Surveillance Cameras in the Crosshairs: When Digital Eyes Become Tools of Military Espionage

Introduction

In today’s connected world, even an apparently innocuous device like a security camera can become an intelligence tool. Starting from February 28, 2026, a coordinated campaign attributed to Iran-linked actors has targeted IP cameras in Israel and several Persian Gulf countries. The episode raises important questions about how truly secure the devices we use every day to protect buildings and infrastructure really are.

What Happened

The attacks targeted surveillance cameras from two globally widespread brands, Hikvision and Dahua, exploiting known vulnerabilities in their software systems. These are security flaws already documented in previous years, some dating back to 2017, for which official patches had already been released. Despite this, many devices were still unpatched and therefore exposed.

The affected countries include Israel, Qatar, Bahrain, Kuwait, the United Arab Emirates, Lebanon, and Cyprus. The responsible actors allegedly used VPN infrastructure and virtual private servers to conduct reconnaissance and network scanning operations, searching for accessible and vulnerable cameras.

According to intelligence agency assessments, the goal was not to sabotage the devices or demand a ransom, but to collect military intelligence: understanding force deployments, assessing damage after kinetic attacks, and supporting field operations. A documented case during the Israel-Iran conflict of June 2025 shows how a compromised camera near the Weizmann Institute in Israel had been breached prior to a missile attack, suggesting a direct use of the footage for operational purposes.

Why It Matters

This episode shows that surveillance cameras are not secondary or marginal targets. When positioned near sensitive sites, they can provide valuable information to those seeking to conduct hostile operations. The issue concerns not only governments and large infrastructures, but also private companies, universities, hospitals, and residential buildings that install these devices without regularly updating them.

What Companies and Users Can Do

The first thing to do is update the firmware of IP cameras to the latest available version, as many of the vulnerabilities exploited in this campaign already had an official patch available for some time. It is also advisable to change the default credentials of the devices, isolate cameras on separate networks from main corporate systems, and rely on professionals for initial configuration. Those who are unsure about the status of their devices should contact their vendor or a cybersecurity expert.

Final Takeaways

  • Unpatched vulnerabilities remain a real risk even years after their discovery: updating devices is not optional.
  • Surveillance cameras can be used as intelligence-gathering tools in conflict scenarios, even remotely and without the owners noticing.
  • Physical security and digital security are increasingly interconnected: protecting a building today means also protecting the connected devices within it.

Sources:
https://securityaffairs.com/189069/cyber-warfare-2/iran-linked-hackers-target-ip-cameras-across-israel-and-gulf-states-for-military-intelligence.html
https://www.cybersecuritydive.com/news/iran-hackers-target-flaws-ip-cameras/813795/
https://www.theregister.com/2026/03/04/iranian_hacking_attempts_ip_cameras/
https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html

Source: Security Affairs