GENERAL

Your Security Cameras Are a Cyber Attack Surface

May 8, 2026 6 min read
Security cameras are no longer passive recording devices. They are networked endpoints, and hackers know it. From nation-state actors targeting Hikvision cameras to 40,000+ exposed feeds found online, your physical security infrastructure may be your biggest cybersecurity blind spot.

Security cameras are supposed to protect you. They watch the doors, scan the parking lots, and keep an eye on the warehouse floor at 3 a.m. But here is something most security directors have not fully reckoned with: every IP-connected camera on your network is a computer. It runs firmware. It has an IP address. It accepts remote connections. And in a staggering number of cases, it is running with default credentials, unpatched software, or no encryption at all.

That makes your security camera system not just a physical security tool, but a cybersecurity attack surface. And threat actors around the world have already figured that out.

40,000 Cameras Exposed and Counting

In 2025, cybersecurity firm Bitsight used its TRACE technology to scan the internet for exposed security cameras. What they found was alarming: more than 40,000 cameras with open, unauthenticated feeds accessible to anyone with a browser. No password required. No exploit needed. Just point, click, and watch.

That number only scratches the surface. Shodan, the search engine for internet-connected devices, indexes hundreds of thousands of camera feeds globally. Many of these belong to schools, hospitals, retail stores, and corporate offices. The owners have no idea their cameras are broadcasting to the open internet.

The root causes are painfully predictable: default passwords that were never changed, UPnP configurations that punched holes in firewalls automatically, and firmware that has not been updated since the cameras were installed years ago.

Exterior-school-surveillance-camera

Nation-States Are Targeting Your Cameras

This is not just about petty hackers or voyeurs. Nation-state threat actors have made IP cameras a priority target.

In March 2026, Check Point Research published findings showing that Iranian-linked threat groups were actively exploiting vulnerabilities in Hikvision and Dahua cameras. These are not fringe brands. Hikvision and Dahua together account for a massive share of the global security camera market. The attackers were using compromised cameras as footholds for lateral movement into corporate and government networks.

A year earlier, in 2025, more than 20 international cybersecurity agencies issued a joint advisory warning that Russian state-sponsored hackers were targeting IP cameras and other IoT devices as entry points into critical infrastructure. The advisory named security cameras specifically as high-value targets because they often sit on the same network segment as more sensitive systems but receive far less security scrutiny.

And this tracks with the precedent set by the Verkada breach. In 2021, attackers gained access to more than 150,000 security cameras across hospitals, schools, prisons, Tesla factories, and Cloudflare offices. The breach exposed live feeds from psychiatric facilities and women's health clinics. Verkada ultimately paid a $2.95 million FTC penalty, not for the breach itself, but for failing to implement reasonable security measures that could have prevented it.

Why Cameras Are Such Easy Targets

Most IT security teams have hardened their servers, locked down their endpoints, and deployed sophisticated threat detection systems. But security cameras occupy an awkward gap between physical security and IT. The physical security team chose them, installed them, and manages them. IT may not even know how many cameras are on the network, let alone whether they are patched.

Here is what makes cameras uniquely vulnerable:

Default credentials persist. A shocking number of cameras ship with admin/admin or admin/12345 and never get changed. Some models have hardcoded backdoor accounts that cannot be disabled without a firmware update.

Firmware updates are rare. Unlike laptops and servers that receive automatic patches, camera firmware updates require manual intervention. Many organizations never update their cameras after initial installation. That means known vulnerabilities stay exploitable for years.

Cameras live on flat networks. In many deployments, cameras share the same network segment as workstations, servers, and sensitive systems. A compromised camera becomes a pivot point for attackers to move laterally through the entire network.

Encryption is optional and often disabled. Many cameras transmit video feeds and management traffic in plaintext. An attacker on the same network can intercept feeds, steal credentials, or inject commands.

Physical access enables digital attacks. Cameras are mounted in accessible locations. An attacker who can physically reach a camera can often reset it, plug into its network port, or replace it with a rogue device.

The Cyber-Physical Convergence Problem

The security industry has been talking about cyber-physical convergence for years, but 2026 is the year it became unavoidable. A survey by the Security Industry Association found that 45% of organizations are prioritizing AI integration into their security systems this year, up from just 21% in 2025. That acceleration means more cameras connected to more networks, processing more data, and presenting more attack surface.

The old model, where physical security and cybersecurity were separate departments with separate budgets and separate concerns, is broken. When your camera system can be weaponized to spy on your own facility, disable your surveillance during an incident, or serve as a launchpad for ransomware, the distinction between physical and cyber threats dissolves.

Consider what happened in the Netherlands in July 2025: a cyberattack knocked an entire network of speed cameras offline. The cameras were not the ultimate target. They were the weakest node in a connected system, and attackers used them to disrupt government infrastructure.

How to Harden Your Camera Infrastructure

The good news is that securing your camera system does not require replacing every device. It requires treating cameras like what they actually are: networked endpoints that deserve the same security rigor as any other device on your infrastructure.

Segment your camera network. Cameras should live on their own VLAN, isolated from workstations, servers, and other sensitive systems. If a camera gets compromised, network segmentation limits how far the attacker can move. This is the single most impactful step most organizations can take.

Change every default password. Audit every camera on your network. If any device still has factory credentials, change them immediately. Use strong, unique passwords and store them in a password manager. If a camera has hardcoded credentials that cannot be changed, that camera needs to be replaced.

Update firmware regularly. Establish a quarterly firmware review cycle. Check manufacturer websites for security patches and apply them. If a camera vendor has stopped releasing firmware updates for your model, that is a red flag. End-of-life cameras with known vulnerabilities are ticking time bombs.

Disable unnecessary services. Turn off UPnP, Telnet, SSH (if not needed), and any remote access features you are not actively using. Every open port and running service is a potential entry point.

Enable encryption. Configure HTTPS for camera management interfaces and use encrypted protocols (SRTP) for video streams where supported. This prevents credential theft and feed interception.

Monitor camera traffic. Your cameras should generate predictable traffic patterns. If a camera suddenly starts communicating with an unfamiliar external IP address or sending unusual volumes of data, that is a strong indicator of compromise. Network monitoring tools can flag these anomalies automatically.

Conduct regular audits. Scan your network periodically for unknown or unauthorized cameras. Shadow IT is real in physical security. Departments sometimes add cameras without informing IT, creating unmanaged attack surface.

The Advantage of Cloud-Managed AI Systems

One of the reasons organizations are shifting toward AI-powered security platforms is that modern systems are designed with cybersecurity as a foundational requirement, not an afterthought. Cloud-managed platforms push firmware updates automatically, enforce encryption by default, and provide centralized visibility into every camera on the network.

IntelliSee, for example, works with your existing camera infrastructure but layers AI-powered analytics on top through a cloud-managed platform. That means the AI processing and alerting happens through a secured, monitored pipeline rather than through vulnerable on-camera firmware. It is a model that reduces the cyber risk inherent in traditional camera deployments while dramatically improving detection capabilities.

This approach also addresses the security staffing crisis. Instead of relying on guards to watch camera feeds around the clock, AI handles the monitoring and alerts human operators only when a genuine threat is detected. That reduces false alarm fatigue and ensures that real incidents get immediate attention.

Stop Treating Cameras Like Dumb Devices

The era of the passive security camera is over. Every camera on your network is a computer, and every computer on your network is a target. The organizations that recognize this and act on it will be far better positioned than those still treating their camera systems as a set-it-and-forget-it investment.

The convergence of physical security and cybersecurity is not a future trend. It is the current reality. And the attack surface is growing with every new camera you connect. The question is whether you are going to secure that surface proactively or wait for a breach to force the issue.

Start with a network audit. Check your credentials. Segment your VLANs. And take a hard look at whether your camera platform is designed for the threat landscape of 2026 or the one from 2016.

Take the Next Step

Turn Your Cameras Into Proactive Protectors

See how IntelliSee layers real-time AI threat detection onto your existing surveillance infrastructure, with no camera replacement required.

Request a Demo