Russian intelligence agencies have hacked thousands of internet-connected IP cameras across NATO member states and Ukraine to conduct surveillance on military logistics operations, researchers have discovered. The campaign allowed operatives to track the movement of military supplies, vehicles, and personnel in real time.
The attackers specifically targeted cameras positioned near military installations, logistics hubs, border crossings, and supply routes. By compromising the surveillance infrastructure, Russian operatives gained persistent visibility into equipment deployments and supply chain movements without the need for physical reconnaissance.
The compromised cameras included widely used models with known security weaknesses, including default credentials and unpatched firmware vulnerabilities. The attackers used the camera network as a distributed surveillance grid, feeding live footage back to intelligence processing centers.
The campaign underscores a growing threat to internet-of-things devices used in sensitive environments. Many IP cameras deployed at logistics facilities, border posts, and transport hubs lack basic security hardening, making them attractive intrusion points for state-sponsored intelligence gathering.
Security researchers recommend organizations evaluate physical security camera networks for unauthorized access, change default credentials, segment camera networks from other infrastructure, and apply firmware updates regularly to mitigate similar espionage operations.
