Dutch intelligence services warned that a Russian intelligence service is systematically compromising internet-connected security cameras in Europe and Ukraine to monitor military transport routes, weapons shipments bound for Kyiv, and Ukrainian troop positions. Authorities said the operation is ongoing and that, in Ukraine, access to breached cameras has been used in attempts to help locate personnel and destroy military equipment. The campaign reportedly targets cameras positioned along sensitive logistics corridors, with Dutch investigators identifying a limited number of compromised devices in the Netherlands and notifying affected organizations.
Reporting indicates the operation relies primarily on weak security rather than novel exploits, including default passwords, unchanged factory settings, outdated firmware, and direct internet exposure. Censys said the exposed attack surface for vulnerable cameras across EU and NATO countries and Ukraine remains significant, while cautioning that exposure and version fingerprinting alone do not confirm compromise. Officials urged organizations to remove cameras from public internet access, disable port forwarding and UPnP, use VPN-based remote access, rotate default credentials, enable MFA where supported, patch firmware, and avoid camera views that reveal sensitive military or transport activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Dutch authorities said they identified a small number of actually breached cameras in the Netherlands located along military logistics routes. They notified the affected organizations about the compromises.
Dutch intelligence services warned that at least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine to monitor military transport routes, weapons shipments to Kyiv, and Ukrainian troop locations. The advisory said the operation is ongoing and that in Ukraine, compromised camera access has been used in attempts to help neutralize military personnel and destroy equipment.
Censys separately estimated a large exposed attack surface of internet-connected cameras across the EU, NATO member states, and Ukraine. It cautioned that internet exposure and version matching do not by themselves prove exploitability or compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecensys.com
Open sourceenglish.aivd.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.