Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-23 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Dutch intel found APT28 on cameras along the NATO logistics tail — not just the front

AIVD/MIVD 10 July 2026 — Russian operators on internet cameras, including a few on military transport routes in the Netherlands. Nozomi's 23 July note ties it to unit 26165's 2022– border-crossing campaign.

RWP Ventures · 2026-09-07 · event 2026-07-10 · 1 min read · priority 8.0

Bottom line up front

CONFIRMED Nozomi, 23 July 2026 — Dutch AIVD and MIVD went public 10 July that Russian operators had compromised internet-connected cameras, including a small number along military transport routes inside the Netherlands, to see what was moving toward Ukraine. Nozomi frames this as the logistics-tail end of the same APT28 / Fancy Bear / unit 26165 camera campaign documented in an April 2025 joint advisory covering border crossings, rail, and military sites since February 2022. Distinct from this archive's 2 April "cameras as BDA" post (Israel–Iran). Doorbell/business-park cameras three countries from the front are in scope. Process/ICS impact: UNKNOWN. Camera-as-ISR: CONFIRMED as Dutch intel + Nozomi class analysis.

Historical backfill of 23 July 2026 reporting; added 7 September 2026.

What happened

GRU-linked operators watched roads, not just trenches. The cameras were on the internet with the usual hygiene.

Why it mattered

"Physical security CCTV" on a plant or port that sits on a military logistics corridor is a national-intel sensor. OT teams that ignore cameras will brief the wrong risk.

Who / what was affected

Netherlands transport-route cameras (small number, per Dutch services). Broader APT28 camera set since 2022.

Technical context

Default creds, exposed management, no segmentation. Same as Hanwha/Cognex lessons with a state actor on the other end.

Exploitation / threat status at the time

CONFIRMED Dutch services + 2025 joint advisory lineage.

REPORTED Nozomi's connective tissue between the two.

What defenders should have done

  1. Scan cameras on industrial and port networks.
  2. Assume APT28 interest if you sit on aid routes.
  3. Do not leave ONVIF on WAN.

RWP assessment

Confidence: High on the Dutch finding. High that this is a separate URL/date from the April warfare piece.

Defensive actions

  1. Camera inventory with geolocation vs logistics.
  2. Kill default passwords.
  3. Brief physical security and OT together — again.

Sources

  1. Nozomi Networks — APT28 IP cameras on NATO supply routes
  2. Dutch AIVD/MIVD public finding 10 July 2026 (as cited by Nozomi) — Dutch AIVD/MIVD public finding 10 July 2026 (as cited by Nozomi)
  3. April 2025 multi-agency advisory on APT28/unit 26165 camera-hacking since Feb 2022 — April 2025 multi-agency advisory on APT28/unit 26165 camera-hacking since Feb 2022