A recent news article highlighted an all-too-familiar story: publicly exposed IP cameras have once again been successfully targeted to help enable nation states in their war efforts. The article references a cybersecurity advisory released by the Netherlands General Intelligence and Security Service (AIVD) and the Netherlands Defence Intelligence and Security Service (MIVD). It warns various EU, NATO member states, and Ukraine that Russian state actors are “systematically conducting digital espionage operations via IP cameras (cameras with internet access).”
In recent years, we have seen cameras hacked to enable one country to target another, and this new evidence indicates that Russia is using hacked cameras to track NATO troop and supply movements. While it isn’t surprising that nation states are finding and exploiting novel techniques to enable their combat effectiveness, it is concerning that IP camera exploitation continues to be so easy.
It’s also interesting and worrisome that the IP cameras that are often being targeted are not owned and operated by defense forces, but are a part of civilian infrastructure. While the intended surveillance targets of the hacked cameras are defense personnel, supply lines, and logistics infrastructure, the source of the data is from everyday cameras on buildings, street corners, and even homes. Unfortunately, many organizations have limited or no visibility into their IP cameras, or their security (or lack thereof). These devices offer not only the perfect tool to spy on your adversary, but also the perfect pivot point for full network exploitation.
The scale of the problem #
According to the article, Censys discovered “87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability” across the EU with over 4,000 of them in the Ukraine. The Censys researcher was careful to clarify that a camera being exposed to the internet, even if it has a CVE or if it’s on the KEV list, does not automatically mean it is hackable or being actively accessed by malicious cyber actors. While this is an important point, we know that CVEs are often not the entry points used by cyber threat actors. For example, default logins allow for easy to gain yet hard to detect access, providing a preferable method for entry.
One important fact not covered in the advisory is that the most prolific IP camera manufacturers, which are banned for use by any U.S. government entity because of their potential ties to the Chinese government, are consistently purchased by non-government entities within the United States and other Allied nations. And while statistics aren’t available for the number of U.S. commercial entities, let alone private citizens, who own and use these risky IP cameras, the number is undoubtedly high. Factor in that these cameras use or expose UPnP, an often and easily abused protocol, and you’ll discover that the U.S., and other countries, are target rich environments for cyber threat actors.
Close the lens: How runZero helps protect against IP camera abuse #
While we don’t expect the abuse of IP-enabled cameras to stop anytime soon, the good news is that the cybersecurity advisory offers some simple yet effective guidance on how to protect these devices:
- Identify and discover what is exposed to the internet, either directly or indirectly through something like a proxy, firewall, or vendor cloud relay.
- Disable the stream from the internet; disable port forwarding and UPnP. Configure camera access through a VPN.
- Disable or change default credentials and enable MFA where possible.
- This is likely harder for non government entities, but if possible, angle the cameras away from logistics routes, loading docks, and other sensitive areas.
- Patch firmware and software regularly, and purchase products with extended support lifecycles.
runZero can help address the security issues presented by IP-enabled cameras in a few ways:>
You need to know everything on your network, not just IP cameras. runZero can discover and identify everything on your network, including IP cameras and let you know whether they are public-facing or not.

runZero knows all about UPnP. We provide UPnP discovery network-wide, allowing you to close down any potential initial or lateral movement opportunities for adversaries.

Just because a camera is present doesn’t mean it's problematic. However, IoT devices are oftentimes unknowingly or unintentionally connected to networks they shouldn’t be. runZero can help to visualize and discover segmentation gaps, multi-homed devices, or simply misplaced devices.

If you aren’t certain that your attack surface, including your IP-enabled cameras, is properly protected, especially in the era of AI-enabled attacks, contact us today or sign up for a free trial.