Russian intelligence services are hacking European IP cameras to collect military information, according to Dutch security agencies.

The attackers use compromised cameras to monitor transport routes, military cargo, weapons deliveries, and the possible locations of military personnel. Researchers have identified at least 87,000 vulnerable devices across Europe.

Many affected cameras use old firmware, default passwords, or unsafe network settings. Therefore, attackers may gain access without using sophisticated hacking techniques.

Russian Spies Use Cameras for Military Intelligence

Russian state-backed groups are systematically compromising internet-connected cameras across Europe.

Once inside, the attackers can view live footage and collect images from sensitive locations. They then use automated image-recognition tools to search the material for useful military information.

The surveillance can reveal cargo movements and transport routes. In addition, it may expose equipment shipments or activity near military facilities.

Russian intelligence is reportedly collecting information from EU and NATO countries. Some of that intelligence may not have a direct connection to the war in Ukraine.

However, hacked cameras in Ukraine have already supported attempts to locate military personnel and destroy equipment.

Authorities have not observed similar attacks outside Ukraine. Nevertheless, they warn that Russian military units could use the same methods during a future conflict.

More Than One Million Cameras Exposed

Researchers found over one million European IP cameras directly accessible from the internet.

The United Kingdom had the highest number, with 113,962 exposed devices. Italy followed with 99,203, while Spain had 81,371.

Turkey recorded 81,148 exposed cameras. Meanwhile, France had 68,317, Bulgaria had 67,277, and Germany had 65,539. Romania also had 64,789.

More than 60,000 cameras were visible in Ukraine. In addition, researchers found over 45,000 exposed devices in the Netherlands.

A publicly accessible camera is not automatically vulnerable. However, internet exposure gives attackers an opportunity to search for weak passwords, outdated software, and unsafe services.

At Least 87,000 Cameras Are Vulnerable

Around one in every 12 exposed European IP cameras operates on a device with a known security flaw.

Researchers estimate that at least 87,000 cameras are vulnerable to existing attack methods. However, they consider this figure a minimum.

Some devices may contain vulnerabilities that scanning tools cannot detect. Others could have weak or stolen passwords despite running updated software.

Almost 2,000 exposed camera hosts contain unpatched flaws that attackers have already exploited in real attacks.

Moreover, thousands of devices still run services with critical vulnerabilities discovered five to ten years ago. Manufacturers may no longer provide security updates for some of these products.

Default Settings Leave Devices Open

Many IP cameras reach the public internet through Universal Plug and Play, or UPnP.

This protocol allows a device to ask a router to open a network port automatically. It usually requires no authentication. As a result, a camera can expose itself online without the owner realizing it.

Factory settings create another major risk. Some cameras still use default usernames and passwords that attackers can easily find online.

Obsolete firmware and unnecessary network services also increase the attack surface. For example, devices may expose Telnet, FTP, SSH, or other protocols even when the owner does not need them.

Once attackers identify an exposed camera, they can test these weaknesses remotely.

How to Protect European IP Cameras

Authorities recommend removing cameras from the public internet unless direct access is essential.

Users should disable UPnP on both the camera and the router. They should also turn off unused services, including Telnet, FTP, Bonjour, and SSH.

For remote access, owners should connect through a virtual private network. This approach keeps the camera behind the local network instead of opening it directly to the internet.

Furthermore, every device should have a strong and unique password. Multi-factor authentication should also be enabled whenever the manufacturer supports it.

Organizations can place cameras on a separate virtual local area network. This step prevents attackers from using one compromised device to reach other systems.

Secure protocols such as HTTPS and RTSPS should replace unencrypted alternatives. In addition, users should install firmware updates as soon as they become available.

Camera Placement Can Reduce the Damage

Technical protection cannot remove every risk. Therefore, authorities also recommend limiting what each camera can see.

Cameras should only capture the area required for their purpose. Their field of view should exclude transport routes, public infrastructure, sensitive facilities, and unrelated activity.

Owners can also mask private areas within the video feed. Meanwhile, location details such as GPS coordinates should not appear in camera streams or metadata.

Finally, buyers should choose manufacturers that promise several years of security support. Unknown brands and unsupported products may leave serious vulnerabilities unfixed.

The campaign against European IP cameras shows how ordinary connected devices can become intelligence tools. Even a camera installed for basic security may expose valuable information if owners leave it unprotected.


0 responses to “European IP Cameras Targeted by Russian Spies”