Russian Intelligence Hacks IP Cameras to Track Weapons Deliveries to Ukraine
Russian state operators are systematically hacking internet-connected cameras to monitor military transport routes, weapons deliveries to Ukraine, and the locations of Ukrainian personnel, according to Dutch intelligence agencies.
The Netherlands General Intelligence and Security Service, known as AIVD, and the Military Intelligence and Security Service, or MIVD, attributed the campaign to at least one Russian intelligence and security service. Their joint cybersecurity advisory covers activity in the Netherlands, Ukraine, and other EU and NATO countries.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The operators target poorly secured IP cameras and analyze their footage with image-recognition software. This allows them to search for military vehicles, identify transported equipment, map logistics routes, and follow activity around facilities that support Ukraine.
How Russian Operators Gain Access to IP Cameras
The campaign does not rely on a newly disclosed zero-day vulnerability or a named malware family. Russian operators scan the public internet for cameras and identify devices through characteristics such as their manufacturer, model, software, or exposed network services.
They then target devices that retain default passwords, use obsolete firmware, expose administrative interfaces, or keep unsafe factory configurations. The official AIVD and MIVD report describes access to many cameras as relatively simple because owners often connect them to the internet without adequate protections.
After gaining access, the operators can view live video or stored footage. Image-recognition tools help them search large volumes of material for specific vehicle types, cargo, uniforms, facilities, and movement patterns.
What Camera Footage Can Reveal
A camera does not need to face a military facility to provide useful intelligence. Cameras outside petrol stations, warehouses, factories, ports, roadside businesses, and private properties can capture vehicles travelling along nearby roads.
One feed may show only a passing truck or convoy. However, analysts can combine footage from several locations to estimate a route, destination, delivery schedule, or recurring operational pattern.
Artificial intelligence can accelerate this work by identifying objects across many streams and connecting separate sightings. This reduces the effort required to follow vehicles across regions or find activity connected to a specific logistics network.
| Camera location | Potential intelligence value |
|---|---|
| Public road or motorway | Vehicle types, convoy direction, timing, and route patterns |
| Petrol station | Vehicle stops, personnel movements, registration details, and travel direction |
| Warehouse or loading area | Delivery schedules, cargo handling, and security procedures |
| Port or railway facility | Transport methods, shipment transfers, and military equipment movements |
| Industrial facility | Operational routines, entrances, contractors, and protected areas |
| Residential or commercial property | Nearby road activity and movements around sensitive locations |
Dutch Agencies Confirmed Camera Compromises
Dutch intelligence identified a small number of compromised cameras positioned directly along military logistics routes in the Netherlands. Authorities informed the organizations responsible for those devices so they could secure them.
The Netherlands attracts Russian intelligence attention because it serves as an important transit country and provides substantial military support to Ukraine. Camera access can help an adversary observe shipments without compromising a military network or logistics company directly.
The Dutch agencies also reported a systematic increase in Russian digital espionage supporting military operations since the start of the war. However, they described camera hacking as one part of a much broader intelligence effort.
Camera Intelligence Has Supported Russian Operations in Ukraine
Inside Ukraine, Russian actors have used access to IP cameras to identify the locations of Ukrainian military personnel and equipment. Dutch intelligence linked the collected information to attempts to neutralize personnel and destroy military materiel.
The joint intelligence assessment warns that Russian cyber operations may also provide early notice of Ukrainian troop movements and planned operations. Such intelligence can help Russian forces disrupt activities or reduce their effectiveness.
AIVD and MIVD have not observed Russia using information from European camera feeds to conduct military attacks outside Ukraine. However, the campaign demonstrates a capability that Russian military units could use more extensively during a future conflict.
More Than 87,000 Cameras Run Potentially Vulnerable Services
Internet intelligence company Censys examined publicly reachable cameras across EU and NATO countries, as well as Ukraine. Its camera exposure analysis identified more than 87,000 devices running at least one service with a version linked to a known-exploited vulnerability.
The total represents a potential attack surface, not a count of confirmed compromises. Censys based its results on internet scan data and service-version matches, which cannot confirm whether every device has a vulnerable configuration.

Censys also described the figure as a lower bound. Its query did not account for zero-day vulnerabilities, unknown exploitation, cameras protected behind other services, or devices that attackers could access through weak or stolen credentials.
| Country | Internet-connected cameras | Cameras running potentially vulnerable services |
|---|---|---|
| Netherlands | 45,386 | 1,992 |
| Ukraine | 60,487 | 4,097 |
| Germany | 65,539 | 8,401 |
| France | 68,317 | 8,977 |
| Italy | 99,203 | 12,678 |
| Poland | 57,534 | 4,250 |
| Romania | 64,789 | 1,963 |
| United Kingdom | 113,962 | 7,142 |
Why the Netherlands Figures Need Context
Censys found 45,386 cameras directly reachable through public IP addresses in the Netherlands. Of those, 1,992 hosts ran at least one service with a version associated with a vulnerability that attackers have exploited in real-world incidents.
However, the vulnerable service did not always belong to the camera software. A host may run a camera service alongside SSH, a web server, or another network-accessible component. A flaw in any of these services could still provide a route to control the wider device.
When Censys limited its search to known-exploited vulnerabilities affecting camera software itself, it found 541 services in the Netherlands. This narrower figure provides greater camera-specific relevance but still relies on version identification rather than direct exploitation tests.
Older Vulnerabilities Remain a Problem
Censys identified 159 Dutch hosts that appeared to run software associated with CVE-2016-7407, an arbitrary code execution vulnerability involving the Dropbear SSH software. Researchers disclosed that vulnerability in 2017.
The company also found 112 cameras that appeared to use Apache HTTP Server versions associated with CVE-2021-39275, an out-of-bounds write vulnerability. These findings show how old software can remain exposed on devices that organizations rarely include in normal patching programs.
Internet-accessible cameras often operate for years with little maintenance. Facility teams may manage them separately from servers, laptops, and other systems covered by corporate security tools.
How Organizations Can Protect IP Cameras
The Dutch agencies recommend reducing both the likelihood of compromise and the intelligence value of camera footage. The first step involves identifying every camera and related management service that the organization exposes to the public internet.
- Remove direct internet access unless operations require it.
- Disable unnecessary port forwarding and Universal Plug and Play.
- Require remote users to connect through a secured VPN.
- Replace default passwords with strong, unique credentials.
- Enable multifactor authentication when the camera supports it.
- Separate administrator accounts from accounts used only to view streams.
- Install current firmware and software updates.
- Replace cameras that no longer receive security updates.
- Place cameras on a network separated from business and operational systems.
- Monitor logins, configuration changes, and unexpected outbound connections.
The agencies also recommend checking what each camera can see. Operators should avoid capturing military routes, loading areas, ports, checkpoints, fuel stops, or unrelated public spaces when those areas fall outside the cameraโs security purpose.
Camera owners can adjust the viewing angle, apply privacy masks, blur sensitive areas, and remove location metadata from video where possible. These controls can reduce the usefulness of a stream even if an attacker gains access.
The Dutch intelligence guidance also urges organizations to assess camera suppliers and the security risks associated with their countries of origin. Procurement teams should consider update support, vulnerability disclosure processes, and remote-access architecture before purchasing equipment.
IP Cameras Now Carry Operational Security Risks
A compromised camera may not contain customer databases or confidential documents. Its live stream can still expose entrances, vehicle movements, staff routines, delivery schedules, security measures, and sensitive physical operations.
Organizations that operate near transport corridors, ports, railway facilities, defence companies, energy infrastructure, or military sites face particular risks. Their cameras may capture useful intelligence even when the organizations have no direct role in weapons deliveries.
The Censys findings show how widely this risk extends across Europe. Security teams should treat cameras as networked computers, include them in asset inventories, and protect them with the same discipline applied to other internet-facing systems.
FAQ
Dutch intelligence says Russian operators use camera footage to identify military vehicles, monitor weapons deliveries to Ukraine, map transport routes, and locate Ukrainian military personnel and equipment.
The operators scan the internet for exposed cameras and target devices with default passwords, outdated firmware, unsafe factory settings, or vulnerable network services.
No. Censys identified more than 87,000 internet-connected cameras running services whose versions matched known-exploited vulnerabilities. The figure represents potential exposure, not confirmed compromises.
Censys counted 60,487 internet-connected cameras in Ukraine. Of those, 4,097 ran at least one service whose version matched a known-exploited vulnerability.
Organizations should remove unnecessary internet exposure, change default passwords, install firmware updates, use VPN-based remote access, enable multifactor authentication, isolate camera networks, and limit each camera’s field of view.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages