the modern supply chain?


Fourth Party Risk

The manufacturer did not build the camera which transmitted data to China; they bought it, the way many manufacturers source critical and specialized components in a global economy. 

Representatives of the drone company said they had been given assurances about the security of the cameras in question, but drone-industry consultant Steve Wright told the Wall Street Journal that tracing a part’s actual origin, and monitoring it on an ongoing basis, is “really, really hard.” He now spends roughly half his advisory work on it.

The same drone company recently won a $49 million contract from U.S. Special Operations Command and a company spokesperson noted to journalists that the cameras in question are compliant with the U.S. National Defense Authorization Act (NDAA). However, NDAA compliance, as it stands today, only requires that a product be free of components sourced from specific manufacturers named on the 1260H list of Chinese military companies. Next year that policy expands to prohibit indirect business with 1260H-listed companies, including providing component parts. 

Even under the expanded rule, it isn’t clear this camera would be a prohibited component, since its manufacturer may not be a “Chinese Military Company.” However, any data entering China, even to private companies, is subject to the country’s 2017 National Intelligence Law, which requires organizations and citizens to support, assist, and cooperate with state intelligence work, and gives Beijing legal grounds to compel firms to build backdoors into equipment or software. 

Senator Chuck Grassley (R, IA)  wrote a letter to Secretary of War Heseth in May seeking information about what actions had been taken to address the presence of counterfeit Chinese components appearing in defense technology. 

Defense technology is not the only industry facing this challenge; in 2024, a congressional investigation found that some cargo cranes used at ports throughout the U.S. contained cellular modems from China that could allow covert espionage and disruption at ports.

More recently, the General Services Administration called for the U.S. AbilityOne Commission to verify the country of origin for many of its listed products after finding many foreign-made products, including technology from China, listed as “Made in America.

Letter-of-the-law compliance is insufficient to protect allied government operations against the threat posed by the Chinese government; Government contractors need to know where their component parts actually come from, so they can make informed decisions about where they’re willing to accept that risk.


The Intractable Threat

Global drone makers lean on Chinese suppliers for parts which are often higher-quality than Western-based alternatives and almost always cheaper. This is in part due to Chinese state sponsorship of drone technology, which serves both to support Chinese manufacturers and disadvantage competitors. The same economics that make Chinese parts attractive make them hard to fully cut out.

Even without these complications, identifying Foreign Ownership, Control, and Influence (FOCI) within a supply chain is complicated. FOCI risk often sits behind shell companies two or more tiers into the chain, inside a joint venture with an undisclosed beneficial owner, or in a supplier that was clean at initial qualification and has since changed hands. A contractor can clear every check at award and still be carrying risk that showed up afterward. That’s the core problem: FOCI risk is not a fact that is established once; it’s a condition that must be continuously monitored.

Vendor screening needs to assess not only the parties signing the contract, but also the vendors providing component parts, the investors and parent companies controlling operations, and other avenues of influence for bad actors.

The scale of such an endeavor cannot be handled manually. Extracting information accurately and understanding the full scope of risk to US interests requires artificial intelligence and machine learning.

A thorough investigation requires resolving entities across variant spellings and colloquial names, mapping relationships between companies and investors through multiple degrees of separation, and flagging risk factors tied to criminal activity or adversarial actors are all tasks that outstrip what analysts can do by hand across tens of millions of private companies, their vendors, and affiliates. But volume of signal is not the only bottleneck; judgment is another. Systems that surface more data without adjudicating it well simply trade missed threats for false positives, and both failure modes carry real cost: overlooked risk endangers national security, while overzealous flagging can disadvantage American companies competing in a global market and further slow an already tedious government contracting process.

The tools capable of closing this gap exist — Quantifind is one of them — but the continued presence of troublesome FOCI risk in government supply chains proves that they are inadequately deployed.


The Future for National Security

The U.S. and other NATO countries are moving in the right direction — toward requiring visibility into ownership and control that extends past the entity named on the contract, down through its suppliers, and down again through theirs. Knowing who signed the contract is the easy part, but knowing who owns the company that made the camera module is the part that actually determines exposure in a global marketplace.

The U.S. and its allies are only beginning to reckon with how many vulnerabilities like this one may already be sitting dormant, in the tools warfighters depend on and in the critical infrastructure everyday citizens rely on. That work needs to start now.


Quantifind is the leader in AI-driven risk intelligence, trusted by seven of the 10 largest U.S. banks and government agencies in the US and UK to uncover hidden risk in complex data. Its Graphyte™ platform combines machine learning, natural language processing, and proprietary Name Science™ to resolve entities and map complex relationship networks across billions of open-source records, detecting indicators of illicit finance, foreign influence, and supply-chain exposure. The result is explainable insight at scale, giving acquisition teams the ability to detect risk earlier and make confident procurement decisions at speed. 

For more information, visit https://www.quantifind.com/industry-public-sector/