IP cameras hacked through NATO: new revival of the AIVD/MIVD case

In this saga : Renseignement russe et surface d'attaque IoT en Europe· Episode 3/3

Cybersecurity 6 h agoAdd to bookmarks

IP cameras hacked through NATO: new revival of the AIVD/MIVD case
Illustration : Momiji Shirogane

The Dutch services AIVD and MIVD reconfirm that unit 26165 of the GRU (« Fancy Bear ») exploits poorly configured IP cameras to track NATO's military logistics - a signal that the geekkitsune watch thread has been following for several editions.

Where we stand

New publication attributed to Dutch intelligence services (AIVD, civil; MIVD, military) that confirms and details what the "Russian intelligence and IoT attack surface" thread has been documenting for several editions: Russian military intelligence (unit 26165 of the GRU, also known as APT28 / Fancy Bear) uses compromised IP video surveillance cameras as remote sensors to monitor Western military logistics flows, particularly to Ukraine.

What's new in this publication

  • The report expands the geographical scope observed beyond the Netherlands alone: several NATO member countries are affected (rail transit points, depots, strategic roads).
  • The targeted cameras are mostly low-cost models, connected to the Internet without changing the factory password or exposing accessible administration interfaces.
  • Access is used both to observe directly (real-time video streams) and to position intelligence for other operations (targeting, calibrating kinetic drone attacks).

What remains true since the beginning of the thread

  • The "public IoT in a strategic environment" attack surface has never been taken seriously enough given the risk: retail cameras, obsolete DVRs, SOHO routers.
  • The attacker does not need an advanced exploit - enumeration and default credentials often suffice.
  • Low-end hardware providers do not push automatic updates and have no contractual obligation towards end users.

Actions to take

  • For local authorities and private actors located on strategic routes: complete audit of exposed cameras/DVRs (Shodan, Censys), reset credentials, firmware update, VPN placement.
  • For logistics site operators: inventory of IoT equipment, strict network segmentation, UPnP deactivation.
  • For decision-makers: the issue is no longer theoretical - it is a documented military espionage vector by two allied services.

Analysis

The AIVD/MIVD report completes the establishment of a standard: in an economy where cheap hardware is as available as it is uncorrectable, the IoT surface is now a full-fledged intelligence domain. The geekkitsune thread will continue to follow documented campaigns, compromised hardware models, and regulatory responses (European Cyber Resilience Act, in particular).

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

7 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information