ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Compromised CCTV can become an intelligence asset

A campaign that compromised more than 14,500 internet-connected cameras shows why CCTV should be treated as sensitive intelligence infrastructure, rather than another category of ordinary connected device.

Linked InXFacebook
bookmark_borderSave to Library

Researchers at Hunt.io said Operation CameraSwarm compromised 14,530 Dahua devices in 35 days using credential attacks, authentication bypasses and a peer-to-peer relay technique. Confirmed compromises were concentrated in Ukraine and Russia, although scanning was conducted globally.

 

According to The Hacker News, attackers created persistent accounts on 1,923 cameras and reached another 283 through a cloud relay using device serial numbers. Much of the campaign also exploited authentication flaws disclosed in 2021, illustrating how long vulnerable surveillance equipment can remain in service.

 

The risk extends beyond unauthorised viewing. CCTV can reveal staff routines, vehicle movements, deliveries, restricted areas and the physical layout of a facility. In sensitive locations, sustained access could support reconnaissance, target selection or the monitoring of security responses. Cameras may also provide an entry point into the wider network or be disabled when their coverage is most needed.

 

Hunt.io did not attribute the campaign to a named group or establish that the footage was used for espionage. However, it assessed with moderate confidence that parts of the toolkit were designed to transfer camera access to third parties.

 

Organisations should therefore manage CCTV according to the intelligence it collects. Devices need to be inventoried, patched and isolated from core systems, with unnecessary peer-to-peer access disabled. Default or weak credentials should be replaced, while new accounts and unusual outbound connections require monitoring.

 

The NCSC has warned that cameras and other edge devices are increasingly targeted and often lack the logging needed to investigate a compromise. If an attacker controls the equipment an organisation uses to observe its own environment, they inherit an established intelligence network.

 

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543