Slovakia just switched off 279 brand-new traffic cameras because they were quietly wired to answer to Moscow.
The country's national security service, the NBU, found that a batch of NERO R-ONE speed cameras deployed as part of a 30 million euro EU-funded modernization project are rebranded CORDON PRO.M units made by Semicon, a St. Petersburg firm. The cameras shipped with a hardcoded list of Russian phone numbers that could trigger shell and network access over SMS. SecureBoot on the devices didn't actually work, and the web management portal exposed live camera feeds to anyone who had the IP address, no password required. The units reportedly reached Slovakia through a Cyprus-based shell company using fake certifications, and the Ministry of the Interior has now deactivated every camera that was installed.
This isn't just a buggy IoT gadget story. It's a public-safety system, bought with EU money, that let a foreign government potentially reach into national infrastructure on demand. The laundering through a Cyprus shell company suggests this wasn't sloppy vetting so much as a deliberate effort to dodge scrutiny of the supply chain, the same blind spot that has burned governments buying Huawei gear or unvetted networking hardware. Investigators say Croatia and other Eastern European countries may be running similar hardware without knowing it yet.
Slovakia's government, led by the Russia-friendly Robert Fico, initially denied the cameras had any Russian origin at all. It took pressure from the opposition to force the NBU investigation that proved otherwise, which says a lot about how this almost stayed quiet.