The Infrastructure Hijack: Why 2026 Marks the End of Passive State Espionage
Recent escalations by Russian and North Korean actors demonstrate a pivot from silent data theft to active infrastructure weaponization, using everything from IoT cameras to software vendors.
The distinction between cyber espionage and cyber warfare has effectively vanished. This past week, a series of revelations regarding Russian and North Korean operations has confirmed a chilling trend: nation-state actors are no longer just watching; they are operationalizing our own infrastructure against us.
The Infrastructure Hijack: 87,000 Eyes in the Dark
The most striking development comes from a joint intelligence report detailing a massive Russian campaign. The FSB’s 16th Centre has systematically hijacked over 87,000 internet-connected security cameras across the EU and Ukraine. This isn't just about privacy; these feeds are being fed into image-recognition AI to track military transport routes and weapon shipments. In Ukraine, this has transitioned into kinetic warfare, with camera data being used to neutralize personnel. The 'unseen' adversary is now literally using our own sight against us.
The Vendor Pivot: APT43’s New Playbook
Simultaneously, North Korean actor Kimsuky (APT43) has shifted its focus toward the 'vendor pivot.' By compromising South Korean collaborative software and SaaS providers, they aren't just stealing code—they are harvesting employee credentials and server information to launch downstream attacks on the vendors' entire customer base. This follows the 'Salt Typhoon' pattern we saw with telecom breaches, proving that the supply chain is now the preferred highway for state-sponsored persistence. If you own the vendor, you own the customer.
Why This Matters for Global Security
We are witnessing the 'pre-positioning' phase evolve into 'active leverage.' When a state actor controls your CCTV or your SaaS provider, they do not need to hack you directly. They already own the environment you trust. UK NCSC CEO Richard Horne recently noted that 75% of major incidents are now state-linked. This is no longer a 'risk to be managed' but a 'contest to be fought' where the terrain is our own digital architecture.
Strategic Recommendations for Leaders
- Aggressive IoT Hardening: The 87,000-camera breach relied on default passwords and obsolete firmware. If a device is internet-facing, it must be treated as a Tier-1 risk, isolated by VLANs, and audited weekly.
- Vendor Trust Verification: It is no longer enough to trust a vendor’s security. Organizations must demand transparency into vendor access controls and assume that any third-party software is a potential entry point.
- Continuous Threat Hunting: Legacy defense-in-depth is failing against 'living off the land' techniques. Teams must hunt for anomalous lateral movement and credential usage rather than just scanning for malware signatures.
Outlook
The remainder of 2026 will likely see more 'Infrastructure-as-a-Weapon' (IaaW) scenarios. As geopolitical tensions rise, expect state actors to flip the switch from silent monitoring to active disruption. The perimeter hasn't just moved; it has been integrated into the adversary's arsenal. Defensive strategy must now assume the internal environment is already contested.

