Russian intelligence agencies have been systematically commandeering internet-connected security cameras across Europe and Ukraine to gather intelligence on military logistics and troop movements. This operation, detailed in a cybersecurity advisory published by the Netherlands' civilian and military intelligence services, AIVD and MIVD, is ongoing and involves using camera feeds to monitor transport routes and weapons shipments intended for Kyiv. In Ukraine, this surveillance has escalated beyond passive observation, with camera access being used to target Ukrainian military personnel and equipment.

The method of infiltration is relatively straightforward. Operatives scan for exposed devices, identify IP cameras by brand, and exploit those still operating with default settings, outdated firmware, or unchanged factory passwords. Once access is gained, image-recognition software is employed to scan the video feeds for military vehicles and cargo. Notably, these intrusions do not require zero-day vulnerabilities.

Despite misconceptions, being accessible online does not equate to being hacked. Martijn Grooten, a principal security researcher at Censys, notes that a publicly accessible camera is not inherently vulnerable. However, the scale of exposure is significant; Censys identified over 87,000 internet-connected cameras across the EU, NATO countries, and Ukraine running services with known vulnerabilities. This figure includes approximately 4,000 cameras in Ukraine alone.

In the Netherlands, Censys discovered 45,386 cameras accessible from the internet, with 1,992 running vulnerable services. When narrowed to issues within the camera software itself, this number decreases to 541. Censys maintains a broader count based on the premise that exploiting one service can lead to control of the entire host.

Two specific vulnerabilities were highlighted: CVE-2016-7407, related to the Dropbear SSH server, and CVE-2021-39275, an out-of-bounds write issue in Apache. Both have been patched, yet Censys counts them as exploited in the wild despite their exclusion from CISA's Known Exploited Vulnerabilities catalog.

Dutch services reported only a few confirmed camera breaches, primarily along military logistics routes in the Netherlands. Organizations responsible for these cameras have been notified to secure their systems. The threat is made portable by the simplicity of the attack; often, the only barrier is a default login, and the risk is determined by the camera's location. The solution involves more than just patching devices; it requires removing them from public internet access and controlling their field of view.