Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-02 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Hijacked IP cameras became BDA tools — plant-floor CCTV is in the same class

Nozomi, 2 April 2026 — traffic cameras and building CCTV used for pattern-of-life, targeting, and bomb-damage assessment in the Israel–Iran fight. Default-cred cameras on an OT VLAN are not "physical security only."

RWP Ventures · 2026-09-07 · event 2026-02-28 · 2 min read · priority 7.3

Bottom line up front

CONFIRMED Nozomi, 2 April 2026 — IP cameras with default creds and unpatched stacks are being used as ISR, not just botnet nodes. Nozomi cites FT: Israeli access to Tehran traffic cameras feeding pattern-of-life before the 28 February 2026 strike that killed Iranian leadership (that kill-chain detail is REPORTED via FT/Nozomi, not independently verified by RWP). June 2025 12-Day War: Iran used cameras around Weizmann Institute for pre-strike and BDA. Spikes against cameras in Israel, Qatar, Bahrain, Kuwait, UAE, Cyprus, Lebanon around 1 March. July 2026 Dutch AIVD/MIVD APT28 camera-on-supply-routes is the European sequel — separate post if seeded, cited here as corroboration of the class. Process impact on industrial control: UNKNOWN. Camera-as-pivot on a plant VLAN: ASSESSED as the defender takeaway. Pair with January Hanwha Wisenet mediums already in this archive.

Historical backfill of 2 April 2026 reporting; added 7 September 2026.

What happened

A tactics note, not a CVE. Cameras that face streets and loading docks are intelligence sensors when they are on the internet.

Why it mattered

Physical security teams own cameras. OT teams own the VLAN. Attackers own both if neither patches defaults.

Who / what was affected

Internet-exposed camera fleets in conflict theaters; any industrial site that put CCTV on the control LAN.

Technical context

Change defaults. Segment. Firmware. Assume a camera is a Linux host with a lens.

Exploitation / threat status at the time

CONFIRMED class of activity as described by Nozomi and later Dutch intel.

REPORTED specific Tehran/Weizmann narratives.

What defenders should have done

  1. Camera VLAN ≠ OT VLAN.
  2. Kill default passwords (Hanwha WDM hard-coded secret is the same lesson).
  3. Monitor camera firmware C2.

RWP assessment

Confidence: High on the class. Do not treat FT targeting details as RWP-confirmed kill-chain.

Defensive actions

  1. External scan for plant CCTV.
  2. Inventory Wisenet/Hikvision/Axis on industrial networks.
  3. Brief physical security and OT in the same room.

Sources

  1. Nozomi Networks — IP cameras in modern warfare
  2. Nozomi Networks — APT28 and NATO supply-route cameras (July 2026 sequel)
  3. Financial Times reporting as cited by Nozomi on Tehran traffic-camera access — Financial Times reporting as cited by Nozomi on Tehran traffic-camera access