Hackers are compromising internet-connected cameras to infiltrate corporate networks, conduct espionage and launch distributed denial-of-service attacks. Belgium’s cybersecurity agency warns that hacked IP cameras can provide an entry point to far more valuable internal systems.

IP Cameras Become Corporate Entry Points

The Centre for Cybersecurity Belgium has warned that threat actors are actively compromising IP cameras and turning them into attack tools.

Internet-connected surveillance systems, baby monitors and similar products may appear separate from other equipment. However, they often share networks with computers, servers and business applications.

A compromised camera can therefore become a pivot point. After gaining initial access, attackers can scan the surrounding network and attempt to reach internal devices.

This approach allows criminals to target corporate systems that may not be directly accessible from the internet. As a result, one poorly protected camera can weaken an otherwise secure organisation.

Hackers can also use infected cameras for cyberespionage, data theft and DDoS attacks. Meanwhile, some hacktivist groups publish stolen recordings as evidence that they breached a targeted organisation.

CameraSwarm Compromised Thousands of Devices

The threat extends well beyond isolated incidents. Cybersecurity company Hunt.io recently identified more than 14,000 compromised Dahua cameras across Ukraine and Russia.

Researchers named the campaign CameraSwarm. The attackers reportedly used the hijacked equipment to steal information.

The discovery demonstrates how quickly criminals can create a large surveillance network from vulnerable devices. Moreover, every compromised camera may expose the network and physical location where an organisation installed it.

Why Hackers Target Internet-Connected Cameras

IP cameras offer several characteristics that make them attractive targets. First, they remain connected to the internet and usually operate continuously.

Many models also have weak security controls or outdated firmware. Owners may install the cameras and then leave them running for years without checking for updates.

Default passwords create another major risk. Attackers can scan the internet for exposed devices and test common login credentials automatically.

Furthermore, some cameras continue operating long after their manufacturers stop providing security updates. Known vulnerabilities may therefore remain available to attackers indefinitely.

Remote management features can increase the exposure. Services such as FTP, UPnP and web-based administration may give criminals additional ways to reach a device.

How to Protect IP Cameras

Users should install every available security update for their cameras. If a device has reached the end of its supported life, replacing it is safer than continuing to rely on outdated software.

Default usernames and passwords should also be changed immediately. Each camera needs a strong, unique password that attackers cannot reuse from another breached account.

Where supported, users should enable multi-factor authentication. They should also disable unnecessary remote access, FTP, UPnP and other services that expose the device to the internet.

Businesses should place cameras on a separate network or VLAN. A dedicated guest-style network can limit an attacker’s ability to move from a compromised camera to sensitive corporate systems.

Organisations should also monitor traffic from connected devices and investigate unusual communication. Stronger detection tools can help security teams identify an intrusion before attackers reach other parts of the network.

Updates Cannot Remove an Existing Infection

Installing the latest firmware can prevent attackers from exploiting some vulnerabilities in the future. However, an update does not automatically remove malware or reverse an earlier compromise.

Businesses should inspect previously exposed devices for suspicious changes, unknown accounts and unusual network connections. If administrators cannot confirm that a camera remains trustworthy, they should reset or replace it.

Hacked IP cameras show how devices intended to improve security can create serious risks when neglected. Regular updates, network separation and stronger access controls can prevent a single camera from opening the door to an entire corporate network.


0 responses to “Hacked IP Cameras Give Attackers Access to Corporate Networks”