top of page
  • X
  • Facebook
  • Linkedin
  • Instagram
Search

Your Own Cameras Are Casing You For Someone Else

22 minutes ago
4 min read

Give us a parking spot across the street and a few days and we'll know your building better than half the people who badge in every morning. When the shift change happens. Which door gets propped at 1700 so the smokers don't have to walk around from the front door. How many guards actually work a Sunday versus how many the roster says. What sits on the loading dock and how long it sits there before anyone moves it. None of that is clever. It's just patience and a line of sight. It is also the first thing we build on a physical engagement before we ever touch a door.


Ignoring all of that, here is the part that should bother you. On more than one job we did, we did not need the parking spot. The client handed us the whole thing through their own cameras. An easily guessed password on their cloud management console. Suddenly we are not casing the building from the street anymore. We are watching it from the inside, through the exact lenses they installed to keep people like us out.


So when the news broke recently that attackers quietly took over more than 14,500 Dahua surveillance cameras in a 35 day operation by some group named Operation CameraSwarm, using a combination of credential stuffing, a few old authentication bypasses and the cameras' own peer to peer feature to reach them; most of the coverage filed it under the same tired headline. Another IoT botnet. More devices collected to throw junk traffic at somebody. While that framing is comfortable, it is wrong. The reason it is wrong is the whole point of these words.


A compromised laptop leaks data. A compromised camera leaks your operation. The botnet story treats 14,500 cameras like 14,500 cheap computers that happen to be good at sending spam. What they actually are is 14,500 sensors pointed at real physical space, and the moment an adversary owns the lens they are not after your bandwidth. They are running reconnaissance on your building for a break in that has not happened yet. Everything we spend days trying to gather from a parked car, they now pull from a browser, on their schedule, with no exposure. Most companies bought these cameras to reduce physical risk. Nobody in the buying meeting ever asked what the same device does for an attacker, because the camera got treated as safety equipment instead of what it really is, a networked sensor that works just as well for whoever controls it.


That is the crossover almost nobody in this industry can speak to honestly. A camera installer thinks about coverage and mounting height. A network team thinks about firmware and VLANs. Neither one owns the question that actually matters, which is what an attacker learns about your physical site through your own devices, and what they do with it next. We sit in both chairs. We have used compromised sensors to plan a physical entry, and we have sat across from clients and shown them that the eyes they installed for safety are a live intelligence feed the second a shipped password holds.


Here is what we would tell you to go check today, before you call anybody.


  • Pull up every camera, NVR, and DVR you own and find out how many are still running the password they shipped with or a password your installer set and never rotated.

    • Be honest about the number. It is almost always higher than the person in charge thinks.

  • Find out which of those devices are reachable from the internet, directly or through a peer to peer or cloud feature you probably turned on without reading what it does.

    • That peer to peer convenience is exactly how CameraSwarm reached its targets, and most owners have no idea it is even on.

  • Ask who would know if a camera feed was being watched by someone who should not be watching it. In most buildings the answer is no one, because nobody monitors the monitors.

    • In most cases, a camera streaming to an attacker looks identical to a camera being monitored by the security team.

  • Then ask the uncomfortable one. If an adversary had three weeks of footage from your cameras, what could they plan that they cannot plan today. Walk that out honestly and you stop seeing a surveillance system and start seeing a map you handed out.


If you only do one thing this week, start to lock down access. Rotate every default and installer set password on every camera and the monitoring console. Secondly, get the cameras off the public internet. That closes the door CameraSwarm walked through. What these quick changes do not do is tell you who already walked through it or what they saw, and that is the part you cannot pull up from a settings page. This will take some work going through audit logs for access attempts, if your vendor even makes those available to you.


If that list is harder to answer than it should be, that is the finding, and it is exactly the gap we close. We assess physical surveillance systems the way an attacker actually treats them, as a cyber attack surface that pays off in physical access, and we run the loop all the way through, from the compromised device to the intelligence it gives up to the entry it makes possible. That is not a camera audit and it is not a network scan. It is the one view that sees how the two become the same problem, and it is the view that keeps your own eyes from working for the other side.


 
 
 

Comments


© 2026 by Red Cell Security, LLC.

Phone

Email

Connect

  • X
  • Facebook
  • LinkedIn
  • Instagram
bottom of page