🔴 [LATEST] THEGARUDAEYE TAKES DOWN PARAGUAY'S IMMIGRATION SERVER FOR 12 HOURS    ◆    🔴 [LATEST] THEGARUDAEYE DOWNS PARAGUAY FOREIGN MINISTRY OVER TRUMP’S BOARD OF PEACE    ◆    🔴 [LATEST] NONAME057(16) DDOS CAMPAIGN TARGETS GERMAN FERRY AND CITY SERVICES    ◆    🔴 [LATEST] CHAT CONTROL PROTEST: RIPPERSEC BREACH ITALIAN SCADA SYSTEM    ◆    🔴 [LATEST] ANGMAR MEDICAL BREACH & BEACON HACK EXPOSE 710GB DATA

[ SYSTEM_MENU ]

> ESTABLISH_CONNECTION

[ X_TWITTER ] [ TELEGRAM ] [ INSTAGRAM ] [ THREADS ] [ UPSCROLLED ]

CYBERASIA INTEL
Independent portal uncovering global cyber warfare operations, tracking APTs, and reporting zero-day vulnerabilities.

~/SCADA & IoTarticle

SCADA & IoT

NoName057(16) Romania CCTV Hack: Hacktivists Spy on Tom Tailor Store

> By Haider | Aug 10, 2026 | 4 min read

Threat intelligence analysts have identified a disturbing NoName057(16) Romania CCTV hack targeting commercial retail spaces. The notorious pro-Russian hacktivist group, traditionally known for executing volumetric DDoS campaigns, has shifted tactics to compromise physical video surveillance systems within Romania.

⚠️ THREAT INTELLIGENCE ADVISORY:
The threat actor has achieved unauthorized access to the CCTV network of a Tom Tailor clothing store franchise in Romania. The leaked footage demonstrates active monitoring capabilities over staff, customers, and sensitive areas including warehouses and fitting rooms.

NoName057(16) Romania CCTV hack
> TABLE_OF_CONTENTS [toggle]

Geopolitical Motivation Behind the Attack

In a public statement released on their primary Telegram channel, NoName057(16) explicitly tied this cyber attack to geopolitical grievances. The group cited Romania’s ongoing political support for the Kyiv regime and its continued supply of weapons to Ukraine as the primary justification for targeting Romanian commercial facilities.

This NoName057(16) Romania CCTV hack represents a calculated attempt at psychological warfare. By shifting focus from state-level infrastructure DDoS attacks to spying on ordinary citizens in commercial spaces, the group aims to instil fear and demonstrate pervasive reach. The actor mocked the contrast between peaceful commerce in Romania and the ongoing conflict in Eastern Europe.

Technical Analysis of the Surveillance Breach

While the threat actor did not disclose the specific exploitation vector, mass compromises of commercial CCTV systems typically exploit systemic vulnerabilities in edge network devices. Retail franchises frequently deploy interconnected Digital Video Recorders (DVRs) or Network Video Recorders (NVRs) to centralize security monitoring.

These devices are often left exposed on the public internet (discoverable via scanning engines like Shodan) with default administrator credentials or unpatched firmware vulnerabilities. Once an attacker gains access to the NVR dashboard, they inherit unmitigated visibility into all connected camera feeds across the facility.

Impact Assessment: Severe Privacy Violations

The severity of this incident is classified as High. Unlike traditional data exfiltration involving financial records, this breach involves severe physical privacy violations. The threat actor explicitly highlighted their access to fitting rooms, escalating the ethical and legal implications of the attack.

Retail operators face significant regulatory backlash under the General Data Protection Regulation (GDPR) when physical surveillance systems are compromised by unauthorized third parties.

Mitigation & Prevention Strategies

Commercial operators utilizing networked CCTV systems must treat this incident as a critical warning. We recommend implementing the following defensive postures immediately:

  1. Remove Internet Exposure: Ensure that NVR and DVR administrative interfaces are strictly inaccessible from the public internet. Access should require an encrypted Virtual Private Network (VPN) tunnel.
  2. Credential Hygiene: Audit all surveillance hardware to ensure default manufacturer credentials (such as admin/admin) have been completely removed and replaced with complex passwords.
  3. Network Segmentation: Isolate all IoT and physical security devices on a dedicated Virtual Local Area Network (VLAN). This prevents attackers who compromise a point-of-sale (POS) terminal from pivoting laterally into the camera network.
  4. Firmware Audits: Regularly patch camera and recording hardware to eliminate known Common Vulnerabilities and Exposures (CVEs) exploited by hacktivist groups.

CyberAsia continues to monitor pro-Russian hacktivist campaigns targeting European infrastructure. Read our latest Cyber Attack analysis for more updates on geopolitical cyber warfare.

Reference: Romanian National Cyber Security Directorate (DNSC).

> DISCLAIMER

The information provided in this article is for educational and threat intelligence purposes only. CyberAsia does not condone, promote, or encourage any illegal activities, including data breaches or unauthorized access to systems. The claims made by threat actors are unverified and reported strictly for awareness and defensive mitigation.


> subscribe_to_intel

Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.

> establish_connection:
[X/Twitter]
[Telegram]

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing NoName057(16) Romania CCTV Hack: Hacktivists Spy on Tom Tailor Store is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.

> share_intel.sh [ X ] [ TG ]

> ABOUT_AUTHOR: Haider

Lead Security Researcher & Malware Reverse Engineer specializing in deconstructing APT toolkits and validating underground breach claims.

> related_intel --suggest