TechNewsReel
Live

Slovakia Finds Russian Backdoor in Traffic Speed Cameras

Authorities discovered rebranded Russian hardware in a no-bid procurement deal allowed remote control via SMS.

TechNewsReel Newsroom · August 23, 2026

Slovakian authorities have uncovered a Russian-linked backdoor embedded in newly acquired traffic speed cameras. The discovery exposes a critical security breach in national infrastructure and highlights the risks of opaque government procurement processes.

The National Security Authority (NBU) identified the vulnerability in NERO R-ONE speed cameras, which were found to be rebranded versions of the Cordon.Pro.M produced in St. Petersburg, Russia. According to the NBU, the hardware contains undocumented Russian-linked modules that allow the devices to be remotely controlled via SMS commands sent from specific Russian telephone numbers.

Procurement Failures

The investigation was triggered by reports regarding the cameras' acquisition, which was conducted through a no-bid deal with Sodasus, a shell company based in Cyprus. Investigators found that the procurement process involved the use of fake certifications to bypass standard security screenings. Subsequent analysis by the NBU confirmed that the devices were not the independent products they were marketed as, but were instead rebranded Russian hardware.

Infrastructure Risks

This incident underscores the severe risk of state-sponsored hardware implants within the critical infrastructure of a NATO and EU member state. By embedding backdoors at the hardware level, a foreign power gains a persistent foothold that is significantly harder to detect than software-based malware. In the context of traffic monitoring, such access could potentially allow an adversary to track the movement of specific individuals, monitor strategic traffic patterns, or disrupt transportation networks during a crisis.

Geopolitical Implications

The breach occurs amid heightened geopolitical tensions in Eastern Europe, where the vulnerability of government supply chains has become a primary security concern. The use of a Cyprus-based shell company to mask the origin of the hardware is a common tactic used to circumvent sanctions and security audits, demonstrating how adversarial states can exploit corporate loopholes to penetrate Western infrastructure.

Next Steps

Slovakian authorities are now assessing the full extent of the deployment and whether other infrastructure components sourced through similar channels have been compromised. While the NBU has flagged the NERO R-ONE cameras, the incident is expected to prompt a broader review of no-bid contracts and the verification processes for hardware certifications across the region.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.