How safe Are Your Cameras? How safe is your privacy

14,000 CCTV Cameras Hacked: Is Your Video Surveillance System Really Secure?

A recently uncovered cyber campaign involving more than 14,000 compromised IP cameras should be a wake-up call for every organisation operating CCTV.

CCTV cameras are installed to protect our buildings, people and assets.

But what happens when the security system itself becomes the security risk?

Cybersecurity researchers at Hunt.io have published details of Operation CameraSwarm, an investigation into the compromise of more than 14,500 Dahua IP cameras during a 35-day period between June and July 2026.

The confirmed compromises were particularly concentrated in Ukraine and Russia, although scanning activity was global.

For businesses operating IP CCTV systems in Ireland, the important lesson isn't simply about one manufacturer.

It is much bigger:

Your CCTV system is part of your IT network — and it needs to be secured accordingly.

What happened in Operation CameraSwarm?

According to Hunt.io, a single operator compromised more than 14,530 Dahua devices in just 35 days.

Researchers identified several different methods being used to gain access to cameras.

These included:

  • Automated attempts to discover and guess camera credentials.

  • Exploitation of previously identified authentication vulnerabilities.

  • Internet scanning for exposed CCTV devices.

  • Access through P2P/cloud connectivity mechanisms.

  • Use of camera serial numbers as part of the attack process.

  • Installation of persistent accounts on compromised cameras.

Perhaps most concerning was the discovery that 1,923 cameras had a persistent backdoor account installed.

Hunt.io reported that this account was stored separately from the normal administrator password. Changing the administrator password therefore did not necessarily remove the unauthorised access.

The researchers also identified 283 cameras reached through a cloud relay using their serial numbers, demonstrating why cybersecurity needs to extend beyond simply protecting the public IP address of a CCTV system.

Why should businesses care?

Modern CCTV cameras aren't simply cameras.

They are computers with lenses.

An enterprise IP camera can contain a processor, operating system, storage, network interface, web server, user accounts, APIs and connections to cloud services.

In many environments it may also have access to other devices on the corporate network.

That creates an important question:

Who can see your cameras?

Imagine an unauthorised person being able to view cameras covering:

  • your offices;

  • production areas;

  • warehouses;

  • retail stores;

  • cash-handling locations;

  • entrances and exits;

  • employee workspaces;

  • computer screens;

  • access-controlled doors;

  • delivery areas; or

  • sensitive operational processes.

The potential consequences go far beyond somebody simply watching a camera.

Your CCTV system contains valuable information

Video surveillance can reveal an extraordinary amount about how an organisation operates.

An attacker with access to CCTV could potentially determine when a building is occupied, when employees arrive and leave, where valuable assets are stored, how security procedures operate and which areas receive the least attention.

Modern video systems increasingly contain analytics and associated metadata too.

Depending on the system, that can include information relating to people, vehicles, number plates, access events and movement throughout a premises.

Video is data.

And organisations need to protect it accordingly.

The danger of old CCTV systems

One of the biggest cybersecurity risks we encounter isn't necessarily the technology originally installed.

It's what happens to it afterwards.

A CCTV system can remain operational for five, seven, ten years or longer.

During that time:

  • firmware becomes outdated;

  • cybersecurity vulnerabilities are discovered;

  • employees and contractors change;

  • passwords may be shared;

  • remote-access services remain enabled;

  • network configurations change;

  • cameras are added without reviewing the overall architecture.

The cameras may continue recording perfectly.

That doesn't necessarily mean the system remains secure.

Changing the password isn't always enough

Operation CameraSwarm provides a particularly useful example.

Hunt.io reported that almost 1,923 affected cameras had an additional persistent account installed.

This illustrates an important cybersecurity principle:

Once a device has been compromised, simply changing the password may not be sufficient.

The device needs to be assessed properly.

That may mean reviewing its accounts, firmware, configuration, network activity and remote connectivity — and potentially rebuilding or replacing it.

Should CCTV cameras be directly accessible from the Internet?

In most commercial environments, there should be a very good reason before any CCTV device is exposed directly to the public Internet.

Historically, remote CCTV access was often achieved through port forwarding.

A router would effectively open a door from the Internet directly to the recorder or camera.

Modern cybersecurity practice allows us to design CCTV networks very differently.

Depending on the application, appropriate measures can include network segmentation, secure cloud connectivity, encrypted communications, tightly controlled user permissions, multifactor authentication and properly managed remote access.

The objective should be simple:

Give authorised people access to the video without unnecessarily exposing the cameras themselves.

P2P connectivity deserves attention too

Operation CameraSwarm also highlights another important issue: P2P and cloud-relay connectivity.

P2P technology can make CCTV installation extremely convenient because users can access a system without traditional port forwarding.

Convenience, however, shouldn't replace cybersecurity assessment.

Organisations should understand:

  • where their video is being transmitted;

  • how devices authenticate with cloud services;

  • what remote services are enabled;

  • who operates those services;

  • how vulnerabilities are managed;

  • how quickly firmware updates can be deployed; and

  • whether services that aren't required can be disabled.

CCTV cybersecurity is an ongoing process

Installing a secure CCTV system isn't the end of the job.

Cybersecurity needs to continue throughout the lifecycle of the system.

At Usee, we believe organisations operating commercial CCTV should periodically review:

  • camera and recorder firmware;

  • administrator and user accounts;

  • password policies;

  • remote access;

  • network architecture;

  • Internet exposure;

  • P2P services;

  • unused accounts and services;

  • manufacturer security advisories;

  • system software;

  • cloud permissions; and

  • the ongoing support status of the equipment.

This is particularly important for organisations where CCTV covers sensitive environments or forms part of a wider security infrastructure.

Cheap CCTV can have an expensive consequence

When organisations compare CCTV systems, the conversation can easily become focused on megapixels, storage capacity and equipment cost.

Cybersecurity needs to be part of that conversation.

The real cost of a CCTV system isn't simply the purchase price of the cameras.

Organisations should also consider:

Who manufactured the equipment?

How does the manufacturer respond to vulnerabilities?

How long will firmware and security updates be provided?

Where is video stored?

How is remote access secured?

Can users be individually identified and controlled?

Can access be revoked immediately?

Is the system being actively maintained after installation?

These questions are increasingly as important as image quality.

What should you do if you operate Dahua cameras?

There is no reason for businesses to panic simply because they have Dahua equipment installed.

There is, however, a very good reason to review it.

Dahua maintains a Product Security Incident Response Team (PSIRT) and publishes security advisories and firmware information for affected products.

If you operate Dahua equipment — particularly older cameras or recorders — you should establish:

  1. Exactly which models are installed.

  2. Which firmware versions they are running.

  3. Whether current security updates are available.

  4. Whether any devices are directly exposed to the Internet.

  5. Whether P2P functionality is enabled and actually required.

  6. Which administrator and user accounts exist.

  7. Whether default, old or shared credentials remain in use.

  8. Whether the CCTV network is appropriately separated from critical business systems.

For larger estates, this should be approached as a structured CCTV cybersecurity audit rather than checking individual cameras in isolation.

The bigger lesson from CameraSwarm

Operation CameraSwarm isn't simply a story about 14,000 hacked cameras thousands of kilometres away.

It demonstrates how quickly automated tools can discover and attack vulnerable video surveillance equipment.

A camera installed on a wall in Dublin can be scanned by a computer anywhere in the world.

Geography provides very little protection on the Internet.

If your CCTV can see your business, you need to know who can see your CCTV.

Usee CCTV Cybersecurity Review

Usee designs, installs and supports enterprise video surveillance and cloud CCTV systems throughout Ireland.

Our approach increasingly brings together physical security, video intelligence, networking and cybersecurity.

For organisations operating older CCTV infrastructure, mixed camera estates or systems that have evolved over many years, we can review the existing environment and identify potential areas of concern.

A CCTV security review can examine the cameras, recording infrastructure, network architecture, firmware, remote connectivity, user access and overall approach to managing video.

Because protecting your premises shouldn't create another way into it.

Concerned about the security of your CCTV system?

Contact Usee.ie to discuss a CCTV cybersecurity and system review.

Next
Next

The Future of High-End Video Surveillance: Why Businesses Are Moving to Cloud-Based Security Solutions