Historical intelligence backfill. This assessment covers reporting originally published on 2026-07-23 and was added to the RWP archive on 2026-09-07.
Dutch intel found APT28 on cameras along the NATO logistics tail — not just the front
AIVD/MIVD 10 July 2026 — Russian operators on internet cameras, including a few on military transport routes in the Netherlands. Nozomi's 23 July note ties it to unit 26165's 2022– border-crossing campaign.
Bottom line up front
CONFIRMED Nozomi, 23 July 2026 — Dutch AIVD and MIVD went public 10 July that Russian operators had compromised internet-connected cameras, including a small number along military transport routes inside the Netherlands, to see what was moving toward Ukraine. Nozomi frames this as the logistics-tail end of the same APT28 / Fancy Bear / unit 26165 camera campaign documented in an April 2025 joint advisory covering border crossings, rail, and military sites since February 2022. Distinct from this archive's 2 April "cameras as BDA" post (Israel–Iran). Doorbell/business-park cameras three countries from the front are in scope. Process/ICS impact: UNKNOWN. Camera-as-ISR: CONFIRMED as Dutch intel + Nozomi class analysis.
Historical backfill of 23 July 2026 reporting; added 7 September 2026.
What happened
GRU-linked operators watched roads, not just trenches. The cameras were on the internet with the usual hygiene.
Why it mattered
"Physical security CCTV" on a plant or port that sits on a military logistics corridor is a national-intel sensor. OT teams that ignore cameras will brief the wrong risk.
Who / what was affected
Netherlands transport-route cameras (small number, per Dutch services). Broader APT28 camera set since 2022.
Technical context
Default creds, exposed management, no segmentation. Same as Hanwha/Cognex lessons with a state actor on the other end.
Exploitation / threat status at the time
CONFIRMED Dutch services + 2025 joint advisory lineage.
REPORTED Nozomi's connective tissue between the two.
What defenders should have done
- Scan cameras on industrial and port networks.
- Assume APT28 interest if you sit on aid routes.
- Do not leave ONVIF on WAN.
RWP assessment
Confidence: High on the Dutch finding. High that this is a separate URL/date from the April warfare piece.
Defensive actions
- Camera inventory with geolocation vs logistics.
- Kill default passwords.
- Brief physical security and OT together — again.
Sources
- Nozomi Networks — APT28 IP cameras on NATO supply routes
- Dutch AIVD/MIVD public finding 10 July 2026 (as cited by Nozomi) — Dutch AIVD/MIVD public finding 10 July 2026 (as cited by Nozomi)
- April 2025 multi-agency advisory on APT28/unit 26165 camera-hacking since Feb 2022 — April 2025 multi-agency advisory on APT28/unit 26165 camera-hacking since Feb 2022