Russian hackers turned ordinary security cameras into spies on NATO supply routes
Dutch intelligence says Russia-linked hackers hijacked internet-connected cameras to watch military shipments bound for Ukraine, part of a wider European campaign.
Commentary & Analysis ·

Verified key facts
- Dutch agencies AIVD and MIVD found Russian state hackers compromised internet-connected cameras, including some along military transport routes in the Netherlands, NL Times reported.
- The Record reported that NATO logistics and Ukrainian troop movements are the top surveillance subjects of the camera-hacking campaign.
- Attackers exploit default passwords, outdated firmware and exposed configurations, then run image-recognition software on the stolen video feeds.
- The Defense Post reported on 14 July that the tactic is used systematically across other NATO and EU countries, not just the Netherlands.
- In Ukraine, hacked cameras have reportedly helped locate soldiers, supporting strikes on personnel and equipment.
The cheap security camera bolted above a loading dock may be working for someone else. Dutch intelligence services say Russian state-backed hackers have quietly compromised internet-connected cameras across the Netherlands and beyond. Their goal, investigators found, is watching NATO military logistics, including weapons and equipment moving toward Ukraine. NL Times reported the findings come from a joint investigation by the AIVD and MIVD, the country's civilian and military intelligence agencies.
What the Dutch agencies found
The joint advisory describes a patient, industrial-scale operation. The Record reported that Russian intelligence-linked actors have been compromising cameras across Europe, with NATO logistics and Ukrainian forces as their top collection priorities. In the Netherlands, a small number of hacked devices sat directly along military transport routes.
That placement is no accident. The agencies said the Netherlands is a prime espionage target because it serves as a transit country for allied equipment and is a vocal supporter of Ukraine. Ports, rail corridors and motorways funnel materiel through Dutch territory before it heads east.
How the camera hijacking works
The intrusion method is simple and depressingly familiar. The Defense Post reported the hackers scan the internet for exposed devices, identify camera models from manufacturer data, and then walk in through weak security. Default passwords, outdated firmware and factory-default configurations do most of the work for them.
The clever part comes after access. According to The Record, the attackers feed hijacked video streams into image-recognition software. The tooling automatically flags military vehicles and attempts to classify their cargo. A human analyst never needs to watch thousands of hours of footage. The cameras become unpaid, unwitting sensors in a distributed surveillance network.
- Internet scans locate exposed cameras by manufacturer fingerprints
- Default credentials and stale firmware provide easy access
- Image-recognition software automatically spots military vehicles and cargo
A tactic with lethal precedent in Ukraine
This is not passive snooping. The Defense Post reported the same tactic has been used inside Ukraine to locate military personnel. In some cases, intelligence from hacked cameras supported attempts to kill soldiers and destroy equipment. Ukrainian authorities have repeatedly urged citizens to disconnect or secure webcams for exactly this reason.
The Dutch disclosure confirms the method has migrated westward into NATO territory. The agencies stressed the campaign is systematic across other NATO and EU countries, NL Times reported. What functions as targeting support in an active war zone serves as logistics reconnaissance in peacetime Europe.
Part of a wider Russian cyber offensive
The camera campaign lands amid a broader European reckoning with Russian cyber operations. Just days earlier, the EU and United Kingdom announced their first coordinated cyber sanctions package. The measures publicly blamed the FSB's Centre 16 and the Turla group for a decade of intrusions against European governments and infrastructure.
Seen together, the disclosures sketch a layered strategy. Elite units burrow into government networks while cheaper operations harvest whatever the internet of things leaves unlocked. Both feed the same intelligence machine tracking Western support for Ukraine.
What camera owners should do now
The defensive advice is unglamorous but effective. Dutch authorities urged camera owners to change default passwords, install firmware updates and disable unnecessary remote access. Devices that must face the internet should sit behind a VPN or authenticated gateway. Organizations near ports, rail lines and military facilities have particular reason to audit their equipment.
Businesses should also ask a simpler question: does the camera need internet exposure at all? Many compromised devices were reachable from anywhere on Earth for pure convenience. Local-only recording eliminates the entire attack surface.
The bigger IoT security lesson
Security researchers have warned about abandoned, unpatched cameras for a decade. The Dutch advisory turns that abstract risk into concrete geopolitics. A consumer gadget with a forgotten password is now a collection asset in a great-power conflict. Regulators in the EU are already tightening device-security rules, and this campaign will strengthen the case for enforcement with real teeth.
Sources
- The Record - NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says (July 2026)
- NL Times - Dutch spy agencies: Russia hacked cameras to spy on military routes (July 11, 2026)
- The Defense Post - Russia Uses Hacked Dutch Security Cameras to Monitor Military Aid for Ukraine (July 14, 2026)
- Ukrainska Pravda - Russian hackers breached cameras on NATO logistics routes to track weapons shipments (July 11, 2026)
You may also like to read

ASML beats forecasts and lifts 2026 outlook as AI keeps chip equipment orders rolling
The Dutch lithography giant posted €9.3bn in sales and €2.9bn profit, raised full-year guidance sharply and will expand EUV capacity 30% to feed the AI boom.

China's fourth-ranked leader visits Pyongyang as Beijing works to pull North Korea closer
Wang Huning's talks with Workers' Party official Jo Yong Won follow Xi Jinping's June visit, as Beijing counters Pyongyang's deepening alignment with Russia.

Apple Intelligence cleared for China launch as regulator approves Alibaba-powered AI
China's cyberspace regulator has registered Apple's generative AI service, ending a 22-month wait and clearing iPhone AI features built on Alibaba's Qwen models.

Airtel Leads Nifty as Jio IPO Nears: Telecom's Duopoly Test
Bharti Airtel led Nifty gainers on 14 July as Jio's Rs 30,000-52,000 crore IPO heads for an August-October window. Analysts see a listed duopoly reshaping telecom.