Russian Intelligence Is Using IP Cameras Across Europe for Military Espionage

19.07.2026 3 minutes Author: Newsman

Dutch intelligence agencies say Russian state-backed hackers are actively exploiting compromised IP cameras across Europe to gather military intelligence. They use automated image recognition software to analyze live video feeds, helping identify potential targets and monitor strategically important locations.

According to the Netherlands’ General Intelligence and Security Service (AIVD) and Military Intelligence and Security Service (MIVD), the attackers are primarily interested in monitoring freight movements, logistics routes, weapons shipments to Ukraine, and the possible locations of military personnel.

“Russia’s intelligence service uses access to IP cameras to collect relevant military intelligence in EU and NATO member states, including information that is not directly related to the war in Ukraine,” AIVD and MIVD said in a joint statement.

Dutch intelligence agencies also reported that footage obtained from compromised cameras in Ukraine has already been used in attempts to locate Ukrainian military personnel and destroy military equipment. While there have been no confirmed cases of this tactic being used in military attacks outside Ukraine, the agencies warn that Russia could employ the same methods in future conflicts.

Following the warning, researchers conducted a large-scale survey of internet-connected surveillance cameras across Europe. The findings revealed that more than one million IP cameras remain publicly accessible online.

The United Kingdom had the highest number of exposed cameras, with 113,962 devices, followed by Italy (99,203), Spain (81,371), Turkey (81,148), France (68,317), Bulgaria (67,277), Germany (65,539), and Romania (64,789). More than 60,000 internet-accessible cameras were identified in Ukraine, while the Netherlands had over 45,000.

However, researchers emphasize that an internet-exposed camera is not necessarily easy to compromise. They identified nearly 2,000 hosts running cameras affected by unpatched vulnerabilities that have already been exploited in real-world cyberattacks.

On average, roughly one in every twelve exposed cameras in Europe is running on a device with a known security flaw. Researchers estimate that at least 87,000 cameras are potentially vulnerable, though the real number is likely much higher due to undisclosed zero-day vulnerabilities and the widespread use of weak or stolen passwords.

In addition, thousands of cameras are still running software with critical security flaws that were disclosed five to ten years ago. Researchers also note that many other weaknesses cannot be detected through external internet scans alone.

Security experts note that once an IP camera is discovered online, gaining access to it is often surprisingly easy. Many devices still rely on default passwords, outdated firmware, or factory security settings, making them attractive targets for attackers.

Dutch intelligence also highlighted the risks associated with Universal Plug and Play (UPnP). This feature can automatically expose cameras to the internet by creating port-forwarding rules without requiring additional authentication.

Users are advised to disable UPnP and avoid making IP cameras publicly accessible unless absolutely necessary. For remote access, experts recommend using a VPN and disabling unnecessary network protocols, including SSH, Bonjour, FTP, UPnP, and Telnet. Whenever possible, only secure protocols such as HTTPS and RTSPS should remain enabled.

Additional recommendations include using strong, unique passwords, enabling multi-factor authentication, isolating cameras on a separate VLAN, and installing security updates on a regular basis.

When purchasing surveillance equipment, users are encouraged to choose manufacturers that provide long-term security support for their products. The Dutch intelligence agencies also recommend considering a camera’s country of origin because of the cybersecurity risks associated with offensive cyber operations conducted by certain states.

Even if all recommended cybersecurity measures are in place, the agencies advise limiting each camera’s field of view as much as possible. Cameras should not capture logistics routes, critical infrastructure, other sensitive locations, or information that could aid a potential adversary, including GPS coordinates or other operational data.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.