AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes
AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.
The joint advisory that Dutch civilian intelligence (AIVD) and military intelligence (MIVD) published July 10 documents an ongoing Russian intelligence operation that treats internet-exposed IP cameras as a persistent, low-cost sensor network aimed at NATO military logistics. According to the advisory — and secondary reporting by The Hacker News on July 20 — an unspecified Russian intelligence service, which the advisory does not name at the unit level and does not tie by name to Fancy Bear / APT28, is systematically identifying vulnerable public-facing cameras through internet scans and pulling their feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. The Dutch Ministry of Defence’s own statement confirms the Netherlands is among the countries targeted.
The scale is on the physical-layer side, not the exploit side. AIVD and MIVD count more than 87,000 cameras across EU and NATO states and Ukraine that carry publicly-known vulnerabilities of the kind this operation is using. In the Netherlands alone, they identify 45,386 internet-reachable cameras, of which 1,992 run demonstrably vulnerable services. Inside Ukraine the reported count is above 4,000. The two CVEs the advisory calls out by number — CVE-2016-7407, an unauthenticated remote-code-execution flaw in Dropbear SSH at CVSS 9.8, and CVE-2021-39275, a heap buffer overflow in Apache HTTP Server 2.4.48 and earlier also at CVSS 9.8 — are not new. They are old, patched upstream, and still sitting in production in a category of device where nobody has meaningfully touched the firmware since it left the factory.
The access story is what you would expect if you spend any time on the physical layer under a camera deployment. Default credentials that were never changed. Vendor firmware that stopped receiving security updates years ago and still ships in racks quietly installed above loading docks and gate cameras. Port-forwarding rules from a home router that got reused when the branch office opened. UPnP still on. Feeds broadcast to the public internet because whoever put the box in wanted to check on it from a phone. The advisory does not name specific camera brands — a deliberate omission — and the mitigations it lists are correspondingly generic to the class rather than to any one vendor: pull the video off the public internet, disable port forwarding and UPnP on the router in front of it, front the feed with a VPN, replace factory credentials, enable MFA where the firmware supports it, mask viewpoints that expose sensitive locations, and patch the firmware or pick a camera line that will actually keep receiving updates.
Why the physical layer is where this lives
An IP camera looking down on a rail yard, a port apron, or the gate of an ammunition depot is not classified infrastructure. It is a low-cost box that a facilities contractor installed years ago on a copper run somebody laid the year before that, connected through a consumer-grade router to a residential ISP link, running vendor firmware that stopped shipping updates around the same time. Nobody has audited that box since. Nobody has a list of every one of them. In every country the advisory covers, the population count is measured in the tens of thousands. When Russia’s target set is Ukrainian troop movements, weapons shipments to Kyiv, and NATO transport routes, that population is already deployed, already exposed, and already broadcasting exactly the picture the operator wants.
The advisory notes that inside Ukraine some of these camera views have been “used in attempts to neutralise Ukrainian military personnel” — the operational side of the loop, not the collection side. That phrasing is the two services’ own, and it is worth reading in the context of the FSB Centre 16 router-hygiene advisory from July 13 and the CERT-UA report on Sandworm’s ClickFix campaign from a week ago. Different services, different toolchains, but the same underlying observation: the Russian side is not spending exploit budget where legacy hygiene gives them the access for free, and the legacy population is enormous.
CVE-2016-7407 was disclosed nine years ago. CVE-2021-39275 was disclosed nearly five years ago. Firmware in this class of device is a legacy artifact from the moment it ships — a fact operators of the network segment the camera sits on end up owning, whether or not they chose the box or knew it was on the wire.
One specific thing to do this week
If your organization has any presence near military transport routes, defense-industrial supply lines, or NATO-adjacent logistics — or if you are simply responsible for the network segment a set of IP cameras sits on — do the enumeration this week. Pull a list of every camera-class device your ranges expose to the internet, confirm which are on factory credentials or unsupported firmware, and pull the feeds behind a VPN or off the public internet entirely. Do not treat the two CVEs the AIVD/MIVD advisory names as the enumeration list. They are illustrative of the class. The class is the enumeration list.
Found this useful? Share it.


