COLUMN: 50,000 cameras hacked by Russia — AI is watching every step in Eastern Europe
In June 2026, Russian hackers compromised more than 50,000 surveillance cameras in Eastern Europe — according to a report by Mash dated
- In June 2026, Russian hackers compromised more than 50,000 surveillance cameras in Eastern Europe — according to a report by Mash dated
- Introduction: When the digital eye becomes a Russian weapon
- 50,000 cameras — a silent army
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: When the digital eye becomes a Russian weapon
50,000 cameras — a silent army
In June 2026, Russian hackers compromised more than 50,000 surveillance cameras in Eastern Europe — according to a report by Mash dated June 21, 2026. These cameras — installed in parking lots, intersections, building entrances, and shops — have become Moscow's eyes in the streets of countries that are officially at peace but find themselves under permanent enemy surveillance. This is not science fiction. It is the documented reality of Russian cyberwarfare in 2026.
What makes this intrusion particularly frightening is the technological layer added on top of it: artificial intelligence is being used to analyse in real time the feeds from these compromised cameras, identify faces, recognise licence plates, and log vehicle colours and models. This is no longer passive surveillance — it is active, intelligent surveillance, capable of tracking targeted individuals across an entire camera network without constant human intervention.
AI as a force multiplier for surveillance
Understanding why this attack is so serious requires understanding what AI changes in mass surveillance. A camera without AI produces video feeds that humans must watch to extract information. 50,000 cameras without AI represent 50,000 feeds that no one can monitor simultaneously. With AI applied to those feeds, it becomes possible to automate face detection, track individuals from one camera to the next, and alert human operators in real time when specific targets are identified.
That transformation is fundamental. What Russia has built with these 50,000 hacked cameras is a mass surveillance system that rivals the capabilities of interior security services in the most authoritarian states. In the streets of Eastern Europe, ordinary residents can be followed, identified, and tracked by a foreign service without even knowing it.
The British NCSC and the 75% hostile-state attack rate
A report that changes the perception of the threat
The NCSC (National Cyber Security Centre) of the United Kingdom published an analysis, documented by Security Matters Magazine on June 20, 2026, according to which 75% of cyberattacks on British critical infrastructure come from hostile states. That figure is striking: three quarters of the most serious attacks do not come from opportunistic criminals or hacktivists — they come from organised foreign states with resources, strategic objectives, and sophisticated attack doctrines.
The hostile states identified in this context are well known: Russia, China, Iran, North Korea. These are the four actors that Western intelligence reports regularly cite as the main sources of cyberattacks on democracies. It is no coincidence: they are also the four authoritarian regimes most actively opposed to the liberal international order. Cyberwarfare is an extension of their foreign policy by other means.
Critical infrastructure as priority targets
Critical infrastructure — electricity grids, water distribution systems, hospitals, financial networks — is the priority target of state cyberattacks. The reason is strategic: striking these infrastructures creates pressure on the civilian population and on governments, without triggering the thresholds for conventional military response. It is a form of coercive pressure that remains in the grey zone between war and peace.
Russia has already demonstrated its willingness to target civilian infrastructure in the context of its aggression against Ukraine — the repeated strikes on the Ukrainian electricity grid are the most brutal illustration. Cyberwarfare against the critical infrastructure of NATO member countries is the subtler version of the same doctrine: creating pain without crossing the Article 5 threshold.
27 seconds to compromise a system: offensive AI
The breakout time reduced to under half a minute
The OriginBrief report of June 22, 2026 cites a terrifying data point from a CrowdStrike study: the breakout time — the average time it takes an attacker to move laterally through a network after an initial intrusion — has fallen to 27 seconds in 2026. A few years ago, this time was measured in minutes or hours. Its reduction to under 30 seconds is directly linked to the use of artificial intelligence in offensive attack tools.
What this figure implies for network defenders is staggering. In 27 seconds, an AI attacker can map a network, identify the most valuable access points, and begin extracting data or deploying malware before traditional detection systems have even generated an alert. The speed of offensive AI exceeds the speed of human reaction. And that is where the real challenge of modern cyber defence lies.
AI-powered attacks up 89%
According to OriginBrief, attacks using AI increased by 89% in 2026 compared to 2025. This exponential growth reflects the democratisation of offensive AI tools. Capabilities that, five years ago, were reserved for the best-resourced intelligence services are now accessible to less sophisticated hacker groups — and naturally to the cyber units of hostile states with the resources to deploy them at scale.
This trend is fundamentally asymmetric: AI advantages the attacker over the defender. An attacker can use AI to automatically scan millions of systems for vulnerabilities, generate personalised phishing messages at scale, and adapt attacks in real time to defenders' responses. A defender must protect all entry points simultaneously. Cyber defence in the AI era is the most asymmetric battle there is.
CISA BOD 26-04: the American response to the cyber emergency
A directive that shortens response timelines
Faced with the rise of AI-powered attacks, the United States has reinforced its cybersecurity framework. CISA (Cybersecurity and Infrastructure Security Agency) BOD 26-04, published on June 10, 2026 and documented by the CSA CISO report of June 20, significantly reduces the vulnerability remediation deadlines for attacks exploiting offensive AI. This directive requires US federal agencies to patch identified flaws within much shorter timeframes.
The logic is clear: if offensive AI can exploit a vulnerability in 27 seconds, correction windows measured in weeks or months are catastrophically inadequate. BOD 26-04 is the institutional response to that inadequacy — an acknowledgement that the speed of the threat demands a comparable speed of response. It is a paradigm shift in the management of cyber vulnerabilities.
NSPM-12 and federal coordination
National Security Presidential Memorandum 12 (NSPM-12), also cited in the CSA CISO report of June 2026, establishes a framework of enhanced coordination among American federal agencies for responding to cyberattacks from hostile states. This coordination is essential: institutional fragmentation — dozens of agencies with different systems, protocols, and chains of command — is one of the main vulnerabilities of the US government in the face of sophisticated cyberattacks.
NSPM-12 represents a step toward a unified federal cyber posture — a cyber defence infrastructure that speaks with one voice and rapidly shares threat information between agencies. Without this coordination, hostile state actors exploit the gaps between agencies — attacking where responsibilities overlap or fall through the cracks. Coordination is the first line of defence against systemic attacks.
OpenClaw and targeted AI agents
The Palo Alto Unit 42 campaign of June 24
Palo Alto Unit 42, one of the most respected cybersecurity units in the world, documented on June 24, 2026 a campaign targeting the OpenClaw AI agent ecosystem. This information, reported by CyberNetSec, reveals a new phenomenon: attackers are no longer only targeting traditional computer networks — they are now targeting artificial intelligence systems themselves.
AI agents — autonomous systems capable of executing complex tasks without constant human supervision — are increasingly deployed in critical environments: network management, sensitive data analysis, industrial systems coordination. Compromising them represents a new frontier in cyberwarfare: hacking an AI that manages other systems means simultaneously hacking all the systems that AI oversees.
The new attack surface of AI
The campaign against OpenClaw illustrates a major trend documented by the Five Eyes. CyberNetSec on June 24, 2026 reports a joint alert from the Five Eyes — the Anglo-Saxon intelligence alliance — on AI-related cyber threats. This alert underlines that the rapid adoption of AI systems is creating new attack surfaces that traditional security frameworks are not designed to defend.
The vulnerabilities specific to AI systems include: training data poisoning attacks (subtly altering training data to bias model decisions), malicious prompt injection (manipulating language models into executing unintended actions), and model theft (extracting the AI model itself for use or compromise). These attack vectors did not exist five years ago — they are the frontier of cybersecurity in 2026.
The 50,000 cameras in their geopolitical context
An operation targeting Ukraine's allied space
The geopolitical context of the 50,000 cameras hacked in Eastern Europe is clear. This region includes countries actively supporting Ukraine — Poland, the Baltic states, the Czech Republic, Slovakia, Romania — and hosting critical logistical infrastructure for the delivery of military aid to Kyiv. Mass surveillance of these countries allows Russia to identify material movements, arms convoys, transit points, and potentially military or intelligence personnel in transit.
This is not speculative. Russia has a direct and documented interest in monitoring Ukraine's supply routes from Europe. The 50,000 compromised cameras represent a surveillance network that, combined with AI feed analysis, gives it a level of visibility into movements in those countries that its human intelligence services alone could not obtain. Cyberwarfare is not separate from the physical war in Ukraine — it is an extension of it.
The vulnerability of cheap cameras
How were 50,000 cameras able to be compromised? The answer lies in an economic reality of the market: the majority of surveillance cameras deployed in commercial and public spaces in Eastern Europe are low-cost devices, often manufactured in China, with firmware rarely updated and default passwords frequently never changed. These cameras are cyber sieves.
Attackers did not need extraordinary sophistication to compromise them — they used automated tools to scan networks for cameras with known vulnerabilities or default configurations. The scale of the intrusion lies not in the sophistication of the attack but in the depth of security negligence in civilian surveillance infrastructure. It is a painful but necessary lesson.
The Five Eyes facing the AI threat
An intelligence alliance that adapts
The Five Eyes — the intelligence alliance bringing together the United States, the United Kingdom, Canada, Australia, and New Zealand — issued a joint alert on AI-related cyber threats, documented by CyberNetSec on June 24, 2026. This joint alert signals that the AI-cyber threat is now considered sufficiently serious to warrant a coordinated response at the level of the highest Western intelligence alliance.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
Five Eyes alerts are rare and significant documents. They are only issued when the threat is serious enough to justify a collective warning — and when agencies from all five countries have coherent information validating the alert. The publication of this alert in June 2026 means that American, British, Canadian, Australian, and New Zealand agencies have all identified the same trend: the use of AI in cyberattacks by hostile states is accelerating rapidly.
International cooperation as an indispensable response
The Five Eyes alert illustrates a fundamental principle of cyber defence: a cross-border threat demands a cross-border response. A cyberattack on British infrastructure is often launched from servers located in Russia, transiting through nodes in Asia, and targeting systems that also connect allies in Europe. Defending these systems in isolation, in a national logic, is insufficient.
Rapid threat-information sharing among the Five Eyes, extended to NATO and EU partners, is one of the most effective countermeasures available. When one agency detects a new AI attack technique, sharing it immediately with all allies allows the entire coalition to put defences in place before the attack spreads. In cybersecurity, the speed of information sharing is a defensive weapon.
The Lijian anti-drone laser and the convergence of domains
When cyber and kinetic converge
DroneSense on June 22, 2026 reports the existence of the Lijian anti-drone laser — a directed-energy weapon system that illustrates the growing convergence between cyber and physical domains. While discussions about hacked cameras and cyberattacks may seem remote from physical combat, the Lijian laser represents a physical response to threats that originate in the digital domain.
Drones — whether Ukrainian attacking Russian targets or potentially used for intelligence operations over allied territory — are systems that depend on digital communications to function. Disrupting them electronically (electronic warfare) or destroying them physically (lasers, anti-drone missiles) are two complementary approaches to the same problem: the threat of digitally guided unmanned aerial systems.
The campaign against Google Workspace: the company as target
DroneSense also reports a campaign targeting Google Workspace — an attack against the cloud infrastructure underpinning millions of companies, government organisations, and educational institutions worldwide. This campaign illustrates how centralised cloud platforms have become prime targets for malicious state actors: compromising a cloud platform can simultaneously grant access to thousands of its customers.
For Ukrainian organisations and their international supporters, who depend heavily on cloud services such as Google Workspace for their communications, the security of these platforms is a direct concern. A successful campaign against these services could expose sensitive communications about the coordination of aid to Ukraine or about military operations. Cyberwarfare does not stop at Ukraine's borders — it follows the networks that support it.
The camera campaign in a broader context
A structured intelligence operation
The 50,000 hacked cameras are not an opportunistic act of digital vandalism — they are a structured intelligence operation with clear objectives. By mapping the flow of people and vehicles in Eastern European cities, Russia can identify movement patterns that reveal valuable military and logistical information: which convoy takes which route and at what frequency; which buildings are visited by personnel identified as associated with aid to Ukraine; which road arteries are used for the transport of military equipment.
This imagery intelligence (IMINT) acquired through civilian cameras complements satellite and cyber intelligence to build a complete operational picture of allied support operations for Ukraine. The targeted countries are not simply victims of a hack — they are victims of a military intelligence operation conducted on their own territory without their consent.
Regulatory and technical responses
Faced with this threat, several responses are required. On the technical front: mandatory minimum security standards for security camera manufacturers — mandatory password change at installation, automatic firmware updates, feed encryption. On the regulatory front: the EU and its members should adopt cybersecurity requirements for connected public surveillance equipment, banning non-compliant devices.
On the strategic front: counter-intelligence services in Eastern European countries must conduct regular audits of their surveillance infrastructure to detect compromises. Collaboration between allied security services to share information on intrusion techniques used by Russian hackers is indispensable. The security of surveillance cameras has become a national security issue — not merely an IT problem.
AI in cyber defence: fighting fire with fire
Defending with the same technology that attacks
If AI is at the core of the cyber threat in 2026, it is also — potentially — at the core of the defensive response. AI-based intrusion detection systems can analyse network traffic flows at a speed and scale impossible for human teams, detect subtle anomalies that foreshadow an attack, and automatically respond by isolating compromised systems before the attacker has had time to move laterally.
The central question is one of response speed. If the breakout time is 27 seconds, the defensive response must be even faster. Defensive AI systems operating at millisecond scale — detecting and neutralising an intrusion before a human operator is even alerted — are the only technically viable response to that speed of attack. Tomorrow's cyber defence is an AI-versus-AI war, with humans as supervisors of last resort.
The limits of defensive automation
Defensive automation carries its own risks. An overly aggressive AI defence system can block legitimate communications, generate false positives that paralyse normal operations, or itself be manipulated by attackers who understand its algorithms. Human oversight remains indispensable for high-impact decisions — isolating an entire network, blocking diplomatic communications, or responding to an attack with an active countermeasure.
The balance between automation and human oversight is the central challenge of AI cyber defence. Organisations that find that balance — a fast defensive AI with intelligent human oversight for critical decisions — will hold the advantage over those that remain either too manual (too slow) or too automated (too risky). Effective cyber defence will always be a human-machine collaboration.
The implications for ordinary citizens
On the same topic
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
Privacy in the age of Russian surveillance
For ordinary citizens in Eastern Europe, the reality of these 50,000 hacked cameras is deeply unsettling. It means that trips to the bank, visits to hospital, and everyday movements recorded by shop or parking cameras may be accessible to a hostile foreign intelligence service. This reality is hard to accept — but denying it would be irresponsible.
Privacy in public space has become a national security issue as much as a civil right. Resistance to Russian mass surveillance passes through individual measures — awareness of camera presence, precautions during sensitive movements — and collective measures — pressure on camera operators to secure their equipment, and political pressure for stricter regulation.
Cyber hygiene education as a defence
Beyond institutional policies, individual cyber hygiene is a real defence. Simple practices — changing default passwords on connected devices, regularly updating firmware, segmenting home networks — significantly reduce the attack surface available to hackers. This is not enough against a sophisticated state attack, but it raises the minimum level of protection for the most vulnerable devices.
Cyber hygiene education is particularly urgent for small and medium businesses, municipalities, and operators of non-critical infrastructure that have no dedicated IT departments but nevertheless deploy dozens of cameras and connected devices. It is in this population of negligent users that Russia recruits its camera armies — and it is there that the awareness battle is most urgent.
Cyber Russia and its digital allies
The hostile cyber ecosystem
Russia does not wage its cyberwar alone. It benefits from an ecosystem of tolerated cybercriminals — groups like Sandworm, APT28, Cozy Bear — that operate in more or less explicit coordination with Russian intelligence services. These groups use global server infrastructure, sophisticated obfuscation techniques, and state-level cyberattack capabilities while maintaining an ambiguity about their official ties to Moscow.
Iran and North Korea contribute to this hostile ecosystem. Their own cyber units — Iranian APT33, North Korean Lazarus Group — run parallel campaigns that sometimes coordinate with Russian operations. The cyber alliance between Moscow, Tehran, and Pyongyang is less formal than their conventional military cooperation, but it is real and documented.
China: competitor or accomplice?
China's position in this ecosystem is more ambiguous. Chinese cyber groups — APT40, APT41 — run their own economic and military espionage campaigns against the West. But their coordination with Russia is limited: Chinese interests in cyberwarfare do not always align with Moscow's. China is more of a strategic competitor profiting from the Western distraction created by the war in Ukraine than a direct cyber ally of Russia.
Nevertheless, Beijing's tolerance of Russian cyber operations — its refusal to publicly condemn or cooperate with investigations — creates an enabling environment for Moscow. When China protects Russia at the UN and tolerates its cyber operations, it becomes de facto part of the security infrastructure of Russian cyberwarfare. Neutrality in cyberwarfare is a form of complicity.
What this cyber war says about our digital future
The free internet under permanent threat
The cyber chronicle of June 2026 — 50,000 hacked cameras, 75% state attacks, 27-second breakout time, OpenClaw campaign, Five Eyes alert — paints the portrait of a digital space under permanent siege. The free internet, built on the idea of open and decentralised communication, has become a battlefield where authoritarian states exploit openness to conduct surveillance, sabotage, and influence operations.
Defending this digital space is not merely a technical question — it is a fundamental political and civic question. Deciding collectively what rules govern cyberspace, how to punish violations, how to protect critical infrastructure and citizens' privacy — these decisions define the type of digital society in which we want to live. Allowing Russia and other hostile actors to define those rules by default would be a civilisational abdication.
Vigilance as a democratic way of life
Ultimately, the response to Russian cyberwarfare cannot be solely technical. It must be cultural and civic. Informed citizens, cyber-aware businesses, governments that invest in resilience and international cooperation, and a free press that continues to document and sound the alarm about these threats — this entire democratic ecosystem constitutes the best defence.
The 50,000 cameras hacked in Eastern Europe are a brutal reminder that war is no longer confined to defined battlefields. It is in the streets of our cities, in the networks of our businesses, in the infrastructure that powers our daily lives. Vigilance is no longer optional — it is the sine qua non of democratic survival in the world of 2026.
The right to privacy in the age of total surveillance
The tension between collective security and individual freedom
The network of 50,000 cameras accessible to hackers raises a fundamental philosophical question: how far can a society accept being surveilled in the name of security? This tension is not new — it has existed ever since the first surveillance cameras were installed in public spaces. But the scale of the breach exposed by this investigation — tens of thousands of video feeds accessible without protection, in private apartments, clinics, and intimate spaces — is a reminder that uncontrolled surveillance carries a real human cost.
The Russia-Ukraine war has demonstrated that this surveillance infrastructure can be turned against those it claims to protect. Every poorly secured camera in a Russian city is potentially a Ukrainian eye on enemy military preparations. That is effective. That is real. But it also compels us to reflect on what we want our cities to become — spaces of freedom or systems of permanent control whose keys can be stolen by anyone with the right technical skills.
Lessons for the cybersecurity of civilian infrastructure
The exposure of 50,000 Russian cameras accessible without serious authentication is not only a Russian problem. Equivalent studies on Western surveillance infrastructure have revealed similar vulnerabilities — thousands of industrial cameras, SCADA systems, and network equipment accessible via default credentials never modified. Russia is not unique in its security negligence: it is simply the most visible example right now.
The lesson for Western businesses and governments is clear: every connected device is a potential entry point into critical infrastructure. Cybersecurity can no longer be an afterthought — it must be integrated from design, from installation, from the first deployment. What Ukrainian hackers did with Russian cameras, any hostile actor could do tomorrow with our own systems.
Conclusion: Watching without being watched — a threat we can no longer ignore
The documented reality of Russian cyberwarfare
The facts documented this week are unambiguous: 50,000 cameras compromised, 75% of state attacks on British infrastructure, AI breakout time of 27 seconds, campaign against OpenClaw, Five Eyes alert. Russia is waging an active, sophisticated, and systematic cyberwar against Western democracies and their allies in Eastern Europe. This war is not a future hypothesis — it is a present reality, documented, measurable.
The response to this reality must match the scale of the threat. It must combine technical investment in cyber defence, regulations on the security of connected devices, enhanced international coordination, and public education in cyber hygiene. None of these responses alone is sufficient — together, they constitute the defensive architecture our societies need.
The last line of defence: citizen awareness
Technology can defend networks. Laws can punish complicit state actors. Alliances can share intelligence. But the last line of defence against Russian cyberwarfare — as against all forms of hybrid warfare — is citizen awareness. Citizens informed about the threats, vigilant about their digital practices, and politically engaged in favour of ambitious cybersecurity policies.
The 50,000 hacked cameras are watching us. It is time to look the threat they represent squarely in the face. And to act accordingly — individually, collectively, democratically.
Signed Maxime Marquette, columnist
Columnist's transparency box
Editorial positioning
This column is written by Maxime Marquette, columnist and analyst. I am not a cybersecurity expert. All facts and figures cited come from the sources listed below, all dated and verifiable. I am pro-Ukrainian and in favour of a strong democratic response to Russian cyber threats — this positioning is transparent.
Limitations of the column
Cybersecurity evolves very rapidly. Some technical details about the documented attacks may be incomplete or partial in the available public sources. Figures such as the 27-second breakout time and the 89% rise in AI attacks are estimates from recognised but non-official industry sources — they reflect real trends but may vary depending on methodology.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). COLUMN: 50,000 cameras hacked by Russia — AI is watching every step in Eastern Europe. MadMax. https://mad-max.co/en/article/chronique-50-000-cameras-hackees-par-la-russie-l-ia-surveille-chaque-pas-en-euro
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.