Traffic Technology TodayTraffic Technology Today
  • News
    • A-D
      • Appointments & Staffing
      • Artificial Intelligence (AI)
      • Asset Management
      • Autonomous Vehicles & ADAS
      • Awards
      • Cloud Computing
      • Congestion Reduction
      • Connected Vehicles
      • Covid-19
      • Cybersecurity
      • Deals, Acquisitions & Mergers
    • E-J
      • Electric vehicles & infrastructure
      • Emissions & Low Emission Zones
      • Enforcement
      • Event News
      • Funding
      • Incident Detection
      • Infrastructure
      • Intersections & Traffic Signals
      • ITS
    • K-S
      • Legal / Government Regulation
      • Machine Vision / ALPR
      • Mapping, Modelling & Navigation
      • Mobility as a Service
      • Multimodality & Micromobility
      • Planning, Testing, R&D
      • Public transit
      • Safety
      • Smart Cities
      • Smart Parking
    • T-Z
      • Tolling
      • Traffic counting & categorization
      • Traffic Management
      • Traveler Information Systems
      • Variable Message Signs
      • Vulnerable Road Users
      • Weather systems
  • Features
    • Features
    • Opinion
  • Online Magazines
    • Recent Issues
    • Archive List
    • Pre-2016 Issue Archive
    • Subscribe Free!
  • Video & Audio
    • Video
    • Audio
  • Podcast
  • Events
  • Webinars
  • Technology Profiles
LinkedIn YouTube X (Twitter)
LinkedIn YouTube X (Twitter)
Subscribe >
Traffic Technology TodayTraffic Technology Today
  • News
      • Appointments & Staffing
      • Artificial Intelligence (AI)
      • Asset Management
      • Autonomous Vehicles & ADAS
      • Awards
      • Cloud Computing
      • Congestion Reduction
      • Connected Vehicles
      • Cybersecurity
      • Deals, Acquisitions & Mergers
      • Electric vehicles & infrastructure
      • Emissions & Low Emission Zones
      • Enforcement
      • Event News
      • Funding
      • Incident Detection
      • Infrastructure
      • Intersections & Traffic Signals
      • ITS
      • Legal / Government Regulation
      • Machine Vision / ALPR
      • Mapping, Modelling & Navigation
      • Mobility as a Service
      • Multimodality & Micromobility
      • Planning, Testing, R&D
      • Public transit
      • Safety
      • Smart Cities
      • Smart Parking
      • Tolling
      • Traffic counting & categorization
      • Traffic Management
      • Traveler Information Systems
      • Variable Message Signs
      • Vulnerable Road Users
      • Weather systems
      • Work zones
  • Features
    • Features
    • Opinion
  • Online Magazines
    1. Recent Issues
    2. Archive List
    3. Pre-2016 Issue Archive
    4. Subscribe Free!
    Featured
    July 23, 2026

    NEW ISSUE: Read the July/August 2026 edition of TTi magazine online now!

    Artificial Intelligence (AI) By Tom Stone
    Recent

    NEW ISSUE: Read the July/August 2026 edition of TTi magazine online now!

    July 23, 2026

    NEW ISSUE: Read the April/May 2026 edition of TTi magazine online now!

    April 21, 2026

    NEW ISSUE: Read the February/March 2026 edition of TTi magazine online now!

    February 25, 2026
  • Video & Audio
    • Video
    • Audio
  • Podcast
  • Events
  • Webinars
  • Technology Profiles
LinkedIn YouTube X (Twitter)
Traffic Technology TodayTraffic Technology Today
Cybersecurity

FEATURE: How did Iran’s traffic cameras get hacked?

Christopher Court-DobsonBy Christopher Court-DobsonAugust 3, 202614 Mins Read
Share LinkedIn Twitter Facebook Email
An illustration of a man in a hood sitting at a laptop, face on, with lines of green zeros and ones falling down behind him over a city street with traffic lights visible
Traffic camera networks are a new target for hackers (Illustration: AdobeStock/Anna Davie)

ITS was thrust to the forefront of global affairs earlier this year, as traffic cameras were revealed to be a key point of vulnerability for Iran. Christopher Court-Dobson asks, how did Israel hack Iranian traffic management? And are current cybersecurity systems and legislation sufficient to protect other countries from such attacks?

This article was first published in the July/August edition of TTi magazine

On the morning of 28 February 2026, a joint US-Israeli strike killed Iran’s Supreme Leader Ali Khamenei at his compound in central Tehran. And it was traffic cameras that provided Israeli intelligence with all the information they needed to pinpoint his whereabouts. A senior Israeli intelligence official described knowing Tehran “like we know Jerusalem” – a picture built over years via its Unit 8200 and Mossad intelligence units.

AI-assisted analysis allowed Israel to use the cameras to map out a comprehensive ‘life pattern’ for Khamenei and his inner circle. The irony is that it was Iran’s own surveillance state that required centralised access to camera feeds and made them easier to hack. It was optimised for exactly the kind of bulk data collection that its adversary wanted to perform. Had the network been properly segmented with encrypted transmission to authenticated endpoints, the hack would have been harder.

There was also a lack of cybersecurity awareness in Iran. Israel’s surveillance operation had be running for years indicating that Iran had insufficient anomaly detection. Either there was no monitoring of outbound data or encryption was used to make the leak indistinguishable from legitimate traffic.

In the rest of the world the Iran strike is bringing into focus previously overlooked vulnerabilities in systems thought to be too dull, too complex, or too patchwork, and making them a new priority for security-minded decision-makers. Across Europe, traffic agencies are doubling down on their cybersecurity role, and the USA’s CISA predicts with high confidence that state-backed agencies are ‘pre-positioning’ within existing networks, bringing cybersecurity to the forefront of operations.

“The transport system must be evaluated with the same critical rigour as any other critical infrastructure, particularly from a cybersecurity perspective,” says Ari Kallio, senior specialist at Traficom, Finland’s combined Traffic and Communications Agency. “When conducting these evaluations, it is essential for European nations to prioritise strict system compliance and ensure comprehensive overall security.”

Apocalyptic scene with a road flyover on fire
The Iran war revealed how ITS networks can be hacked for military aims (Image: AdobeStock)

While Western states may take comfort from Iran’s apparent lack of cybersecurity awareness, it is dangerous to be complacent. The specific enabling factor in Iran – centralised, always-on, remotely accessible camera feeds – is not unique to authoritarian surveillance states. It describes a large proportion of modern Western traffic management infrastructure. Urban traffic management centres (TMCs) aggregate feeds from hundreds or thousands of cameras. Many systems allow remote access for maintenance and monitoring. Cloud-based video analytics platforms, increasingly common in smart city deployments, are architecturally similar to what Iran had, just with different intended uses.

However, there are some differences: while the lack of ITS interoperability is often bemoaned by those wishing to see greater efficiency and usability of systems, it is paradoxically the patchwork nature of Western ITS – multiple vendors, multiple protocols, inconsistent integration – that does in fact provide some incidental protection. A unified, centrally accessible system is easier to exploit at scale than a messy ecosystem of incompatible components. This cuts both ways, of course: fragmentation also makes systematic security upgrades harder.

“Our approach means every cabinet has a network that we can then control using AI, and that also helps us to detect threats generated by AI in ‘zero-day’ attacks”

Wolfgang Bloem, head of research and development, Swarco

Western systems are also now being increasingly governed by formal cybersecurity requirements, such as the EU’s NIS2 directive, which has required commercial platforms used to receive security patches. Iranian infrastructure, particularly older layers, may have been running unpatched or custom systems with no vendor support.

In the West private sector vendors are finding themselves at the sharp end, with increasing demands for end-to-end security. “Traditionally, cybersecurity was not a major focus in the ITS industry,” says Wolfgang Bloem, head of research and development at Swarco. “There was always reliance on air gapping and physical security, with the hope that these measures would be sufficient. However, with the introduction of EU directives like NIS2, our customers are starting to ask more questions.”

Swarco itself is able to deliver some of the most cutting-edge cybersecurity solutions available on the market with all communication points such as vehicles, traffic lights, and roadside infrastructure secured using a Public Key Infrastructure (PKI), ensuring that only authenticated and trusted messages are accepted (see Points of Vulnerability, below, for more)

A CCTV camera in an indoor concrete location like a car park with green back light and a blue light in the camera lens
The ubiquity of traffic cameras makes them an ideal surveillance network (Image: AdobeStock)

Physical air-gapping, that is keeping all or parts of the roadside unit (RSU) completely disconnected from the wider network, used to be the go-to solution. Many ITS components were effectively air gapped by default – traffic controllers, tunnel management systems, variable message signs, etc were built on proprietary protocols and closed networks with no expectation of internet connectivity.

As ITS has matured, however, connectivity (V2X; real-time data; C-ITS etc) has become central to its value proposition. That connectivity progressively erodes the conditions under which air gapping was ever viable, and it means the attack surface for critical transport infrastructure has expanded dramatically. “Air gapping was great in the last 20 years. But now, things are changing,” says Bloem.

Legislation

The inadequacy of legacy cybersecurity systems is addressed by the EU’s NIS2 directive (which came into force in October 2024 for member states that transposed it on time). It lists transport as a critical sector and mandates stricter incident reporting, risk management, and supply chain security. Non-compliance risks fines, and senior management can be held liable.

NIS2 implicitly challenges air gapping as a sufficient defence by requiring a risk-based approach to security, pushing ITS operators towards layered systems that don’t rely on any single control. It now must include patching regimes, network monitoring, incident response plans, and supply chain vetting.

“Air gapping is certainly still relevant, and it was the solution number one in the past. But it is becoming increasingly difficult to implement in practice, due to modern control methods in traffic engineering,” says Bloem. “AI based models and digital twins, are highly data driven. Where you put together data from various sources, it makes it extremely hard to still have everything 100% air gapped. Now, with NIS2 and all these regulations, we also have to monitor the systems and over the air update the systems.”

A hooded man sits at computer screens in a dark room
Armed with just a computer, hackers are able to inflict serious damage on targets anywhere in the world (Image: AdobeStock)

“The transport system must be evaluated with the same critical rigor as any other critical infrastructure, particularly from a cybersecurity perspective” 

Ari Kallio, senior specialist, Traficom, Finland

Swarco actively participates in certification and standardization committees at EU level, collaborating even with competitors to raise overall security requirements for highway and connected mobility projects. Another significant piece of EU regulation now coming into force is the Cyber Resilience Act (CRA) mandating cybersecurity for products with digital elements (e.g. smart devices, software). It requires security-by-design, vulnerability handling, and transparent reporting across the product lifecycle. Products must carry a CE mark to show compliance.

The CRA fills gaps left by NIS2, which focuses on entities and networks, by regulating hardware and software before sale. Non-compliance can lead to fines or market withdrawal, ensuring both manufacturers and supply chains are accountable for digital product safety.

The legislation pushes public agencies like Finland’s Traficom into a level of hands-on involvement that would have been unthinkable a decade ago. “The organization’s scope of responsibility has expanded significantly following the implementation of the NIS2 Directive and the subsequent enactment of our national Cybersecurity Act,” says Traficom’s Ari Kallio.

The regulatory burden on companies and municipalities is high – simply understanding what the obligations are, and the risks of non-compliance, is a huge job. Coming up with the best, most creative, efficient ways to deal with them is another. But the new digital landscape has created a lot of opportunity for vendors who promise to reliably ease that regulatory burden on behalf of their clients.

An aerial shot of a city road junction at night in Olsztyn
The Polish city of Olsztyn lost control of its traffic lights and public transit ticketing during a single cyberattack (Image: AdobeStock)

‘’NIS2 and CRA lead to a certain diversification and shift within the industry. But it becomes increasingly difficult for smaller companies to keep up with these complex regulations,’’ says Bloem.

For legacy infrastructure that was designed around isolation, this creates a significant compliance and engineering challenge – particularly for smaller road authorities who may never have had dedicated cybersecurity personnel. “As operators of critical infrastructure, they often realize they do not have the proper security solutions in place,” says Bloem

AI sword and a shield

Threat actors are integrating AI to improve effectiveness, stealth, and adaptability. Some advanced persistent threats (APTs) and cybercrime groups are using AI for automated reconnaissance – scanning targets, identifying vulnerabilities, and deploying malware with minimal human involvement.

“Highly complex and interconnected systems inherently introduce novel risk factors. This is particularly evident during the early stages of technological rollout, when the industry has not yet established standardized security practices and mature protocols,” says Kallio.

But AI is also a shield and enables entirely new methods of network monitoring, and a potent, dynamic, flexible alternative to conventional antivirus software. “Our approach means every cabinet has a network that we can then control using AI, and that also helps us to detect threats generated by AI in ‘zero-day’ attacks,” says Bloem.

And it is ‘zero-day’ attacks, meaning ones that exploit previously unknown vulnerabilities, which are most devastating for critical infrastructure. These are exactly the sorts of exploits that state-backed actors are most likely to deploy.

A traffic camera with a blurred road scene behind it
Behind every traffic camera there is a digital network that must be protected with up-to-date cybersecurity (Image: AdobeStock)

“The traditional antivirus software is usually working on matching patterns to fingerprints that they have stored in their database. This is not how the machinelearning models work. They are instead looking into what is expected to be a normal behaviour on the network,” says Bloem.

RSUs are a perfect environment to push these novel AI based protection techniques. Unlike a PC which is frequently changing with new software and system updates, there is a definite baseline of how the miniature network is supposed to operate. This makes it easier to spot even very subtle variations that could be signs of a malicious attack.

A CCTV camera high on a building in an urban setting
Image: AdobeStock

“One of the advantages is that we are in an environment where we know what normal means. AI has certainly brought a new level of sophistication to attack scenarios. There is a general consensus on this within the cybersecurity community and a topic of constant and intense discussions everywhere around the world, and not only in our industry,” says Bloem.

Cybersecurity now

The need for enhanced cybersecurity has been noted, discussed and planned for at the highest level. The ongoing barrage of cyberattacks and a world of increasing interstate conflict is bringing a security dimension to almost every aspect of technology and daily life.

While the Iran operation required years of sustained intelligence effort against a specific high-value target and with a level of investment only usually achievable by state-level adversaries it nevertheless exposes a tension that is directly relevant to Western ITS: the more useful you make a camera network (the more you centralise it, connect it, make it analytically powerful) the more valuable and accessible it becomes to an adversary.

The answer isn’t to avoid connectivity – that ship has sailed – but to design security in from the start. The Iranian network wasn’t insecure because Iran was an authoritarian state; it was insecure because the security architecture didn’t match the threat model. That’s a mistake Western operators are entirely capable of making.

Technological advances, security, and comprehensive EU-wide legislation is driving immense change, and old assumptions fall by the wayside. The roles and function of traffic agencies increasingly overlap with communications, which itself is increasingly overlapping with national security considerations. Meanwhile, in the private sector, vendors are now undoubtedly called upon to deliver robust cybersecurity in a rapidly evolving landscape.

7.5%

The percentage of all cyberattacks in the EU that were targeted at transportation in 2025, making it the second most attacked sector 

Source: Cyble


Points of vulnerability

Modern ITS is a complex beast composed of many overlapping layers. All of these present a potential vector of attack for a hostile actor. A hacker getting control of the TMC could shut down a city in a short space of time.

“The first layer is the central traffic management system – MyCity in our case. This is either operated directly within the data centre, or cloud based,” says Bloem. “The second component is the roadside controllers that are installed everywhere on the streets. They comprise local networks with edge controllers and integrated devices like traffic cameras, lidar using devices to communicate between the infrastructure and vehicles.

“The connecting glue between both is the network, and it sits in between the central management system and the roadside devices and their network layer, and this is a wide area network, which is again something, which you typically rely on third party companies to provide,” says Bloem.

Swarco’s security framework spans application, network, information, and operational layers, underpinned by structured business continuity and disaster recovery planning. The company embeds the four foundational principles of cybersecurity – confidentiality, integrity, availability, and authenticity – at the architecture level. In practice, this means Transport Layer Security (TLS) encryption for data in transit and at rest, certificate-based integrity validation, round-the-clock system monitoring, and multifactor authentication as standard access control.

Swarco’s MyCity, developed by an ISO/IEC 27001-certified entity, follows international security standards, with dedicated teams conducting recurring penetration tests and security assessments to proactively identify and close vulnerabilities.

30% 

The increase in investment in cybersecurity for the road sector in 2024, making it the fastest growing of any transport mode 

Source: Rinnovabili


2023 OLSZTYN CYBERATTACK

In 2023, the Polish city of Olsztyn became one of the starkest recent examples of what a successful cyberattack on integrated urban traffic infrastructure actually looks like on the ground.

Olsztyn had built a reputation as one of Poland’s more technologically advanced cities, operating a traffic management centre that coordinated signal control across nearly a hundred intersections in the city centre, alongside integrated public transport ticketing and intersection monitoring systems.

When attackers hit the network, the effects were immediate and physical. Traffic lights across the city centre were disrupted, major jams formed on arterial roads, and residents found themselves unable to purchase public transport tickets. The city’s transport authority, ZDZiT, was left with no sophisticated remediation option – its response was to physically disconnect its servers from the network to stop the attack spreading further.

The incident is significant beyond its immediate disruption. Olsztyn was not a soft target chosen for weak defences – it was targeted precisely because its systems were connected and integrated. The attack demonstrated that smart city investment, without equivalent investment in cybersecurity, simply enlarges the attack surface available to adversaries. No attribution for the attack was ever made, but Poland has been under constant pressure from pro- Russian hackers.

38% 

The percentage of cyberattacks that are ransomware, making it the most common type, followed by DDoS (24%) and phishing (18%) 

Source: Rinnovabili


160,000+ 

The number of organisations that now fall under the EU’s NIS2 cybersecurity directive, with transport entities falling in the Essential section 

Source: Legiscope

Share. Twitter LinkedIn Facebook Email
Previous ArticleTECH PROFILE: AI scene calibration unlocks incident detection on any PTZ camera
Christopher Court-Dobson

Related Posts

Artificial Intelligence (AI)

NEW ISSUE: Read the July/August 2026 edition of TTi magazine online now!

July 23, 20262 Mins Read
A man and woman drive a red convertible along a dirt road at sunset, with the woman raising both arms in the air
Features

FEATURE: Drivers trust road safety tech more than experts, study finds

July 16, 20265 Mins Read
Protesters gather on steps outside a public building holding placards calling for safer roads in Los Angeles. Signs include messages such as "Cars are killers", "Traffic collisions kill more in LA than guns" and "LA roads are a state of emergency". Several demonstrators wear yellow T-shirts bearing the Streets Are For Everyone (Safe) logo. Some hold white roses and photographs of people killed in traffic collisions.
Features

FEATURE: On US road-safety campaigning front lines

June 25, 202611 Mins Read
Latest Posts
An illustration of a man in a hood sitting at a laptop, face on, with lines of green zeros and ones falling down behind him over a city street with traffic lights visible

FEATURE: How did Iran’s traffic cameras get hacked?

August 3, 2026
Citilog’s system automatically generates a detection mask and identifies incidents, such as stopped vehicles, within the zone

TECH PROFILE: AI scene calibration unlocks incident detection on any PTZ camera

August 3, 2026
Pre-deployment site design reduces installation time by configuring sensor placement and alarm zones in advance

TECH PROFILE: Solid-state lidar brings intelligent 3D perception to wrong-way detection

August 3, 2026
FREE WEEKLY NEWS EMAIL!

Get the ‘best of the week’ from TrafficTechnologyToday.com direct to your inbox every Thursday


Supplier Spotlights
  • Conduent Transportation
    Conduent Transportation
  • Norbit ASA
    Norbit ASA
  • Teconer Oy Finland
    Teconer Oy
  • MESSAGEMAKER DISPLAYS
  • Carrida Technologies GmbH
    CARRIDA Technologies GmbH
  • triple sign system AB
    Triple Sign System AB
  • Cross Zlin
    CROSS Zlín a.s.
  • SMATS traffic solutions logo
    SMATS Traffic Solutions Inc.
  • Star Systems International Limited
Our Social Channels
  • Twitter
  • YouTube
  • LinkedIn
Getting in Touch
  • Free Email Newsletters
  • Contact Us
  • About Us
  • Supplier Spotlight

Upcoming Events

Notice
There are no upcoming events.
© Copyright 2026 Mark Allen Group. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
  • Cookie Policy
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.