What Happened
Dutch intelligence agencies AIVD and MIVD jointly disclosed on July 19, 2026 that at least one Russian intelligence service has systematically compromised internet-connected IP cameras across NATO member states, European Union countries, and Ukraine. The operation targets surveillance cameras positioned near military installations, logistics hubs, weapons storage facilities, railway yards, and border crossings to monitor the movement of weapons supplied to Ukraine and the positioning of military units.
The attack methodology is straightforward and opportunistic. Threat actors scan for cameras with default credentials, known firmware vulnerabilities, or direct internet exposure — skipping hardened targets in favour of the vast pool of poorly secured devices. Hikvision and Dahua cameras account for the majority of compromised devices identified in the advisory, though the technique works against any exposed camera with weak authentication. Censys internet exposure data suggests approximately 87,000 devices in Europe alone match the risk profile. Once access is established, attackers feed harvested video into automated image-recognition software to classify vehicles, count units, and track shipment patterns without requiring continuous human monitoring. Dutch officials noted that video harvested from Ukrainian cameras has in some instances been used to locate military personnel for subsequent kinetic strikes. Source: The Hacker News
Why This Matters for Canadian Organizations
Canada’s exposure to this threat is direct and multifaceted. As a NATO member, Canada hosts NATO-affiliated facilities, logistics chains, and military infrastructure. As a Five Eyes partner and active contributor to Ukraine support operations, Canadian facilities involved in coordinating or staging military aid are plausible targets for the same intelligence collection operation the Dutch advisory describes. The Canadian Forces, National Defence, and Public Safety Canada operate or oversee facilities where camera security is a national security question, not an IT housekeeping matter.
Beyond government and military targets, the threat has a broader commercial and privacy dimension. Canadian ports, airports, rail yards, and industrial facilities near sensitive infrastructure operate large camera estates, often sourced from the same Hikvision and Dahua product lines flagged in the advisory. The Canadian Centre for Cyber Security has previously issued advisories recommending against deploying network-connected devices from vendors with links to foreign state intelligence services — guidance that applies directly to Hikvision and Dahua equipment given their connections to the Chinese state. The intersection of Russian operational interest and Chinese-manufactured surveillance equipment creates a compounding risk for Canadian organizations.
Under PIPEDA, cameras that capture identifiable individuals in non-public or semi-public spaces carry personal information obligations. If attackers access camera feeds that include employee faces, vehicle licence plates, or entry/exit patterns of individuals, organizations face potential breach notification obligations on top of the operational security implications.
What to Do
Start with an audit. Identify every internet-connected camera your organization operates: how many, what brands, what firmware versions, and whether they are exposed directly to the internet or protected behind a firewall. Any Hikvision or Dahua device running firmware older than the most recent security update is a priority for immediate patching. Devices with default or unchanged factory credentials — still the most common attack vector — must have credentials rotated before end of week.
Remove direct internet exposure wherever operationally possible. Cameras do not need to be reachable from the public internet in most use cases. Place them behind a firewall, restrict access through a VPN or zero-trust gateway, and segment camera networks from IT and OT environments so that a compromised camera cannot become a pivot point into broader infrastructure. For organizations near sensitive logistics, military, or critical infrastructure sites, treat this advisory as a trigger for an immediate physical security audit of camera placement relative to sensitive activities. Review the CCCS guidance on IoT device security and assess whether your camera procurement and deployment practices align with current recommendations.






