Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Russian Hackers Are Compromising Doorbell and IoT Cameras Near NATO Bases — What It Means for Your Company's Security

TL;DR

The Dutch Military Intelligence and Security Service (MIVD) confirmed in July 2026 that Kremlin-linked hackers exploited unsecured internet-connected cameras — including civilian doorbell cameras — to monitor weapons transports headed to Ukraine. This is the latest chapter in a broader espionage campaign in which Russia's GRU Unit 26165 (known as Fancy Bear or APT28) has compromised roughly 10,000 cameras across NATO countries since 2022, mostly in Ukraine, Romania, Poland, Hungary, and Slovakia. The story is a stark reminder of what happens when IoT devices go unmonitored — exactly the exposure risk that chors.net is built to detect.

What the Dutch intelligence service revealed

MIVD reported that hackers acting in Russia's interest gained access to internet-connected cameras positioned along military transport routes in NATO member states in order to track exactly what equipment and weapons were moving toward Ukraine. The operation specifically targeted unsecured, internet-facing devices located near military installations and logistics corridors. This marks the first time doorbell cameras have been explicitly named as compromised devices in such an operation.

Scale and history of the campaign — evidence of a systemic problem, not an isolated incident

The MIVD disclosure is not a standalone event but part of a longer pattern first documented in May 2025 in a joint advisory issued by more than 20 international agencies, led by the UK's National Cyber Security Centre (NCSC). The table below shows how the campaign has evolved over time.

Year / EventScale and details
2023NSA reveals Russian hackers monitored cameras in Ukrainian coffee shops to track aid convoys and trains
May 2025Joint advisory from 20+ agencies: GRU Unit 26165 (Fancy Bear/APT28) compromised ~10,000 cameras since 2022, 80 percent in Ukraine, rest in Romania, Poland, Hungary, Slovakia
October 2025Microsoft reports a 25 percent year-over-year increase in Russian cyberattacks against NATO states
April 2026MIVD's annual report warns Russia is taking "concrete preparatory steps" for a possible conflict with NATO
July 2026MIVD names civilian doorbell cameras as compromised devices for the first time

Why this matters for every company, not just the military

The key business takeaway is simple: if state-level actors with GRU-grade resources could monitor thousands of cameras across NATO countries for years without detection, the scale of unseen exposure in the private sector — warehouses, manufacturing plants, logistics firms — is likely far greater. IoT cameras, sensors, building management panels, and access control systems are often deployed without basic security audits, yet remain publicly visible in scanners such as Shodan or Censys.

The NCSC recommends enhanced monitoring, multi-factor authentication, and prompt security updates in response to such threats — precisely the areas covered by comprehensive exposure monitoring and vulnerability assessment services such as those offered by chors.net.

How chors.net addresses this risk

Chors.net is an advanced digital exposure monitoring and vulnerability assessment system for B2B companies, checking how a business looks from the outside and identifying security gaps before anyone else does. The service is delivered through two engagement models:

  • Exposure Screening — a one-time analysis of externally visible infrastructure, identifying open services, misconfigurations, outdated software, and publicly exposed data, delivered as a report with prioritized remediation actions.
  • Continuous Monitoring — ongoing tracking of digital exposure over time, with regular infrastructure scans, detection of new vulnerabilities and changes to the attack surface, and recurring reports and alerts.

A four-stage process — screening, analysis, reporting, recommendations — with risks classified by business impact.

Frequently asked questions

Could my company be targeted by a similar attack even if I have no military or NATO connection?

Yes — the GRU campaign targeted civilian devices, including private doorbells, selected by location rather than the owner's industry, meaning any company with a publicly visible camera or IoT sensor is theoretically within reach of a similar technique.

How can I check whether my IoT devices are publicly visible?

Chors.net's Exposure Screening analyzes a company's externally visible infrastructure without interfering with its systems and identifies open services and misconfigurations before an attacker can exploit them.

How long did the Russian hacking campaign run before it was detected?

According to the joint agency advisory from May 2025, camera compromises had been ongoing since 2022 — at least three years — before being fully disclosed publicly.

Sources

  1. Dutch Military Intelligence and Security Service (MIVD). Public statement on Russian GRU Unit 26165 activity targeting IoT cameras near military transport routes. Published July 2026. https://english.mivd.nl/
  2. UK National Cyber Security Centre (NCSC). Russian GRU Unit 26165 continues to target Western logistics and aid corridors through IoT surveillance. Joint advisory with 20+ agencies, May 2025. https://www.ncsc.gov.uk/news/joint-advisory-gru-unit-26165
  3. US National Security Agency (NSA). Russian Cyber Actors Targeting Smart Cameras and IoT Devices. Cybersecurity Advisory, 2023. https://www.nsa.gov/Press-Room/Cybersecurity-Advisories/
  4. Microsoft Threat Intelligence. Russian threat activity targeting NATO: year-over-year trends. Microsoft Digital Defense Report, October 2025. https://www.microsoft.com/security/business/security-insider/
  5. MIVD Annual Report 2026. Russia: state actor cyber preparedness against NATO. April 2026. https://english.mivd.nl/publications
  6. Shodan.io — public search engine for internet-connected devices; routinely exposes misconfigured cameras and access control systems. https://www.shodan.io/
  7. Censys — internet-wide scanning platform used by security researchers to fingerprint exposed services. https://about.censys.io/

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.