Hackers are hijacking IP cameras to break into corporate networks
IP cameras in the wrong hands can open the door to your network.

- Belgium’s cybersecurity agency warns hackers are compromising IP cameras to gain access to corporate networks.
- Attackers can also use compromised cameras for DDoS attacks, espionage, and data theft.
- Hunt.io found more than 14,000 hacked Dahua cameras across Ukraine and Russia in the CameraSwarm operation.
- Internet-connected cameras remain attractive targets because they often run continuously and use outdated software.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Centre for Cybersecurity Belgium (CCB) is warning citizens that threat actors are actively compromising IP cameras and turning them into weapons.
Internet-connected cameras, such as surveillance cameras and baby cameras, are meant to make you feel safe. However, they aren’t simple, isolated devices without risk.
For example, hackers have compromised IP cameras for a number of malicious activities, including DDoS attacks and espionage on critical infrastructure. Hacktivist groups have been using recordings as proof they’ve breached systems.
This isn’t just theoretical. Last month, cybersecurity firm Hunt.io found that over 14,000 Dahua cameras across Ukraine and Russia had been hacked and were used to steal data. The operation was dubbed CameraSwarm.
“A compromised IP camera can be used as a pivot point to breach into a corporate network. Because such cameras often come with poor security features, some threat actors target these devices to gain initial access to a network and from there go on to target internal devices,” the CCB explains.
Threat actors prefer attacking IP cameras for numerous reasons. For starters, they’re directly connected to the internet and run continuously. In addition, most of these devices are poorly secured or run on outdated software. Lastly, many remain operational, even when they no longer receive security updates.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
As a result, IP cameras stay online despite having known vulnerabilities.
The CCB is recommending that users make sure their cameras are either up-to-date with all available security patches or replaced once they've reached their end-of-life status.
Furthermore, users should immediately change default passwords, disable unnecessary internet access/remote administration like FTP and UPnP, use multi-factor authentication (MFA), and put cameras on a separate network/VLAN, like a guest Wi-Fi network.
The CCB recommends that organizations upscale their monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion.
The cybersecurity agency concludes with one important note: patching appliances or software to the newest version may protect against future exploitation, but it doesn’t remediate historic compromise.