Russian Military Espionage Campaign Exploits Hacked IP Cameras Across NATO and Ukraine
- Jul 20
- 4 min read
Key Findings
Russian intelligence services are systematically hacking internet-connected IP cameras across NATO member states, EU countries, and Ukraine
Camera feeds are used to monitor military transport routes, weapons shipments to Ukraine, and locations of Ukrainian troops
In Ukraine, hacked camera access has been directly used to target and neutralize Ukrainian military personnel and equipment
The operation relies on basic tactics: default passwords, outdated firmware, and factory settings rather than sophisticated zero-day exploits
Automated image-recognition software scans video feeds for military vehicles and their cargo
Dutch intelligence caught only a small number of compromised cameras on military logistics routes within the Netherlands, but assesses the capability threat extends across NATO
This represents a small part of a larger systematic Russian cyber espionage campaign that intensified since the full-scale invasion of Ukraine
Background
The Netherlands' AIVD and MIVD, the civilian and military intelligence services respectively, published a joint advisory on July 10 confirming the operation. The finding is based on intelligence gathered by both services and covers a campaign that has escalated since Russia's invasion of Ukraine began. Dutch officials characterize this as an ongoing operation demonstrating Russian state actors' capability to derive significant tactical and strategic advantages from cyber operations supporting military objectives.
The Ukraine Application
In Ukraine, the surveillance operation has moved beyond passive intelligence collection. Russian forces use the camera access to identify locations of Ukrainian military personnel, and this information is subsequently used to conduct military strikes against Ukrainian forces and their equipment. A roadside camera or business camera overlooking a loading area becomes a targeting asset. The chain is direct: a default password left unchanged leads to reconnaissance that informs strikes on Ukrainian positions.
The information obtained reveals EU and NATO military transport routes and weapon deliveries to Ukraine. Russian operators use image recognition software to conduct targeted automated searches through video feeds, looking specifically for military vehicles and the cargo they carry. The system requires no sophisticated hacking tools, just access to a compromised camera and basic automation.
Surveillance in NATO and EU States
Across EU and NATO member states, the same camera hacking is collecting military intelligence unrelated to the Ukraine war. This broader surveillance serves a different but related strategic purpose. The Dutch services have not observed camera-derived intelligence being used for military attacks outside Ukraine to date. However, they assess that Russia now possesses demonstrated capability to apply this approach in future conflicts, and the same tactics could be adapted by Russian military units operating in other theaters.
The intelligence collected in NATO and EU states includes data on military transport routes and weapons movements, providing Russia with advance visibility into allied military logistics and capabilities.
Technical Method
The intrusion technique is straightforward and requires no zero-day vulnerabilities. Russian operators scan the internet for exposed IP cameras, fingerprint the devices by brand and model, then attempt to gain access through the internet. Many cameras remain vulnerable because they lack adequate security measures: default passwords are never changed, firmware remains outdated, and factory configurations stay untouched.
Once inside a camera, image-recognition software runs automated searches through the video feed looking for military vehicles and their cargo. The operation is efficient and scalable because the barrier to entry is low and the payoff—a live view of physical operations—is immediate and actionable.
Exposure Scale
The scale of exposed cameras is substantial. Across the EU, NATO members, and Ukraine, researchers at Censys counted more than 87,000 internet-connected cameras running services with known-exploited vulnerabilities, with more than 4,000 of those located in Ukraine. In the Netherlands alone, Censys found 45,386 cameras reachable from the public internet, with 1,992 flagged as running services with known vulnerabilities. When narrowed to bugs in the camera software itself, the Dutch figure drops to 541.
Being reachable from the internet is not identical to being hacked, but the exposed surface remains enormous. The Dutch services separately confirmed they caught a small number of cameras breached directly on military logistics routes inside the Netherlands and warned the organizations running them so they could take corrective action.
Recommended Defenses
Organizations should start by identifying which cameras are reachable from the public internet through port-forwards, UPnP mappings, or vendor cloud relays. Cameras overlooking transport routes, ports, and other sensitive sites deserve priority attention, with logs checked for unrecognized access.
Keep video streams off the public internet by disabling port forwarding and UPnP, and access cameras instead through a VPN. Replace all default credentials and enable multi-factor authentication where supported. Where MFA is not available, keep the camera off the public internet entirely.
Deliberately aim camera lenses to exclude logistics routes, loading docks, and other sensitive areas. Where sensitive spots cannot be avoided, mask them from the frame. Patch firmware and software regularly, and when purchasing new cameras, prioritize vendors offering years of security support rather than just months.
Strategic Implications
Dutch intelligence assesses there has been a systematic increase in digital espionage operations by Russian state actors supporting military operations since the Ukraine war began. The IP camera surveillance forms only a small part of their broader cyber operations. What makes this threat particularly portable is the ordinariness of both components: entry is often just a default login, and the value is determined by what the camera happens to observe.
A compromised camera hands an adversary a live read on physical operations—when trucks move, who comes and goes—without requiring deeper breach of protected networks. This capability, once demonstrated, establishes a baseline threat that Russian military planners can reference for future operations.
Sources
https://securityaffairs.com/195708/intelligence/dutch-intelligence-warns-russia-uses-hacked-ip-cameras-for-military-espionage.html
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
https://www.facebook.com/alyona.mclevin.50596/posts/the-dutch-intelligence-service-aivd-warns-nato-countries-that-russia-is-hacking-/37428582813422373

Comments