Dutch intelligence warns that at least one Russian agency is systematically compromising network cameras across Europe to gather military intelligence.
Summary
- Dutch intelligence officials have identified a Russian campaign targeting internet-connected cameras to conduct surveillance on military logistics and Ukrainian personnel in Europe.
- The operation focuses on cameras positioned near facilities relevant to NATO supply chains and the movement of Ukrainian troops.
- At least one Russian intelligence agency is attributed to the activity, according to the advisory.
- The campaign highlights how commercially available network cameras represent a persistent and underappreciated intelligence-gathering vector.
- Organisations with cameras near sensitive locations — including logistics hubs, transport corridors, and military-adjacent facilities — face elevated exposure.
What Dutch Intelligence Has Reported
Dutch intelligence officials have issued an advisory describing a Russian operation to compromise internet-connected cameras at locations across Europe. The primary intelligence targets are NATO military logistics operations and the movements of Ukrainian troops and personnel. At least one Russian agency is involved, according to the advisory, though the sources do not specify which service or services are responsible.
Why Cameras Are an Attractive Collection Tool
Network cameras — including those used for building security, traffic monitoring, and facility management — are widely deployed, often under-patched, and frequently exposed to the internet without strong authentication controls. For an intelligence service seeking persistent, low-risk observation of a physical environment, a compromised camera at a logistics depot or transit point offers significant value at relatively low operational cost. Unlike human intelligence or satellite imagery, hacked cameras can provide real-time, continuous feeds without placing an asset at risk.
The Targeting Logic
The focus on NATO logistics is consistent with Russia’s documented interest in disrupting or pre-empting Western military support to Ukraine. By observing the movement of materiel and personnel, an adversary can build pattern-of-life intelligence, identify shipment schedules, and potentially anticipate or influence operational decisions. The targeting of Ukrainian troops and personnel suggests the campaign extends beyond supply chain monitoring to include surveillance of individuals — raising concerns about personal safety as well as operational security.
What Remains Unknown
The advisory, as reported by The Record, does not specify the precise methods used to compromise the cameras, the number of devices affected, the countries in which they are located, or the full range of Russian agencies involved. It is also unclear from available sources how long this campaign has been active or whether any of the collected intelligence has been operationally exploited.
Broader Implications for Enterprise Security
While the immediate focus is on military and defence logistics, the tradecraft described is not exclusive to government targets. Any organisation whose camera infrastructure overlooks areas of strategic interest — ports, freight hubs, border crossings, defence industry facilities, or even the car parks of sensitive buildings — could be unwittingly providing an adversary with useful observation. The advisory is a reminder that physical security technology sits firmly within the cyber risk landscape and demands the same rigour applied to enterprise IT systems.
Camera Security as a Governance Issue
For many organisations, network cameras are procured and managed outside the IT security function — handled instead by facilities teams or physical security vendors. This creates a governance gap in which devices with internet exposure may never receive firmware updates, may retain default credentials, or may sit outside vulnerability management programmes entirely. CISOs operating in sectors adjacent to defence, critical infrastructure, or national logistics should treat this advisory as a prompt to review how network cameras are inventoried, managed, and monitored.
Why it matters
This campaign demonstrates that internet-connected physical security devices are active intelligence collection tools in the hands of nation-state actors. For CISOs in defence-adjacent industries, logistics, critical infrastructure, or any sector with proximity to military activity, the risk is direct: compromised cameras can expose operational patterns, personnel movements, and facility layouts to a sophisticated adversary. Even organisations not directly targeted should recognise that the same techniques and tooling can be redirected. Network cameras must be brought under standard asset management, patching, and access control disciplines — the advisory makes clear that treating them as out-of-scope IT devices is no longer a defensible position.
What to do now
- Audit your organisation’s internet-connected camera inventory, including devices managed by facilities or physical security teams outside the core IT function.
- Confirm that all network cameras are included in your vulnerability management programme and are receiving firmware updates on a regular schedule.
- Eliminate default credentials on all camera systems and enforce strong, unique authentication for administrative access.
- Review which cameras have direct internet exposure and assess whether that exposure is operationally necessary; restrict access where it is not.
- If your organisation operates near logistics corridors, military facilities, or defence supply chain infrastructure, consider this advisory a prompt to elevate the priority of camera security reviews.
- Engage physical security vendors to understand their patch and support commitments for deployed camera hardware.
