- What: A July 10 advisory from the Dutch AIVD and MIVD says at least one Russian intelligence service is systematically hijacking internet-exposed IP cameras across EU/NATO states and Ukraine to surveil military transport routes and weapons shipments, with image-recognition software automating the search for military vehicles.
- Impact: In Ukraine, compromised cameras have been used in attempts to kill personnel and destroy equipment, and across NATO the same access collects military intelligence; Censys counts 87,000+ exposed cameras in the region matching known-exploited vulnerabilities.
- Fix / mitigation: Take cameras off the public internet (kill port forwarding and UPnP, front them with a VPN), replace default credentials, enable MFA, patch firmware including CVE-2016-7407 (Dropbear) and CVE-2021-39275 (Apache, fixed in 2.4.49), and keep sensitive sites out of frame.
- Who's at risk: Any organization running internet-reachable cameras near transport routes, ports, logistics hubs, or military-adjacent infrastructure in Europe and Ukraine, from businesses to municipalities to homeowners.
At least one Russian intelligence service is running an ongoing campaign to hijack internet-connected security cameras across Europe and Ukraine, using the live feeds to monitor military transport routes, weapons shipments bound for Kyiv, and Ukrainian troop positions. That is the core finding of a July 10 advisory from the AIVD and MIVD, the Netherlands' civilian and military intelligence services. Inside Ukraine, the access has gone beyond watching: the services say camera feeds have been used in attempts to neutralise Ukrainian military personnel and destroy equipment. A roadside camera or a shop's parking-lot feed becomes a targeting aid. Across EU and NATO states, the same access is also collecting military intelligence unrelated to the war.
The tradecraft is embarrassingly simple
Nothing in the advisory requires a zero-day. The operators scan the internet for exposed devices, fingerprint cameras by brand, and log into the ones still running default passwords, obsolete firmware, and untouched factory settings. Once inside, image-recognition software does the heavy lifting, running automated searches through video for military vehicles and the cargo they carry. That automation matters: it converts thousands of low-value individual feeds into a scalable collection platform. No human has to watch anything until the software flags a convoy.
How big is the exposed surface
Censys, in its own analysis of the advisory, counted more than 87,000 internet-connected cameras across the EU, NATO members, and Ukraine running a service whose version matches a known-exploited vulnerability, a figure it calls a lower bound. More than 4,000 of those sit in Ukraine. In the Netherlands alone, Censys found 45,386 cameras reachable from the public internet, flagged 1,992 as running a service with a known-exploited vulnerability, and narrowed that to 541 when counting only bugs in the camera software itself. Censys keeps the wider count on the logic that a foothold on any service on the host can often be leveraged into full device takeover.
A service banner is not a reachable exploit. Of the two CVEs Censys highlights, CVE-2016-7407 sits in dropbearconvert, a local key-import tool in the Dropbear SSH server that only executes code when someone converts a malicious key file; it was fixed in July 2016 and matched 159 Dutch hosts. CVE-2021-39275 is an out-of-bounds write in Apache that Apache itself rates low because no bundled module feeds untrusted data to the affected function; it was patched in 2.4.49 in 2021 and matched 112 Dutch hosts. Neither appears in CISA's KEV catalog, though Censys classifies both as exploited in the wild. As Censys researcher Martijn Grooten puts it: having a camera publicly accessible doesn't make it hackable.
Confirmed intrusions vs. theoretical exposure
Set the 87,000-camera exposure figure against what the Dutch services actually caught: a small number of confirmed camera breaches, sitting directly on military logistics routes inside the Netherlands. The affected organisations have been warned and are locking things down. The services also say they have not observed camera-derived intelligence being used for military attacks outside Ukraine. The gap between exposure and confirmed compromise is real, but the direction of the threat is unambiguous, and the operators are choosing cameras by what they can see, not by who owns them.
Why this model is portable
Both halves of this operation are ordinary. Entry is often just a default login. Value is set by where the lens happens to point. A compromised camera hands an adversary a live read on physical operations, when the trucks move, who comes and goes, and what sits on the loading dock, with no deeper network breach required. Any intelligence service, and plenty of criminal groups, can replicate this against ports, rail yards, data centers, or corporate campuses. If your camera overlooks anything an adversary would want to watch, assume someone has already scanned it.
What defenders should do
- Inventory exposure first: find every camera reachable from the public internet via forgotten port-forwards, UPnP mappings, or vendor cloud relays. Prioritise cameras overlooking transport routes, ports, and sensitive sites, and review their logs for unrecognised access.
- Get video off the public internet: disable port forwarding and UPnP, and reach cameras only through a VPN.
- Replace default credentials everywhere and enable MFA where the device supports it. Where it doesn't, that camera stays off the internet entirely.
- Aim the lens deliberately: keep logistics routes, loading docks, and sensitive areas out of frame, and mask what you can't avoid.
- Patch firmware and underlying services, including old bugs like CVE-2016-7407 and CVE-2021-39275, and buy cameras with years of security support, not months.
If your cameras have line of sight to military logistics routes, ports, rail, or defense-adjacent facilities anywhere in Europe, treat them as targeted now. Check access logs, rotate credentials, and pull them behind a VPN before your next maintenance window, not during it.
The fix is not glamorous and that is the point. This campaign succeeds because tens of thousands of devices were installed, exposed, and forgotten. Patching helps, but the durable fix is architectural: take the camera off the public internet and control what it can see. An adversary can't hijack a feed they can't reach, and can't exploit a view that was never in frame.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us