The Slovak cameras that keep phoning home

In August 2026, Slovakia’s national security authority (NBU) dropped a security alert that reads like a spy novel with a very mundane punchline: the speed cameras the government bought to catch speeders contain a backdoor that lets someone back in Russia take control of them with a text message.

Speed camera in Mount Rainier, Maryland capturing a speeding car on a public road
Image: Speed camera capturing a violation in Mount Rainier, Maryland via Wikimedia Commons (Public domain)

The cameras, NERO R-ONE high-speed units, were part of a €30 million EU-funded project to rebuild the country’s national traffic monitoring system. The interior ministry allegedly bought 279 of them. And according to the NBU, they were not what they seemed.

This is not a distant, abstract warning from threat researchers. It’s a concrete, named, physical example of state-sponsored tampering buried inside bought hardware. And as someone who spends my days inside a government ICT division, it hit close to home in a way few stories do.

What the NBU found inside

The NBU’s technical report identified an undocumented module tied to a list of hardcoded Russian phone numbers. Send an SMS to the camera from one of those numbers, and the device grants shell and network access. With a password, that becomes full remote control.

Security expert Peter Bátor, who reviewed the findings, said nine of the numbers were mobile numbers from the St Petersburg area, two were St Petersburg landlines, and one was a mobile number from the Kemerovo region. Using one of the pre-set numbers plus a password, an operator could fully control a camera.

The devices turned out to be a rebranded version of a Russian speed camera model called CORDON PRO.M, produced by St Petersburg-based firm Semicon. They were bought through a no-bid direct deal with Sodasus, a Cyprus shell company that Slovak media linked to fake certifications.

Worse than a single backdoor

The backdoor is the headline, but the NBU catalogued a longer list of problems that stack on top of it.

The cameras ship with a crucial SecureBoot feature turned off, which means the firmware’s origin is never enforced. The web management portal contains multiple vulnerabilities. And the devices expose their live streams to anyone without a password who knows the broadcasting IP.

That last point is the one that should worry people most. A backdoor behind an SMS gate is on by default. A live camera feed anyone on the internet can pull if they know an IP is a surveillance network with the door left open.

Analyst Vladimír Bednár noted that Russia has already used access to cameras in Ukraine to help plan attacks and assess their results. In the Slovak case, the risk is serious because the devices contain remote-access mechanisms built in from the factory, rather than requiring an attacker to first hack in.

The politics did not help

What makes this story better than most is how quickly the blame game started. The interior ministry initially denied the cameras were Russian and insisted there was no risk of data theft because they sat on a closed-loop police network.

Then Prime Minister Robert Fico dismissed the whole thing. “I’m holding my stomach when someone tells me that two road cameras are supposed to threaten the security of the Slovak Republic,” he said, adding that it “makes absolutely no difference what components they have.” He compared the cameras to spy satellites, which he argued were a bigger threat.

Security experts pushed back. Former Czech intelligence chief Petr Mlejnek pointed out that satellites and roadside cameras give different, complementary intelligence. A satellite can spot a convoy; a network of cameras can reconstruct exactly where vehicles came from, when they crossed a border, and where they went.

The opposition party Progressive Slovakia, which obtained the NBU assessment through a freedom-of-information request, called for the interior minister’s dismissal and said it would file a criminal complaint. The ministry eventually paused deployment, ordered the two test devices removed, and said it would bring in an independent auditor.

Why this should matter in Manila

It’s tempting to file this under “another European country’s problem.” But I think this is exactly the kind of story that a government IT team anywhere in the world should read twice.

Because here’s the uncomfortable truth: every procurement office that buys connected hardware is a potential candidate. Cameras, access control panels, network gear, even smart displays in meeting rooms. The plug-and-play convenience that makes these devices attractive is the same convenience that makes them hard to audit.

The three things that failed in Slovakia are the same three things that fail in underfunded IT divisions everywhere. The buyer trusted the vendor’s certifications instead of verifying the hardware. The default security features were left on unsafe settings. And the “closed network” reassurance was treated as a guarantee when it should have been treated as a claim to test.

The supply chain is the attack surface

The CORDON PRO.M story fits a pattern I have written about before. Not long ago I covered how a jscrambler supply chain attack slipped malicious code into software that thousands of developers ran without thinking. And I put together a practical guide to detecting compromised npm packages because the threat is now routine.

Software supply chains get the attention because they’re easier to weaponize at scale. But hardware is the older, and in some ways scarier, cousin. A malicious npm package can be pulled with a lockfile update. A malicious chip or firmware needs a teardown to find, and most organizations never do one.

There is a hard lesson here about treating vendor claims as auditable facts rather than sales copy. Slovakia’s ministry was told the cameras were safe on a closed network. The NBU found they were speaking to Russian phone numbers over the linked config. Those are two very different pictures of the same device.

What I’d actually do about it

If I were advising a government agency or even a small business that just bought a batch of smart devices, I would not frame this as a reason to panic. I’d frame it as a reason to do a few boring, valuable checks.

First, verify the origin story. A supplier that can’t explain, in writing, where the hardware was manufactured and who controls the firmware is a supplier you shouldn’t be staking your network on. The Cyprus shell company with fake certifications is the kind of detail that a two-hour background check would have caught.

Second, check the defaults. SecureBoot should be on. Management interfaces should not be internet-facing. Passwords should be changed the day a device lands on your network, not whenever someone gets around to it. When I wrote about AMD quietly disabling memory encryption, the lesson was the same: security guarantees only count if they’re actually switched on.

Third, test the “closed network” claim. If a system communicates only with the police network, prove it. Put a device behind a monitor and watch what it phones home to. The gap between what the docs say and what the traffic shows is where backdoors live.

The bigger picture around trust and state power

There’s also a geopolitical thread worth pulling. We’ve seen a lot of writing about private firms launching offensive cyber operations and how capability spreads beyond nation-states. This story is the flip side: a state embedding surveillance into equipment it sells abroad, quietly, as a product.

The NBU warning didn’t just name NERO R-ONE. It also flagged Cordon-series speed cameras manufactured by Simicon in Russia and Cordon-series units from NEROline in Croatia, and advised affected organisations to identify them and contact the authority.

For anyone building trust decisions around hardware, the takeaway is to think about who has a motive to put a backdoor in the box, not just who has the technical skill. The vendor with political ties to an adversary is a risk factor that no firewall can fix.

And while all of us in IT think about security in the age of AI agents, it’s worth remembering that the old attacks never went away. They just moved into cheaper, dumber hardware where nobody is looking.

Bottom line

Slovakia did the right thing, eventually. It halted the rollout, pulled the test units, and called in an independent auditor. The fact that it took an opposition party filing a freedom-of-information request to surface the NBU’s findings says a lot about how hard it is to scrutinize government procurement in practice.

But the larger lesson is not about Slovakia, or Russia, or speed cameras specifically. It’s about the assumption that hardware you buy is hardware you can trust. That assumption is expensive to verify, and very expensive to skip. If a government that spent €30 million on traffic enforcement didn’t catch a backdoor until an opposition party took a look, the rest of us should assume our own procurement is only as clean as the checks we actually run.

Filed under Tech & Gadgets
Last Update: August 24, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted