The 14,500 Dahua Cameras Hacked in a Month: What Went Wrong

·
Listen to this article~6 min
The 14,500 Dahua Cameras Hacked in a Month: What Went Wrong

Over 14,500 Dahua cameras were compromised in a month-long attack using credential stuffing, auth bypasses, and P2P relays. Here's what happened and how to protect your devices.

When a security camera gets compromised, it's usually a single device, a single owner, a single headache. But what happens when it's not one camera, but over 14,500 of them, all hit in a coordinated attack over just a few weeks? That's the scenario cybersecurity researchers at Hunt.io have laid out in a new disclosure, and it's a wake-up call for anyone who relies on internet-connected surveillance. The campaign, which they've codenamed Operation CameraSwarm, ran from June 17 to July 22, 2026. That's roughly five weeks of relentless activity. The researchers reconstructed the entire operation from a 407 MB working directory that was left exposed online. Inside, they found 2,616 files that painted a detailed picture of how the attackers pulled this off. It wasn't a single clever exploit. It was a combination of old-school credential stuffing, two specific authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique that made the whole thing harder to trace. ### The Anatomy of the Attack Let's break down what actually happened, because the details matter. The attackers didn't just guess passwords and hope for the best. They had a multi-layered approach. - **Credential Attacks:** This is the brute-force side of things. They used lists of default and previously leaked usernames and passwords, trying them across thousands of devices. It's surprisingly effective because many people never change the factory-set credentials on their cameras. - **Authentication Bypass Flaws:** This is the more dangerous part. The attackers exploited two known vulnerabilities that allowed them to bypass the login process entirely. This means they didn't need to guess a single password on those devices; they just walked right in. - **P2P Relay Technique:** This is the sneaky part. Instead of connecting directly to the cameras, they used a peer-to-peer relay. This hides the attacker's true location and makes it much harder for network defenders to block the traffic, because it looks like normal device-to-device communication. ### What This Means for You If you're running a Dahua device, or any IP camera for that matter, this should get your attention. This isn't a theoretical risk. It's a proven, active campaign that compromised tens of thousands of devices in a single month. Think about it this way: your camera is a door into your network. If an attacker gets in, they can watch your home, your office, or your warehouse. But worse, they can often use that device as a launching pad to attack other systems on your network. A camera is rarely the final target; it's usually the first step. ### The Hard Truth About Default Settings The biggest takeaway here is the importance of changing default credentials. It's the simplest advice, but it's also the most ignored. The credential attacks worked because too many devices still had their factory settings. If you haven't changed the admin password on your camera, do it today. Not tomorrow. Today. > "The most sophisticated attack in the world still relies on the most basic mistake: leaving the front door unlocked." Beyond that, make sure your device firmware is up to date. The two authentication-bypass flaws they exploited likely have patches available. If you don't update, you're leaving those doors wide open. ### The Bigger Picture for Digital Privacy This story is about cameras, but it's really about a broader principle: anything connected to the internet is attackable. Whether it's a camera, a router, or a smart thermostat, if it has an IP address, someone out there is trying to get in. That's why the concept of digital privacy and secure browsing is so critical. It's not just about hiding your browsing history. It's about controlling your digital footprint. Using tools that help you manage your online identity, like an antidetect browser, can be part of a larger strategy to keep your activities private and your devices secure. ### What to Do Right Now If you own a Dahua device, here's your immediate action plan: 1. Log into your device and change the administrator password to something long, unique, and complex. 2. Check for firmware updates and install them immediately. 3. Disable any features you don't use, especially remote access or P2P if you don't need it. 4. Put the camera on a separate network segment, away from your main computers and sensitive data. Operation CameraSwarm is a reminder that cyber threats are not abstract. They are real, they are active, and they are targeting devices you probably have in your building right now. The question is: are you going to be the next statistic, or are you going to lock the door?