A few months ago, my colleague Markus Mueller wrote about how IP cameras have become standard equipment in modern warfare: hijacked for pre-strike reconnaissance, real-time targeting and post-strike bomb damage assessment. That piece was about the battlefield. This one is about the road that leads to it.
On July 10, the Dutch intelligence services (the AIVD and MIVD) went public with a joint finding: Russian operators had compromised internet-connected cameras, including a small number positioned along military transport routes inside the Netherlands. The goal was not a missile correction, as in Iran, but still reconnaissance supporting a war effort. By watching those feeds, Russia could see what was moving, when it moved and what kind of defense equipment was headed toward Ukraine.
The Dutch agencies were blunt about two things. First, this was not only a Dutch problem: they described the tactic as one Russia uses systematically across other NATO and EU countries, and inside Ukraine itself. Second, it was shamefully simple. The cameras were easy to hack because many still ran default passwords or outdated firmware. Three days later, the Netherlands summoned the Russian ambassador over it.
Nozomi Networks Labs has spent the last five years pulling these IoT devices apart, and the findings are consistent: improper authentication and authentication bypass, command injection and hard-coded or weak credentials, across multiple vendors.
Surveilling IP Camera Feeds in Business Parks, Parking Lots… and Doorbells
If this sounds familiar, it should. An April 2025 joint cybersecurity advisory signed by more than 20 international agencies documented that since February 2022, Russian military unit 26165, better known as APT28 or Fancy Bear, had been hacking IP cameras near Ukrainian border crossings, rail stations and military sites to track Western aid. The battlefield targeting Markus described and the supply-route surveillance the Dutch just exposed are two ends of the same campaign.
What changed is the ambition. Watching a border crossing near a war zone is one thing. Watching a business park camera or even a doorbell camera three countries away, on the road NATO uses to move material, is strategic espionage against the logistics tail. The device is the same cheap camera. The mission moved upstream. The level of planning, reconnaissance, coordination and execution at scale is a magnitude more complex.
Why IP Cameras? Unauthenticated, Unpatched and Unmanaged.
There’s nothing exotic here, and that’s the point. IP cameras are attractive to an intelligence service for the same reasons they frustrate the people who own them.
- They are exposed. Search engines like Shodan and Censys index internet-facing devices constantly, and an attacker can find cameras with open or unauthenticated feeds in minutes. Censys alone identified 680 unauthenticated Dahua feeds reachable on the public internet in a single March scan.
- They are unpatched. The prior post pointed to CVE-2021-36260, a Hikvision command-injection flaw that hands an attacker full root control of the device. A patch has existed for years. Plenty of devices never got it, because nobody was sure whose job it was to apply it.
- They are orphaned. A camera bolted to the side of a warehouse in 2019 often has no clear owner, no maintenance contract and no one watching its logs. That ambiguity is the vulnerability. An attacker doesn’t need a zero-day when the front door still uses the password printed in the manual.
Nozomi Networks Labs has spent the last five years pulling these IoT devices apart, and the findings are consistent: improper authentication and authentication bypass, command injection and hard-coded or weak credentials, across multiple vendors, including five new flaws in Hanwha Vision’s Wisenet line. Of the more than one million devices Nozomi monitors through anonymized telemetry, roughly 8% are IP cameras. They’re everywhere, and most of them were installed to watch a parking lot, not to survive a nation-state.
From Reconnaissance to Payload: One Long Campaign
If a hacked camera sounds like a low-grade problem, consider what could happen when bad actors move from surveillance to weaponization. On July 13, the UK and EU formally attributed the December 2025 attack on Poland’s power grid to the Russian FSB’s Centre 16 division. Investigators say the operators tried to deploy destructive wiper malware and, had it succeeded, could have cut power to roughly 500,000 people in midwinter. It failed, and the response was the first joint UK-EU cyber sanctions package.
The attack on Poland’s power grid attack may seem unrelated, and no doubt Centre 16 would have you believe so. However, the same list of Centre 16 targets reads like a map of the NATO supply route: France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, Finland. Passive camera surveillance and an attempted grid wiper are not separate stories. They are the reconnaissance and the payload of one long campaign, and the cheap IoT device is how a lot of it starts.
Secure Your IP Cameras with Basic Cyber Hygiene
Here’s the part that should be reassuring, if you act on it. Almost every entry point in these operations comes back to hygiene, not sorcery. You don’t defend against this with a better algorithm. You defend against it by doing the unglamorous work.
Immediate Steps
- Start by finding what you have. You cannot protect a camera you didn’t know was on your network or facing the internet. Assess your external IP space and internal IoT estate and build an accurate inventory of devices, and how and where they communicate.
- Remove exposed devices from the open internet and put remote access behind a VPN or a zero-trust gateway.
- Change the credentials, all of them, because the default password is the single most reliable way in.
Medium-term Steps
- Prioritize firmware updates on the devices you now know you own.
- Segment the camera network away from your OT and business systems so a compromised feed cannot become a foothold.
- Watch for the tells: repeated login failures, logins from odd places and cameras suddenly making outbound connections they never made before.
None of this is new advice. That’s exactly why it works, and why it keeps getting skipped.
What Do Your Cameras See, and Who Might Be Interested?
If you operate along a transport corridor, run a rail or logistics site, or simply own a lot of cameras, assume yours could be of interest to someone whose interest has nothing to do with you and everything to do with what passes by. That’s not a reason for alarm. It’s a reason to close the easy doors before someone else uses them.
Nozomi Networks helps critical infrastructure operators see every OT and IoT device on their networks, spot the exposed and unpatched ones, and monitor them for exactly the kind of quiet access these campaigns depend on. If you are not sure what your cameras can see, or who else can see through them, that’s a conversation worth having. Contact us.






