According to intelligence information from the AIVD and MIVD, Russian state actors target IP cameras to spy on (critical) infrastructure in NATO countries. However, the NCSC notes that this misuse is not limited to governments: hacktivist groups and cybercriminals also compromise IP cameras. With IP-camera security against spying, you reduce the chance that your camera is used for intelligence gathering, data theft, or attacks such as DDoS.
The good news: you don’t have to “turn everything upside down.” By taking a few targeted measures, you make it much harder for malicious actors to gain access.
Why IP cameras are attractive to attackers
IP cameras often look straightforward: a device records video and streams it to an app or NVR. For attackers, that’s exactly what makes them appealing. In most cases, they don’t need advanced techniques; much of the abuse happens because cameras are directly exposed to the internet with default settings or because security updates are not installed often enough.
There’s more: a compromised camera doesn’t just “leak images.” Live camera feeds can also serve as a digital reconnaissance tool—they can help track troop and equipment movements or map infrastructure. In addition, poorly secured cameras can be used in botnets, for example for DDoS attacks or for sending spam and phishing.
The threat is broader than state actors
Although the warning specifically focuses on spying by Russian state actors, the risk is not limited to governments. The NCSC reports that hacktivist groups also regularly claim compromises of IP cameras via social media. Their motives may be politically or ideologically driven and sometimes align with the interests of foreign governments.
Cybercriminals also play a role in the “practical” reality: an unsecured camera is often easy to find and provides immediately usable access.
What you can do as an organization
For businesses, IP cameras can add extra risk to the wider corporate network—not only because the cameras themselves may be vulnerable, but also because access to a camera can serve as a stepping stone for other attacks.
Work on multiple layers at the same time:
- Inventory your devices and stay alert to IoT devices such as cameras, streaming boxes, and related systems.
- Block unnecessary outbound ports (such as SOCKS5 and proxies) at the network or device level.
- Implement an asset/device policy to keep unknown or unauthorized devices out of the network, including attention to BYOD.
- Limit installation permissions to prevent shadow IT.
- Do patch management: keep cameras and any NVR systems up to date so known vulnerabilities are remediated.
- Replace End-of-Life devices that no longer receive security updates.
- Use segmentation with VLANs: place cameras (and NVRs) in a separate, isolated IoT network. This helps malware spread less easily.
- Improve detection by being able to spot unusual traffic. An IoT segment that suddenly generates a lot of outbound traffic may be a warning sign.
- Use firewall rules and implement IDS/IPS where possible. Block suspicious sources and unauthorized services.
- Monitor and respond to unusual inbound traffic. Block suspicious sources if needed.
- Restrict camera access to local access or via VPN for access from outside.
- Disable insecure protocols, such as UPnP, Telnet, FTP, HTTP, and unencrypted RTSP. Choose safer alternatives like HTTPS/RTSPS or SFTP.
- Turn off unnecessary features, for example SSH and other management capabilities you don’t need.
- Consider Zero Trust for organizations with high security requirements, including continuous verification of devices and users.
What can you do as a home user?
At home, IP-camera security against spying can also have an immediate impact. A compromised camera can be used to view the images from the places you monitor. In addition, an attacker may launch DDoS attacks using your devices, without you noticing right away. The consequences can become visible through slower connections, blocked access to websites—or worse: that you end up unintentionally participating in cybercrime.
So focus on getting the basics right:
- Treat every internet connection as a risk. IP cameras are often less well secured and updated less frequently than other devices.
- Limit the field of view. Position the camera so you aren’t filming locations where misuse would cause extra harm. Make the decision based on your situation.
Although the NCSC mainly highlights the points above for home users, the core message is clear: prevent your camera from becoming the weakest link.
Take action now: reduce the chance of abuse
Criminals and other actors can use IP cameras for multiple purposes: reconnaissance, data breaches, spying, and participation in botnet-based attacks. By taking IP-camera security against spying seriously—with updates, access restrictions, and network security—you reduce the chance of data theft and prevent malicious actors from misusing your camera.
Whether you manage an organization or use cameras at home: start today with the measures that have the biggest impact in your environment. That way, you help not only yourself, but also others working together toward a more digitally resilient Netherlands.
