← BACK TO FEED
RussiasurveillanceNATOcybersecurityUkraine

Russian Intel Is Using Your CCTV Camera to Watch NATO Weapons Shipments

Russian intelligence services are systematically compromising internet-connected security cameras across Europe and Ukraine to monitor military logistics, weapons shipments, and troop movements, according to a July 10 advisory from Dutch intelligence agencies. In Ukraine, the access has gone beyond surveillance, being used to target military personnel and equipment, while across NATO states it is gathering broader military intelligence. Entry is typically straightforward, exploiting default passwords, outdated firmware, and publicly exposed devices, with image-recognition software then automating the search for military vehicles and cargo.

At least one Russian intelligence service has been quietly hijacking internet-connected security cameras across Europe and Ukraine, using the footage to monitor military transport routes, track weapons convoys heading to Kyiv, and identify the movements of Ukrainian troops. This is not speculation. It is the conclusion of a joint advisory published on July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence agencies, who describe the operation as active and ongoing.

In Ukraine, the surveillance has crossed a line. Camera access there has reportedly been used in attempts to kill Ukrainian military personnel and destroy their equipment. A roadside shop camera or a business car park feed becomes a targeting tool. That is a significant escalation from passive intelligence gathering.

Across EU and NATO member states, the same compromised cameras are being used to collect broader military intelligence, unrelated to Ukraine entirely.

The technical entry point is embarrassingly mundane. Operators scan the internet for exposed devices, identify camera brands and models, then walk straight into the ones still running factory-default passwords, outdated firmware, or misconfigured settings nobody ever touched. Once in, automated image-recognition software does the legwork, scanning video feeds for military vehicles and cargo without a human needing to watch a single frame. No zero-days required. Just negligence.

Cybersecurity firm Censys, which scans the public internet, has tried to quantify how bad the exposed surface actually is. Across EU and NATO countries plus Ukraine, they counted over 87,000 internet-connected cameras running a service version that matches a known-exploited vulnerability. That figure includes more than 4,000 cameras in Ukraine alone. Censys calls this a lower bound.

In the Netherlands specifically, Censys found 45,386 cameras reachable from the public internet, with 1,992 flagged as running a service tied to a known vulnerability. If you narrow it down to bugs in camera software itself, that drops to 541. Censys keeps the broader count on the reasonable grounds that a foothold on any service running on a host can often escalate to full device compromise.

Two specific CVEs get a mention. CVE-2016-7407 affects a local key-import tool in the Dropbear SSH server and only fires when someone converts a malicious key file locally. It was patched in July 2016. CVE-2021-39275 is an out-of-bounds write in Apache that the Apache project itself rates as low severity, since exploiting it requires a third-party module feeding untrusted data to the affected function. It was fixed in Apache 2.4.49. Neither appears in CISA's Known Exploited Vulnerabilities catalogue, which is worth noting when someone calls them 'exploited in the wild.'

Version banner matching is not the same as a confirmed exploitable configuration, and Censys is transparent about this. The 87,000 figure describes exposure, not confirmed compromise.

On confirmed intrusions, the Dutch intelligence services are rather more restrained. In a separate statement, they said only a small number of cameras had actually been breached, specifically ones positioned along military logistics routes inside the Netherlands. The operators of those cameras have since been notified and told to clean things up.

So what should organisations actually do? The remediation list is unglamorous but effective. Audit what cameras are reachable from the public internet, whether through port forwarding, UPnP, or a vendor cloud relay. Prioritise any overlooking transport routes, loading docks, or sensitive infrastructure. Pull the video stream off the public internet entirely and route access through a VPN. Replace default credentials, enable MFA where the device supports it, and if it does not, keep it off the public internet. Think about what the camera can physically see and mask sensitive areas where possible. Patch firmware regularly, and when buying new kit, check that security updates are supported for more than a few months.

The Dutch services say they have not seen camera-derived intelligence used to support military attacks outside Ukraine. But the threat is portable because both halves of it are completely ordinary. Getting in often requires nothing more than a default login. The value of what you get depends entirely on where the camera happens to be pointing.

A compromised camera gives an adversary a live window into physical operations: when vehicles move, what they carry, who shows up. No network breach needed beyond the device itself. The fix is not just updating the firmware. It is taking the camera off the public internet and being deliberate about what it can see.

READ NEXT
Russia's Shadow Fleet May Be Running a Drone Harassment Campaign Across NATO EuropeThis Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand TotalRansomware Knocks Fairlife's US Dairy Plants Offline