AIVD and MIVD Warn Russian Intelligence Hijacks IP Cameras Across NATO States and Ukraine to Track Military Logistics
A Dutch intelligence advisory raises the stakes on Russian camera-hijacking activity — critical-infrastructure defender teams review IP-camera posture this week.
Dutch intelligence puts a NATO-and-Ukraine frame on Russian camera surveillance — and the recommended fix is unglamorous exposure control.
THE HAGUE — The Netherlands' two intelligence services warned on July 10, 2026 that at least one Russian intelligence service is systematically compromising internet-connected security cameras across NATO states and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. The joint advisory, issued by the country's civilian General Intelligence and Security Service (AIVD) and its Military Intelligence and Security Service (MIVD), describes the operation as ongoing and frames it as a collection problem spanning the alliance, not a single country's incident.
The services stopped short of naming which Russian intelligence service is responsible, and they did not put a public figure on how many cameras have been accessed. What they did set out, according to reporting by The Hacker News on the joint AIVD and MIVD advisory, is a picture in which the exposed surface is broad, the entry is often trivial, and a camera's value is set by where it happens to point.
What the AIVD and MIVD Advisory Documented
The core finding is narrow and stated plainly: at least one Russian intelligence service is systematically compromising internet-connected cameras across NATO states and Ukraine, and turning the feeds toward military logistics. The AIVD and MIVD report that the access is used to watch transport routes, track weapons shipments bound for Kyiv, and observe where Ukrainian troops are located. Across EU and NATO states, the services add, the same access has also collected military intelligence with no direct connection to the war.
In Ukraine, the advisory says, the surveillance has not stayed passive: camera access there has reportedly been used in attempts to locate and neutralise Ukrainian military personnel and destroy their equipment, turning an exposed roadside or business camera into a targeting aid. The services were careful, however, to bound what they have confirmed at home. In a separate statement they said they had caught only a small number of cameras actually breached, sitting on military logistics routes inside the Netherlands, and that the operators had since been warned.
The advisory frames the entry as unremarkable rather than sophisticated: exposed devices reachable from the public internet, default credentials that were never changed, and obsolete firmware. On the reporting available, none of the access described required a zero-day — the barrier to this collection is low, and so is the cost of raising it.
The NATO-Scope and Ukraine-Logistics Targeting in Defender-Team Terms
For a defender, the most important distinction in the coverage is between a camera being reachable and a camera being compromised. Internet-scanning firm Censys, in its own analysis of the exposed surface, counted more than 87,000 internet-connected cameras across the EU, NATO members and Ukraine running a service whose version matches a known-exploited vulnerability — a total it explicitly calls a lower bound, and more than 4,000 of which sit in Ukraine. In the Netherlands alone it found 45,386 cameras reachable from the public internet, and narrowed the count with a known-exploited vulnerability in the camera software itself to 541.
Those are exposure figures, not intrusion figures, and Censys is clear that being reachable from the internet is not the same as being hacked. The number that should anchor a defender's read is the far smaller set the Dutch services confirmed — a handful of real intrusions on cameras positioned over logistics routes. Treating the surface count as a casualty count overstates the picture.
Continuation Context: A Widening Line of Allied Attributions
The advisory does not arrive in isolation. It extends a run of on-the-record allied attributions of Russian state activity against the systems behind essential services, sitting alongside the UK National Cyber Security Centre's statement that hostile-state activity is behind roughly three-quarters of attacks on UK critical infrastructure, the US, UK and allied advisory on Russian targeting of routers and edge devices in critical infrastructure, and the EU, UK and Poland attribution of power-grid intrusion activity — each an example of governments quantifying or naming state-linked pressure in public.
What the camera advisory adds is a new surface — the physical-world sensor — extending a posture of public attribution that also includes Germany's attribution of Signal phishing against lawmakers to Russia. Crucially, the Dutch services did not tie the camera activity to any named cluster, and nothing in the advisory establishes an overlap with previously tracked Russian operations; a reader should not infer one from the surrounding attributions.
Defender Posture for Organizations Operating IP Camera Fleets
The guidance the Dutch services and Censys converge on is deliberately dull, and that is its strength. The first move is discovery: find which cameras are reachable from the public internet — through a forgotten port-forward, a UPnP mapping, or a vendor cloud relay — and prioritise the ones overlooking transport routes, ports, loading docks and other sensitive sites. Check their access logs for connections you do not recognise.
From there the fixes are familiar operational hygiene. Keep the video stream off the public internet by turning off port forwarding and UPnP and reaching cameras through a VPN. Replace default credentials and enable multi-factor authentication where the device supports it; where it does not, keep the camera off the public internet entirely. Aim the lens deliberately, keeping sensitive areas out of frame or masked. And treat firmware the way you treat any other reachable system — apply disciplined patch management, and buy cameras that ship with years of security support rather than months.
The lesson underneath the checklist is that a compromised camera hands an adversary a live read on physical operations with no deeper network breach required. The remedy is therefore to take the camera off the public internet and control what it can see, and organisations in defence-adjacent or critical-infrastructure roles should fold camera fleets into their incident-response and recovery planning, not leave them in a facilities-management blind spot.
Open Questions
Several load-bearing details remain unstated. The advisory attributes the activity to at least one Russian intelligence service but does not name which one, and defenders should resist filling that gap — the public record does not support asserting the GRU, SVR, FSB or any other body. The services also did not publish a total for how many cameras have been accessed, which is why the 87,000 exposure figure and the small confirmed-intrusion set must be kept distinct.
It is likewise unconfirmed which NATO-member camera vendors or fleets are affected beyond the Dutch cases disclosed, and whether the campaign overlaps with Turla, Sandworm or any other tracked cluster; the advisory does not assert such an overlap. What is firmly established is enough to act on: two allied intelligence services have, on the record, described ongoing Russian compromise of internet-exposed cameras across NATO states and Ukraine, tied it to military-logistics collection and, in Ukraine, to targeting, and pointed operators at exposure control as the fix.
The CyberSignal Analysis
The reported facts above are the AIVD and MIVD's, with exposure figures from Censys; what follows is The CyberSignal's editorial reading for defenders. None of it asserts which Russian service is responsible, or that any specific camera is among those accessed.
Signal 01 — Exposed Surface Is Not a Body Count
The 87,000 figure is the number most likely to be quoted and the one most likely to be misread. It measures how large the scannable field is — cameras reachable from the internet whose service version matches a known-exploited flaw — not how many devices an adversary has taken; the Dutch services' own confirmed set is far smaller and geographically bounded.
The practical consequence is to treat the surface number as a prompt to inventory and reduce exposure, not as evidence a given fleet is already compromised.
Signal 02 — The Value Is in Where the Lens Points
What makes this activity portable, and cheap, is that neither half of it is exotic: the way in is often just an unchanged default login, and the payoff is set entirely by what the camera overlooks. A device pointed at a loading dock or transport corridor is an intelligence asset in a way an identical camera on an empty car park is not.
So camera security is a siting and exposure problem as much as a software one — and the fixes that matter most, taking the feed off the public internet and controlling what the lens can see, reduce the value of a compromise even on a device that cannot be fully hardened.
Signal 03 — Watch the Advisory Cadence, Not the Attribution Label
This advisory reads as one entry in an accelerating pattern of allied governments publicly naming Russian state pressure on infrastructure. More advisories on exposed edge and sensor hardware are likely to follow, and their durable content will be the defensive prescription rather than the attribution label.
The discipline worth keeping is restraint on the parts the advisory left open: it does not name a specific Russian service, quantify the total cameras accessed, or claim overlap with a tracked cluster. The takeaway is the direction and the fix — reduce exposed camera surface now.