Skip to content
The ColumnEditorial· No. 678

EDITORIAL: 50,000 cameras hacked by Moscow in Europe — cyberwarfare has changed in scale

On June 21, 2026, Russian media outlet Mash — considered close to Russian intelligence services — reveals that Russian hackers have compromised

Premium reading
MadMax
Key takeaways
  1. On June 21, 2026, Russian media outlet Mash — considered close to Russian intelligence services — reveals that Russian hackers have compromised
  2. Introduction: A figure that should wake us up
  3. June 21, 2026: Mash lifts the veil
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: A figure that should wake us up

June 21, 2026: Mash lifts the veil

On June 21, 2026, Russian media outlet Mash — considered close to Russian intelligence services — reveals that Russian hackers have compromised 50,000 surveillance cameras in Eastern Europe. These cameras are now being used with active AI capable of facial recognition, licence plate reading, and vehicle and clothing colour identification. The presumed objective: to monitor allied military movements and identify Western advisers and instructors in Ukraine.

Fifty thousand cameras. This is not a targeted attack on a specific infrastructure. It is a mass surveillance network built silently in apartment buildings, intersections, businesses, and airports — by hackers who exploited the vulnerabilities of poorly secured systems to create large-scale passive human intelligence. This is industrial espionage in the digital age.

Why this editorial is necessary

This editorial defends a simple thesis: we are not sufficiently prepared. Not governments, not businesses, not citizens. The Mash revelation is not an isolated incident — it is a symptom of systemic vulnerability that experts have been flagging for years and that political decision-makers have not yet addressed with the urgency it requires. It is time to shift gears.

Cyberwarfare is no longer an abstract threat for information security specialists. It is playing out in the streets of Warsaw, Tallinn, Bucharest — on cameras you never look at but which may be watching you on Moscow's behalf.

What 50,000 cameras mean concretely

A mass surveillance network at low cost

To grasp the scale of this intrusion, one must understand how a modern surveillance camera system works. An IP camera — the most common type in public and commercial spaces — is connected to the internet. When it is poorly configured, with unchanged default passwords or unpatched firmware, it is accessible from anywhere in the world.

Specialised search engines — Shodan, Censys — allow anyone to discover millions of poorly secured cameras in seconds. Russian hackers with automated tools can compromise tens of thousands of these cameras in days. The operational cost of this attack is minimal — but its intelligence return is considerable.

AI in the service of military surveillance

What makes this attack particularly dangerous is the integration of AI into image processing. Facial recognition AI can identify known individuals — allied military officers, Western advisers, liaison personnel — from databases of public or stolen photographs. Automated licence plate reading allows tracking the movements of military vehicles across countries.

Identification by vehicle and clothing colour completes this system — allowing convoys or individuals to be tracked even when image resolution does not permit facial identification. By combining these three levels of analysis, Russian hackers can create a detailed intelligence picture of military movements in countries bordering Ukraine — without ever needing a human agent on the ground.

75% of UK cyberattacks linked to hostile states

The UK NCSC sounds the alarm

The revelation about hacked cameras fits into a context of sharply rising state cyber threats. According to the UK National Cyber Security Centre (NCSC), documented by Security Matters Magazine (June 20, 2026), 75% of cyberattacks targeting UK critical infrastructure are now linked to hostile states — Russia at the top, followed by China and Iran.

That figure is striking. Three quarters of attacks on power plants, water distribution systems, transport networks, and British hospitals are not the work of cybercriminals seeking a ransom — they are deliberate acts of espionage or pre-positioning for future offensive actions. The boundary between peacetime and a state of latent war has dissolved in cyberspace.

The NCSC's 2028 forecast: AI and OT vulnerabilities

The NCSC goes further with a troubling forecast: by 2028, AI will enable large-scale exploitation of vulnerabilities in legacy OT systems (Operational Technology — industrial control systems in critical infrastructure). These systems — often twenty or thirty years old — were never designed to withstand sophisticated digital attacks.

An attacker equipped with AI capable of automatically identifying vulnerabilities in these systems could, in theory, simultaneously compromise dozens of power plants, water treatment facilities, and gas networks across a country. This is the catastrophic cyberwarfare scenario — and the NCSC says it will be technically feasible in two years.

CISA BOD 26-04: Washington acknowledges the urgency

AI weaponises vulnerabilities in hours

In the United States, the Binding Operational Directive 26-04 from CISA (Cybersecurity and Infrastructure Security Agency), published on June 10, 2026, officially acknowledges that AI can "weaponise" vulnerabilities in hours. This directive — applying to all American federal agencies — drastically shortens required remediation timelines.

Before AI, exploiting a newly discovered vulnerability typically required days or weeks of development. With generative AI tools applied to exploit code, this window can be reduced to hours. Defenders following multi-week remediation cycles find themselves structurally behind attackers operating at AI speed.

The directive as a partial admission of helplessness

CISA BOD 26-04 is also a partial admission of helplessness: it implicitly acknowledges that current remediation procedures are no longer adapted to the pace of AI-assisted attacks. It imposes new rules — but those rules presuppose that government organisations have the human and technical resources to implement them.

For the tens of thousands of companies and organisations that do not fall under CISA's mandate — small and medium businesses, local authorities, private infrastructure operators — no directive applies. That is where surveillance cameras are. That is where legacy OT systems are. That is where Russian hackers operate.

eCrime 2026: breakout time of 27 seconds

Attack speed becomes inhuman

According to the OriginBrief report (June 22, 2026), in 2026 the attackers' cybercriminal "breakout time" has fallen to just 27 seconds. "Breakout time" measures the delay between an initial system compromise and the moment the attacker expands access to other parts of the target network.

Twenty-seven seconds. That is less time than it takes for IT security staff to be alerted to an anomaly, let alone make a decision and act. An attacker who penetrates a network at 2:00 PM can have compromised the entire system before the alert is read at 2:00:27. In this environment, real-time AI detection is not a luxury — it is the only technically credible response.

AI-assisted cyberattacks up 89%

AI-assisted cyberattacks have increased 89% year-on-year according to the same OriginBrief data. This figure covers both state and criminal attacks. It reflects the mass adoption of AI tools to automate all attack phases: reconnaissance, exploitation, lateral movement, exfiltration.

For states like Russia or China, AI transforms cyberwarfare from a labour-intensive activity requiring highly skilled personnel into a massively scalable capability. With the right AI tools, a team of a few dozen hackers can conduct operations that would have required thousands of people five years ago. The cost-effectiveness ratio of cyberattacks has radically shifted in favour of attackers.

What Europe must do — now

Securing cameras and IoT as a national priority

The revelation of 50,000 hacked cameras demands an urgent policy response. Every European country must impose minimum security standards for IP cameras and connected IoT (Internet of Things) devices on public networks. Passwords mandatorily changed at installation, automatic firmware updates, disabling unnecessary remote access — these are basic measures that would have drastically reduced the attack surface exploited by Russian hackers.

The EU's NIS2 Directive, in force since 2023, imposes cybersecurity requirements on essential infrastructure operators. But small surveillance camera installers in residential buildings do not fall within its scope. Regulation must be extended to connected surveillance equipment in at-risk areas — borders, military bases, sensitive industrial zones.

Cyber intelligence as active defence

Passive defence — fixing vulnerabilities, securing equipment — is no longer sufficient. European countries must invest in active cyber intelligence: identifying Russian and Chinese attack infrastructure, mapping it, disrupting it before it is used. This is what UK GCHQ, the US NSA, and a few European agencies already do — but not with adequate resources.

The CyberNetSec report (June 24, 2026) documents Five Eyes warnings about active cyber threats. This intelligence alliance — the United States, United Kingdom, Canada, Australia, New Zealand — shares threat information in near-real time. The European Union should systematise its integration into these intelligence flows for all its members.

Ukraine under permanent cyberattacks: what we can learn

Ukraine as a cybersecurity laboratory

Ukraine has been, since 2014 and even more intensively since 2022, the most targeted country by Russian cyberattacks in the world. Dozens of major attacks — some temporarily taking essential services offline — have been documented and attributed to groups linked to the Russian GRU and FSB.

But Ukraine has developed, through this adversity, one of the most advanced cyber defence capabilities in the world. Its Cyber Emergency Response Team, supported by Microsoft, Google, Amazon, and other Western tech giants, has developed detection and resistance methods that set the reference standard. Europeans should systematically learn from Ukraine's experience.

Cooperation as an imperative

The Russian hackers who compromised 50,000 cameras do not distinguish between a Polish, Estonian, or Romanian camera. Their network covers all of Eastern Europe — it transcends national borders. The response cannot be national — it must be collective.

ENISA (EU Agency for Cybersecurity) has the technical competence to coordinate a European response. But it lacks resources, strong mandates, and direct action capacity. A strengthened ENISA is needed, equipped with intervention powers in member states in the event of a state-sponsored attack, and offensive intelligence capabilities to disrupt adversary attack infrastructure.

Critical infrastructure security: the European coordination challenge

ENISA and the limits of European cyber governance

ENISA (EU Agency for Cybersecurity) is technically competent but structurally limited. It has no direct action mandate in member states, no offensive capabilities, and resources inferior to those of a single large private cybersecurity firm. Against Russian hackers operating with state resources and sophisticated AI tools, this response level is structurally insufficient.

The EU's NIS2 Directive, in force since 2023, imposes cybersecurity requirements on essential infrastructure operators. But small surveillance camera installers in residential buildings do not fall within its scope. Regulation must be extended to connected surveillance equipment in at-risk areas — borders, military bases, sensitive industrial zones near the EU's eastern borders.

Five Eyes cooperation and European integration into cyber intelligence

The CyberNetSec report of June 24, 2026 documents Five Eyes warnings on active cyber threats. This intelligence alliance — the United States, United Kingdom, Canada, Australia, New Zealand — shares threat information in near-real time. The European Union should systematise its integration into these intelligence flows for all its members, which requires formal sharing agreements that not all member states have yet signed.

Ukraine, as our file notes, has become the most targeted country by Russian state cyberattacks in the world. It has developed, through this adversity, one of the most advanced cyber defence capabilities available. Europeans should systematise the sharing of experience with the Ukrainian cyber team, supported by Microsoft, Google, and Amazon. These operational practices developed under real fire are infinitely valuable.

Conclusion: Cyberwarfare is here, and we are not ready

This editorial's call to action

This editorial defends a simple, urgent position: Europe — its governments, businesses, and citizens — must treat cybersecurity as a top national priority, on par with conventional defence. The 50,000 hacked cameras, the 75% of UK critical infrastructure attacks linked to hostile states, the 89% rise in AI cyberattacks, the 27-second breakout time — these figures describe a wartime reality, not a hypothetical threat.

Putin does not need to send soldiers to Western Europe to begin destabilising its societies. He only needs to maintain active cyber capabilities — cheap, deniable, with no direct risk of military retaliation. Hybrid cyberwarfare is the first front of the war against the West — and it is a front on which we are falling unacceptably behind.

What this editorial defends

This editorial defends the thesis that digital freedom and security are fundamental rights that must be protected by active public policies. It also defends the thesis that Moscow is waging permanent hybrid warfare against European democracies — and that ignoring this fact out of comfort or fear of escalation is a dangerous policy.

Zelensky resists Russian missiles and drones with courage that commands the admiration of the entire world. Europe, for its part, must resist Russian hackers with the resources, regulations, and political will that are still too often lacking. That is the minimum we owe to all those fighting for our common freedom.

Signed Maxime Marquette, columnist

Columnist's transparency box

Sources and data

This editorial rests on the dated sources listed below. The figures cited — 50,000 cameras, 75% state attacks on UK critical infrastructure, 27-second breakout time, 89% increase in AI cyberattacks, the NCSC 2028 forecast on OT vulnerabilities, CISA BOD 26-04 of June 10 — come directly from the sources without modification.

The revelation about the 50,000 cameras is attributed to Russian media outlet Mash, relayed by www1.ru (June 21, 2026). The columnist notes that this information comes from a source close to Russian services — which may mean either an embarrassing truth that Russia's own media reveals, or a deliberate information operation. Journalistic caution is warranted on this attribution, even if the described methods are technically credible.

Editorial position

This editorial is an acknowledged opinion journalistic genre. The columnist defends a firm political position: Europe must massively strengthen its cybersecurity against Russian and Chinese state threats. This position is consistent with his support for Ukraine and his opposition to Putin's regime.

The columnist has no affiliation with cybersecurity firms or government agencies. His analysis is independent. He acknowledges his technical limits in this specialised domain and relied exclusively on published expert sources.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). EDITORIAL: 50,000 cameras hacked by Moscow in Europe — cyberwarfare has changed in scale. MadMax. https://mad-max.co/en/article/editorial-50-000-cameras-piratees-par-moscou-en-europe-la-cyberguerre-a-change-d

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Editorial3 reads2406 words16 min read