Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine

Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial image, 16:9, full-frame edge to edge
Share

Key points

  • Dutch civilian and military intelligence services published a joint advisory on 10 July warning that Russian spies are hijacking internet-connected security cameras.
  • The hackers are watching military transport routes, weapons shipments heading to Ukraine, and the locations of Ukrainian troops.
  • The campaign spans multiple European countries and Ukraine itself, targeting ordinary CCTV cameras exposed to the internet.
  • Dutch agencies AIVD and MIVD attribute the activity to at least one Russian intelligence service.
  • Owners of internet-connected cameras near ports, rail hubs, borders or military sites are the most exposed.

Russian spies are not just breaking into email accounts anymore. They are watching the roads.

That is the blunt takeaway from a joint advisory published on 10 July by the AIVD, the Netherlands' civilian intelligence agency, and the MIVD, its military counterpart. The two services say at least one Russian intelligence unit is systematically hijacking internet-connected security cameras across Europe and inside Ukraine, and using the live feeds to spy on the war effort.

The reporting was surfaced by The Hacker News.

What are the Russians actually looking at?

They are looking at trucks, trains and troops. According to the Dutch agencies, the hijacked cameras are being used to track military transport routes, shipments of weapons and aid bound for Kyiv, and the movements and locations of Ukrainian forces.

Think of the kind of camera bolted to the outside of a petrol station, a small port office, a rail siding or a warehouse near a border crossing. Many of these devices are plugged straight into the internet so the owner can check them from a phone. That same internet connection is what the attackers are abusing.

Once inside, the spies do not need to plant a bomb or send an agent. They just watch. A convoy of military lorries rolling past a filling station in eastern Poland at 3am tells Moscow a great deal.

How are they getting into the cameras?

The advisory points at the boring, familiar weaknesses that plague small internet-connected devices.

Many CCTV cameras ship with a default username and password printed in the manual. Owners rarely change them. Others run old firmware, meaning the software inside the camera has known bugs the manufacturer has since patched, but the fix was never installed. Some are simply exposed to the open internet with no firewall in front of them.

This is not a clever zero-day, meaning a brand-new flaw nobody knew about. It is opportunism at industrial scale. The hackers scan the internet, find cameras that answer, try common passwords, and log in.

Would multi-factor authentication have helped? Honestly, on most of these cheap cameras, MFA (a second login step such as a code from your phone) is not even offered. That is part of the problem.

Should ordinary people be worried?

If you have a home doorbell camera pointing at your front garden in Rotterdam, you are not the target. Relax.

The risk sits with businesses and public sites that happen to overlook something militarily interesting: ports, rail yards, motorways near bases, border posts, logistics depots. If that is you, or your employer, the advisory is a nudge to check what your cameras can see and who else can see them.

A few practical steps close most of the door. Change the default password on every camera. Put the cameras behind a firewall or a VPN, which is a private tunnel that hides the device from the open internet, rather than exposing them directly. Update the firmware. Turn off remote access you do not use.

Why this matters beyond Ukraine

Camera hijacking is cheap, quiet and hard to notice. There is no ransom note. The lights stay green. The owner has no reason to suspect anything until an intelligence service tells them.

Expect this playbook to spread. Any conflict, any sanctions-busting shipment, any sensitive site with a webcam pointed at it, is now fair game.

© 2026 Threat Vectr