Security Cameras Become Wartime Spy Tools, Exposing Business Risks

URL has been copied successfully!

Britain’s National Cyber Security Centre warned on August 27 that increased attacks on internet-exposed operational systems had caused limited real-world disruption. Its alert adds urgency to a separate wartime threat documented this year: hackers targeting civilian security cameras. For businesses, equipment installed to protect premises can become an outsider’s view into operations.

Check Point Research reported on March 4 that targeting intensified from February 28, 2026. It identified activity involving Hikvision and Dahua systems in Israel, Qatar, Bahrain, Kuwait, the United Arab Emirates and Cyprus, with additional activity in Lebanon.

The researchers attributed the attack infrastructure to Iran-linked actors and assessed that camera access could support military operations, including checking damage after missile attacks. That is an assessment of the activity’s likely purpose, rather than proof that every attempted intrusion succeeded or guided a particular strike.

The campaign sought systems exposed to five known security vulnerabilities. Check Point said patches were available for all five. Some weaknesses affect camera-management software and related surveillance products, making the recording and management equipment part of the security problem.

These systems contain computers as well as lenses. A software flaw can let an unauthorized user bypass security or take control, while weak login credentials offer another route. Changing a password addresses one weakness; it does not repair vulnerable software.

The Russian campaign illustrates the scale. A joint advisory issued in May 2025 by the National Security Agency, FBI and international partners described targeting by Russian military intelligence unit 26165 against Western logistics and technology companies supporting Ukraine.

The agencies said the actors likely used private cameras near border crossings, military installations and rail stations to track supplies entering Ukraine. They also used legitimate municipal traffic-camera services.

In a sample of more than 10,000 targeted cameras, 81% of attempts were associated with Ukraine and 9.9% with Romania. Those figures describe targeting activity, not a verified total of successfully hijacked cameras.

The advisory documented attempts using publicly known factory credentials and password guessing. A camera overlooking a loading area could therefore have intelligence value even when its owner handles no classified information. The potential exposure is what moves through its field of view.

For American businesses, the broader concern extends beyond stolen footage. The National Institute of Standards and Technology describes how a compromised camera on an unrestricted small-business network can be used to attack other local devices or outside targets.

That does not mean accessing a camera automatically opens payroll or customer databases. The risk depends on the network’s layout, access controls and additional vulnerabilities. But treating surveillance equipment as separate from cybersecurity can leave a business overlooking a possible entry point.

NIST also warns that compromised connected devices can be assembled into networks used to overwhelm online services. The resulting outages can prevent customers from reaching a business, with potential losses in revenue, reputation and trust.

The practical defenses address several different failure points. Check Point recommends unique passwords, updated camera and recorder software, and removing direct internet exposure. Its guidance also calls for isolating surveillance equipment from corporate networks and monitoring unexpected connections.

Britain’s camera-security guidance recommends disabling remote viewing when it is unnecessary. Its August alert also urges organizations to inventory internet-facing equipment, retire unsupported devices and monitor unexpected connections. For owners who need remote viewing, the installation needs controlled access rather than an openly reachable management interface.

WIRED’s March reporting independently examined the Check Point findings. It said Hikvision and Dahua did not respond to its requests for comment about the campaign.

The next business decision is whether existing cameras remain supportable and properly isolated. A replacement budget may be necessary for obsolete equipment; supported devices still need ongoing updates and access reviews. The purchase price covers the hardware. Keeping it from becoming someone else’s surveillance system requires maintenance.

JBizNews Desk | Washington, D.C.

© JBizNews.com. All rights reserved. This article is original reporting by JBizNews Desk. Unauthorized reproduction or redistribution is strictly prohibited.

Please follow us:
Follow by Email
X (Twitter)
Whatsapp
LinkedIn
Copy link