IP cameras hacked: the AIVD/MIVD report documents Russian intelligence monitoring NATO military logistics

In this saga : Renseignement russe et surface d'attaque IoT en Europe· Episode 2/2

Cybersecurity 9 h agoAdd to bookmarks

IP cameras hacked: the AIVD/MIVD report documents Russian intelligence monitoring NATO military logistics
Illustration : Momiji Shirogane

Dutch intelligence services publish a joint advisory: at least one Russian service systematically hijacks connected security cameras to spy on arms convoy routes to Ukraine and troop positions.

Facts

Hacker News reports on July 20, 2026, a joint opinion of the Dutch civil (AIVD) and military (MIVD) intelligence services published on July 10, 2026. According to this opinion, at least one Russian intelligence service systematically hijacks Internet-connected security cameras across Europe and Ukraine.

The compromised video streams are used to:

  • observe military transport routes (NATO logistics convoys, equipment destined for Ukraine);
  • monitor weapon deliveries to Kiev;
  • track the position of Ukrainian troops.

Analysis - why the IP camera is the perfect attack surface

What the AIVD/MIVD documents is not a sophisticated exploit: it is a civil infrastructure hijacking made possible by default passwords, exposed admin interfaces, aging firmwares. We follow this dynamic in our thread russian-intelligence-iot: the current campaign is in line with the 87,000 poorly configured cameras already exploited, which we previously discussed.

Three elements make the IP camera ideal for this type of intelligence engineering:

  1. It is in a position of permanent observation, often at a crossroads, at a depot or at the entrance to a sensitive site.
  2. It is rarely patched: owners treat them as devices that "work", not as information systems.
  3. It produces a stream that can be exploited in real time, whereas a compromised computer produces data that needs to be sorted.

To do - for NATO and private organizations

  1. Inventory all IP cameras visible from the Internet within the organization's perimeter (Shodan, ZoomEye, internal scans).
  2. Segregate: cameras have nothing to do on the same network as user stations, even less accessible from the WAN without VPN.
  3. Audit passwords: the campaign partly exploits default or weak credentials.
  4. Firmware: establish a minimum update policy, even on equipment treated as furniture.
  5. Log admin accesses: a successful login from a foreign ASN on a camera installed in a port is a signal.

To remember

The AIVD/MIVD opinion confirms what the defensive community has been hammering home for years: a connected camera is a potential listening post for a state adversary. The threat is no longer theoretical - it is documented, it is active, and it targets specific military objectives. Treating IP cameras as information security equipment is no longer an option for critical infrastructures.

Thread continuity: this article extends the follow-up started on russian-intelligence-iot with an official source that goes further up the campaign chain.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

6 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information