Dutch intelligence agencies AIVD and MIVD warned that Russian state-backed hackers are systematically compromising internet-connected IP cameras in the Netherlands, elsewhere in Europe, and Ukraine to support military espionage. The operation targets exposed cameras with default passwords, outdated firmware, and insecure default settings, then uses the video feeds to monitor NATO military logistics, including routes linked to weapons shipments bound for Ukraine. Dutch authorities said a small number of compromised cameras were identified along military logistics routes in the Netherlands, a key transit country for support to Kyiv.
The advisory said the campaign extends beyond supply-chain surveillance and, in Ukraine, compromised cameras have in some cases been used to help locate Ukrainian troops for attempted battlefield strikes. Investigators said the actors also apply image-recognition software to analyze footage for military vehicles and cargo, underscoring a broader Russian effort to collect militarily relevant intelligence inside NATO and EU countries. The Dutch services described the activity as an ongoing espionage operation and issued security guidance to help organizations secure internet-accessible cameras against further compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2026-07-10, Dutch intelligence services AIVD and MIVD published a security advisory warning that Russian state-backed actors were compromising internet-accessible IP cameras in the Netherlands, other European NATO countries, and Ukraine for military espionage. The advisory said the activity supported intelligence collection on NATO logistics and weapons shipments and included guidance to help defend against the campaign.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourceaivd.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.