F35

The F-35 Shipment That Went to Hong Kong: Why Critical Components Need Verifiable Custody

Australia confirmed on 22 September that unserviceable F-35 components shipped from the country for repair in the United States had instead been diverted to Hong Kong. The Australian government is assisting US authorities and Lockheed Martin with the investigation.

ABC reported that the shipment included a canopy incorporating radar-resistant technology and that an intermediary was responsible for transport. Australia’s defence minister, Richard Marles, also said that, according to his understanding, no technologically sensitive equipment had been lost. The reason for the diversion, the present location of every component and any access by a third party have not been publicly confirmed.

That distinction matters. This is not evidence that China obtained F-35 secrets. It is evidence of a custody-control failure serious enough to trigger government and congressional scrutiny.

A manifest records intent, not physical reality

A shipping document can say “United States” while the physical asset travels somewhere else. In a multi-party transport chain, information moves through maintenance teams, freight forwarders, airlines, customs agents and repair facilities. A wrong routing instruction, an unauthorised change or a simple mismatch between systems can survive several handoffs before anyone sees the full picture.

Critical logistics therefore needs independent evidence tied to the component itself—not only to an aircraft, booking or airway bill.

At Sensefinity, we connect the physical unit to its digital identity. An item-level or case-level sensor can report location, movement, opening, light exposure, separation from its assigned container and abnormal loss of communication. Geofences can cover approved routes, airports and jurisdictions. When the component leaves that policy envelope, the platform can create an exception while intervention is still possible.

An alert does not prove hostile intent. It reduces the time between divergence and response.

Learn more about Sensefinity Cargo Safety.

A destination change must become a signed custody event

Rerouting is normal in global logistics. Silent rerouting is not acceptable for controlled components.

Every destination or carrier change should require:

  • strong identity for the requesting party;

  • dual authorisation for high-risk exceptions;

  • an explicit reason and timestamp;

  • confirmation through a channel independent of the change request;

  • acceptance by the new carrier and consignee;

  • reconciliation with the component’s live telemetry.

Each physical handoff should bind the person, organisation, component identifier, seal, time and location. If the transport record says the United States while the sensor indicates Hong Kong, the mismatch should block automatic acceptance and open an investigation.

Blockchain makes later rewriting visible

Sensors show what happened in the physical journey. Blockchain can help preserve who authorised it, what each participant accepted and which record existed at a specific time.

The right design for sensitive supply chains is permissioned. Military or commercially restricted information does not need to be published on a public chain. Hashes, identities, document versions and timestamps can be anchored while operational detail remains off-chain under access control.

This creates a shared, tamper-evident chronology across organisations that may not share one database. An investigator can compare the original manifest, authorised route, sensor events, custody receipts and later changes without trusting a single party’s retrospective export.

Blockchain does not make bad input true, and it does not physically prevent diversion. It is effective when combined with authenticated sensors, strong approvals and an operational response process.

See how our Blockchain solution connects telemetry, identity and chain of custody.

Five controls critical shipments should adopt now

  1. Bind identity to the physical unit. Link every component, case and container to its sensor, seal, manifest and authorised destination.

  2. Monitor policy, not just position. Alert on prohibited jurisdictions, route deviations, unplanned transfers, opening and abnormal silence.

  3. Make changes explicit. Require dual approval and out-of-band confirmation for destination, carrier or consignee changes.

  4. Prove every handoff. Record strong identity, time, location, condition and counterparty acceptance at each custody transfer.

  5. Preserve the evidence. Keep raw telemetry and anchor approvals and versions in a permissioned, tamper-evident record with defined escalation and recovery procedures.

The lesson is broader than defence. Semiconductor equipment, prototypes, medical products, luxury goods and other high-value assets face the same gap between the route written in a system and the journey taken by the physical object.

Critical cargo should never be “somewhere in the network.” It should have a continuously verifiable identity, route and custodian.

Read the complete Prova analysis, including the confirmed facts and the limits of what is publicly known.

Sources