Internet connected cameras are often treated as physical security equipment. But when these devices are exposed to the internet, poorly configured, outdated, or protected by weak credentials, they can become an entry point for cyberattacks.
A recent campaign involving more than 14,000 Dahua IP cameras across Ukraine and Russia highlights how attackers can compromise large numbers of connected surveillance devices and potentially use them for intelligence gathering, persistence, and broader cyber operations.
The incident is a strong reminder that cybersecurity does not stop at laptops, servers, cloud platforms, or applications. Every connected device within an organization’s environment can become part of its attack surface.
The Growing Risk of Connected Cameras
Modern organizations deploy thousands of cameras across offices, warehouses, factories, transportation facilities, retail locations, hospitals, government buildings, and other sensitive environments.
These devices are increasingly connected to corporate networks, cloud management platforms, remote monitoring systems, and security operations centers.
When security controls around these devices are weak, attackers may be able to:
• Identify exposed cameras through internet scanning
• Exploit outdated firmware or known vulnerabilities
• Abuse weak or default credentials
• Establish unauthorized access
• Access video feeds or stored footage
• Use compromised devices as part of attacker infrastructure
• Attempt to move from IoT devices toward other network resources
• Maintain persistence through compromised configurations or accounts
The scale of the recent campaign demonstrates that attackers do not always need to compromise a high value server first. A poorly secured camera can provide an alternative path into an organization’s digital environment.
Why IP Cameras Are Attractive Targets
Surveillance cameras frequently operate continuously and may remain connected for years.
In many organizations, security teams know which servers, applications, laptops, and cloud resources are deployed, but IoT devices can receive less attention.
This creates several security challenges.
First, cameras can be difficult to monitor using traditional endpoint security tools.
Second, organizations may not patch their camera firmware as frequently as they patch operating systems.
Third, remote administration can expose management interfaces to the internet.
Fourth, cameras may communicate with cloud services or external systems that are not always included in traditional network security reviews.
These characteristics make connected surveillance infrastructure an attractive target for threat actors.
The Danger of Persistent Access
One of the most concerning aspects of large scale IoT compromises is the possibility of persistent unauthorized access.
Changing an administrator password is an important security step, but it may not always remove every form of compromise.
Security teams should therefore investigate whether an affected device has:
• Unauthorized accounts
• Modified configurations
• Suspicious firmware
• Unexpected network connections
• Unknown administrative sessions
• Abnormal outbound traffic
• Unapproved remote access mechanisms
• Indicators of compromise associated with previous attacks
Organizations should treat a suspected compromised camera as a security incident rather than simply as a device that needs a password reset.
From Physical Security to Cybersecurity
The traditional view of CCTV systems focuses primarily on physical protection.
Today, that approach is no longer sufficient.
A modern surveillance environment can involve:
IP cameras
Network switches
Video management systems
Cloud platforms
Mobile applications
Remote administration portals
Storage systems
Authentication services
Corporate networks
Each component introduces potential cybersecurity considerations.
A compromise of one device may not automatically mean that the entire corporate network has been breached. However, organizations should assume that compromised IoT infrastructure could provide attackers with valuable information about the environment and investigate potential pathways for further activity.
Industries at Risk
The issue is relevant to virtually every industry using connected surveillance technology.
Government and Public Sector
Government facilities often use surveillance systems to protect buildings, transportation infrastructure, public spaces, and sensitive facilities.
Security assessments can help identify exposed devices, weak configurations, unnecessary internet access, and vulnerabilities across surveillance environments.
Manufacturing and Industrial Organizations
Factories and industrial facilities use cameras to monitor production areas, warehouses, equipment, and restricted zones.
COE Security can help organizations assess the security of connected devices, segment surveillance networks, test exposed services, and identify weaknesses that could affect operational environments.
Transportation and Logistics
Airports, ports, warehouses, distribution centers, rail facilities, and transportation operators rely heavily on surveillance systems.
Compromised cameras could create both physical security concerns and cybersecurity risks, making IoT security and network segmentation important parts of a broader security strategy.
Retail and E-commerce
Retail organizations operate cameras across stores, warehouses, distribution facilities, and corporate offices.
Security teams should ensure that surveillance infrastructure does not become an overlooked pathway into business networks.
Healthcare
Hospitals and healthcare organizations use surveillance systems across facilities while also managing highly sensitive patient and operational information.
Healthcare organizations can benefit from IoT assessments, network segmentation, vulnerability management, monitoring, and security testing designed to protect connected devices.
Financial Services
Banks, financial institutions, and payment organizations operate extensive physical security infrastructure.
Protecting cameras and other connected devices is another important layer in protecting facilities, employees, customers, and digital infrastructure.
What Organizations Should Do Now
Organizations using internet connected cameras should consider a comprehensive security review.
1. Identify Every Connected Device
Maintain an accurate inventory of cameras, recorders, management systems, and associated network infrastructure.
Unknown devices represent unknown risk.
2. Remove Unnecessary Internet Exposure
Camera management interfaces should not be directly exposed to the public internet unless there is a clear business requirement and appropriate security controls.
3. Patch Firmware
Organizations should establish a process for monitoring vendor security advisories and updating camera firmware and associated software.
4. Eliminate Default Credentials
Every device should use unique, strong authentication credentials.
Where supported, organizations should also implement multifactor authentication for administrative access.
5. Segment Surveillance Networks
Cameras should not automatically have unrestricted access to corporate systems.
Network segmentation can reduce the potential impact if a surveillance device is compromised.
6. Monitor Device Behavior
Security teams should monitor unusual outbound connections, unexpected traffic patterns, unauthorized administrative activity, and communication with suspicious infrastructure.
7. Perform IoT Security Testing
Vulnerability assessments and penetration testing can identify weaknesses before attackers discover them.
Testing should include externally exposed devices, authentication mechanisms, firmware, management interfaces, APIs, and network configurations where authorized.
8. Prepare an IoT Incident Response Plan
Organizations should know how to isolate compromised cameras, preserve evidence, investigate related network activity, reset affected credentials, and restore devices securely.
A Broader Lesson for Cybersecurity Leaders
The biggest lesson from this campaign is not simply that thousands of cameras were compromised.
It is that organizations need to think about cybersecurity across the entire connected environment.
A camera may appear to be a simple physical security device, but once it is connected to a network, remotely managed, or integrated with cloud services, it becomes part of the organization’s digital attack surface.
Cybersecurity programs therefore need visibility across traditional IT, operational technology, IoT, cloud infrastructure, applications, and physical security systems.
Conclusion
The compromise of more than 14,000 IP cameras is another reminder that attackers are increasingly looking beyond traditional endpoints.
Connected surveillance devices can contain sensitive information, provide visibility into physical environments, and potentially become stepping stones for further attacks when they are poorly secured.
Organizations should treat cameras and other IoT devices as security assets rather than standalone equipment.
Strong authentication, timely patching, network segmentation, continuous monitoring, vulnerability assessments, penetration testing, and incident response planning can significantly improve resilience against attacks targeting connected infrastructure.
As organizations continue expanding their use of smart devices, cybersecurity teams must ensure that convenience and connectivity do not come at the expense of security.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
For organizations operating connected surveillance and IoT environments, COE Security can help assess camera and IoT security, identify exposed systems, evaluate authentication and configuration weaknesses, perform vulnerability assessments and penetration testing, strengthen network segmentation, improve monitoring, and support incident response planning.
Our services can support organizations across government, financial services, healthcare, manufacturing, transportation, logistics, retail, technology, and other industries where connected devices form an important part of daily operations.
COE Security also helps organizations strengthen cybersecurity governance and compliance by connecting technical security assessments with broader risk management and data protection requirements.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
Click to read our LinkedIn feature article