Russian intelligence operatives are hacking internet-connected security cameras across Europe and Ukraine, using ordinary roadside and commercial surveillance systems to follow military vehicles, weapons shipments and the movements of Ukrainian troops.

The operation allows Russia to collect physical intelligence without breaching military networks. A camera outside a petrol station, warehouse or loading zone can reveal when a convoy passes, what type of vehicles it contains and which route it is following.

The Netherlands’ General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD) disclosed the findings. The agencies said that at least one Russian intelligence service was systematically accessing IP cameras in the Netherlands, Ukraine, and other EU and NATO member states.

Software searches camera footage for military vehicles

The stolen video is not necessarily watched manually. According to the Dutch intelligence services, Russian operators use image-recognition software to search captured footage for military vehicles and the cargo they carry.

Automated analysis makes it possible to examine feeds from large numbers of cameras and identify useful activity without continuously assigning people to watch each one.

A single camera may record only one vehicle at one location. Footage gathered from several points along a route, however, can help reveal convoy schedules, frequently used roads and the movement of particular categories of military equipment.

The intelligence collected includes information about EU and NATO military transport routes, weapons deliveries to Ukraine and the locations of Ukrainian military personnel. Russian operators are also collecting military information in European states that is not directly connected to the war in Ukraine.

Camera footage used against Ukrainian forces

Inside Ukraine, the surveillance has moved beyond reconnaissance.

The Dutch agencies said that those who compromised the cameras used the information they obtained to locate and “neutralise” Ukrainian military personnel and destroy equipment used by the Ukrainian armed forces.

They have not observed Russian services using intelligence from hacked cameras to support military attacks outside Ukraine. However, the same method allows Russian services to monitor sensitive physical activity elsewhere without accessing protected defence systems.

Investigators confirmed that attackers had compromised a small number of cameras along military logistics routes in the Netherlands. They warned operators to secure the devices.

The cameras are often poorly protected

The intrusions do not necessarily depend on previously unknown vulnerabilities or highly sophisticated malware.

Attackers can use internet-scanning services to locate exposed cameras and identify details such as their manufacturer or software. They can then test the devices for default passwords, outdated firmware and insecure factory configurations.

Many IP cameras remain accessible from the public internet because owners enable port forwarding, leave automatic network settings active or fail to replace the credentials supplied with the device.

Once attackers gain control, the camera becomes a live view of the physical site. It may expose vehicle movements, delivery schedules, personnel routines and activity around entrances or loading areas.

The Dutch advisory describes gaining access as relatively simple in many cases because security measures on internet-connected cameras are often inadequate.

More than 87,000 potentially exposed cameras identified

An analysis by internet-intelligence company Censys found more than 87,000 internet-connected camera hosts across EU and NATO countries and Ukraine running at least one service associated with a potentially exploited vulnerability. More than 4,000 were located in Ukraine.

The figure does not represent confirmed Russian intrusions. It also does not prove that every listed camera can be successfully hacked.

Censys based the count on software and service versions visible during internet scans. Some identified vulnerabilities may affect another service operating on the same host rather than the camera software itself.

In the Netherlands, Censys identified 45,386 publicly reachable cameras. Of these, 1,992 appeared to run a service associated with a known exploited vulnerability. When the search was restricted to weaknesses in camera software itself, the number fell to 541.

Part of a broader campaign against military logistics

The latest findings follow earlier warnings about Russian cyber operations directed at organisations supplying Ukraine.

In May 2025, cybersecurity agencies from several countries attributed a campaign against Western logistics and technology organisations to Unit 26165 of Russia’s GRU military intelligence service, also tracked as APT28.

That operation targeted organisations involved in coordinating and transporting aid to Ukraine. The attackers also sought access to internet-connected cameras at Ukrainian border crossings and near military installations to monitor shipments.

The new Dutch advisory does not identify the Russian service responsible for the latest operation. It describes the camera intrusions as systematic and ongoing.

Recommended protections include removing camera feeds from the public internet, disabling port forwarding and UPnP, replacing default passwords and keeping firmware updated.