TLDR: New speed cameras in Slovakia contained an undocumented module that allowed them to be controlled remotely and granted full access to them via mobile network. All it took to activate it was to send a text message from one of 12 Russian numbers.

Further context:

Cameras purchased by Slovakia’s Interior Ministry for road surveillance have been traced to a Cypriot shell company [Sodasus Ltd] with no business history, with the only identifiable trail leading back to Russia, raising serious security concerns about the procurement.

Article translation:

The cameras installed by the Ministry of the Interior along Slovakia’s roads were, in fact, entirely Russian-made. They even contained 12 Russian telephone numbers that could be used to hack directly into the cameras and view the footage.

This was highlighted by the opposition movement Progressive Slovakia, which claims that Interior Minister Matúš Šutaj Eštok was misleading the public when he claimed at a press conference last week that only certain parts of the speed cameras were Russian. Progressive Slovakia cites an assessment by the National Security Authority, which the movement obtained via a freedom of information request.

A backdoor for foreign espionage

On Friday, the National Security Authority issued its own assessment of the radars. Based on this assessment, Peter Bátor, a security expert with the movement, described the mechanism by which, in his view, it was possible to access data from the radars under test. According to him, all it took was to send a message to one of the pre-set telephone numbers, enter a password, and the attacker gained full access to the camera. This is because the devices contained a module that is not documented anywhere; it was retrofitted into the device and is hard-coded in such a way that it cannot be removed or altered.

“This is a very specific example of how Russia uses the technology it sells for espionage,” said Bátor, adding that twelve Russian telephone numbers were linked to this undocumented module. Any one of them was sufficient for an unauthorised operator to gain full control of the camera. Furthermore, the device also had built-in administrator access with a precisely defined password. According to the findings, it was therefore possible to control the camera not only via a standard 3G or 4G port, but there were many more connection options available.

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 days ago

    So, not to diminish the specific case here, but there’s also a broader problem of IoT cameras having chronic security issues. There have also been plenty of major examples of this being exploited in important ways.

    https://en.wikipedia.org/wiki/2025_Louvre_heist

    Other security lapses came to light in the aftermath, including insufficient CCTV coverage with only 39% of the museum’s rooms being monitored by cameras, and the CCTV in the Apollo Gallery facing the wrong way.[6] A 2014 audit by France’s National Cybersecurity Agency had warned the museum about serious security flaws, including the use of “trivial” passwords and outdated software.[7] It was reported that the password to get into the surveillance system was “Louvre”.[8][9]

    https://www.wired.com/story/from-ukraine-to-iran-hacking-security-cameras-is-now-part-of-wars-playbook/

    From Ukraine to Iran, Hacking Security Cameras Is Now Part of War’s ‘Playbook’

    New research shows hundreds of attempts by apparent Iranian state hackers to hijack consumer-grade cameras, timed to missile and drone strikes. Israel, Russia, and Ukraine have also adopted this trick.

    https://chinaobservers.eu/the-invisible-risks-of-insecure-chinese-surveillance-cameras/

    The Invisible Risks of Insecure Chinese Surveillance Cameras

    Although security cameras make up only 5 percent of Enterprise Internet of Things (IoT) devices, they account for 33 percent of all security issues. Two Chinese suppliers – Hikvision and Dahua – dominate international markets due to their competitive prices and product features. Our recent study shows that both of these brands are easily exploitable and slow to repair reported vulnerabilities.

    This last one is really where I think most of the risk is. Not so much risk from China-as-a-state—though as the article points out, that can also be a risk—but that inexpensive cameras are a major source of not-updated, sensor-connected, and Internet-connected devices. If they aren’t maintained, sooner or later, they’re liable to be compromised by someone.

    And there’s an even broader issue with IoT devices in general that aren’t maintained, but cameras are an issue in-and-of themselves because they provide access to sensors themselves.