More than 40,000 security cameras found openly accessible on the internet

More than 40,000 security cameras found openly accessible on the internet

A new report from cybersecurity firm Bitsight reveals that over 40,000 internet-connected security cameras are openly accessible online without any password protection, allowing anyone to view live footage. 

The finding, published in Bitsight’s latest research from Bitsight TRACE, indicates a persistent vulnerability first highlighted by the company in 2023, with no significant improvement in the situation.

The cameras, intended for security or convenience, are inadvertently exposing sensitive spaces due to minimal setup requirements. The report Big Brother Is Watching And So Is Everyone Else suggests that the ease of purchase and deployment contributes to this ongoing threat, making the 40,000 figure likely a conservative estimate of the true scale of the problem. Accessing these unprotected feeds does not require advanced hacking skills; a standard web browser and the correct IP address are often sufficient.

Global exposure and vulnerable locations

Bitsight’s scan of the internet for exposed HTTP-based and RTSP-based cameras identified the United States as having the highest number of exposed devices, with approximately 14,000 cameras. Japan followed, with Austria, Czechia and South Korea also showing significant numbers of vulnerable cameras.

The exposed cameras are found in a wide range of settings, from residential properties monitoring front doors and living rooms to corporate environments revealing confidential information on whiteboards and screens. Factory cameras are also exposing manufacturing secrets, and even public transportation cameras are openly streaming passengers. While some cameras are intentionally set up for public viewing, such as those streaming beaches or bird feeders, the vast majority of exposed cameras are unintentional security risks.

Dark web activity indicates malicious interest

Bitsight’s Cyber Threat Intelligence team has uncovered discussions on dark web forums where malicious actors are actively sharing tools and tactics to locate and exploit these exposed cameras. Some individuals are even reportedly selling access to these live feeds, confirming that the threat is not theoretical but an active concern.

Recommendations for enhanced security

Bitsight urges individuals and organisations to take immediate steps to secure their internet-connected cameras. Key recommendations include:

  • Checking for internet accessibility: Users should attempt to access their camera feeds from a device outside their home or company network. If remote access is possible without secure login through an app or VPN, the camera may be exposed.
  • Changing default credentials: It is crucial to change factory-set usernames and passwords to strong, unique ones, as many cameras come with weak or publicly known default settings.
  • Disabling unnecessary remote access: If remote viewing is not required, users should disable this feature to prevent outside connections.
  • Regular firmware updates: Keeping camera firmware up to date is essential, as manufacturers frequently release security patches to address vulnerabilities.

For organisations managing surveillance systems, additional precautions include restricting access with firewalls and VPNs to ensure only authorised personnel can view feeds, and monitoring for any unusual activity or login attempts.

Browse our latest issue

Intelligent CISO

View Magazine Archive