When 150,000 video surveillance cameras get hacked, it’s big news. Even if the main reason for the hack was to make a point. Even if the major consequence is bad publicity for a video company (and, by extension, the entire video surveillance industry).

The target of the hack was Silicon Valley startup Verkada, which has collected a massive trove of security-camera data from its 150,000 surveillance cameras inside hospitals, companies, police departments, prisons and schools. Previously, Verkada has been known for an aggressive sales approach and its intent to disrupt the traditional video market.

The data breach was accomplished by an international hacker collective and was first reported by Bloomberg. The reported reasons for the hack were “lots of curiosity, fighting for freedom of information and against intellectual property, a huge dose of anti-capitalism, a hint of anarchism – and it’s also just too much fun not to do it,” according to Bloomberg.

Tesla amongst those impacted

The “fun” included access to a video showing the inside of a Florida hospital, where eight hospital staffers tackled a man and pinned him to the bed. Inside a Massachusetts police station, officers are seen questioning a man in handcuffsA view inside a Tesla warehouse in Shanghai, China, showed workers on an assembly line. Inside a Massachusetts police station, officers are seen questioning a man in handcuffs. There are even views from Verkada security cameras inside Sandy Hook Elementary School in Connecticut, where a gunman killed more than 20 people in 2012.

In a “security update” statement, Verkada reports: “Our internal security experts are actively investigating the matter. Out of an abundance of caution, we have implemented additional security measures to restrict account access and further protect our customers.”

Hacking was possible due to built-in feature

The hacker group was able to obtain “root” access on the cameras, meaning they could use the cameras to execute their own code, reports Bloomberg. Obtaining this degree of access to the camera did not require any additional hackingUsing that access, they could pivot and obtain access to the broader corporate network of Verkada’s customers or hijack the cameras and use them as a platform to launch future hacks, the hackers told Bloomberg. Obtaining this degree of access to the camera did not require any additional hacking, as it was a built-in feature.

Elisa Costante, VP of research for cybersecurity firm Forescout, calls the Verkada security camera hack "shocking."

"Connected cameras are supposed to provide an additional layer of security to organisations that install them,” she says. “Yet, as the Verkada security camera breach has shown, the exact opposite is often true. [It is worrisome that] the attack wasn't even very sophisticated and didn't involve exploiting a known or unknown vulnerability. The bad actors simply used valid credentials to access the data stored on a cloud server.”

Super Admin account had access to all cameras

Hackers gained access to Verkada through a “Super Admin” account, allowing them to peer into the cameras of all of its customers. They found a username and password for an administrator account publicly exposed on the internet, according to Bloomberg. The hackers lost access to the video feeds and archives after Bloomberg contacted Verkada.Hackers lost access to the video feeds and archives after Bloomberg contacted Verkada

The results could have been worse, says Costante. "In this case, the bad actors have seemingly only resorted to viewing the footage these cameras have captured. But they are likely able to cause a lot more damage if they choose to do so, as our own research team has discovered. We were able to intercept, record and replace real-time footage from smart cameras by exploiting unencrypted video streaming protocols and performing a man-in-the-middle attack. This effectively gives criminals a virtual invisibility cloak to physically access premises and wreak havoc in the real world.”

Impact on broader video surveillance industry

The impact of a well-publicised cyber-attack on the broader video surveillance industry is also a concern. “As an industry, and as manufacturers in physical security, we cannot take these hacks lightly,” says Christian Morin, CSO & Vice-President of Integrations & Cloud Services, Genetec. “The potential broad-reaching impact of these hacks on physical security systems, including providing a beachhead to facilitate lateral movement onto networks, resulting in data and privacy breaches or access to critical assets and infrastructure, cannot be overstated. It is our responsibility and duty to users of our technology to prioritise data privacy and cybersecurity in the development, distribution, and deployment of video surveillance systems.”

Widespread government and healthcare use

The Verkada cameras are in widespread use within government and healthcare, which are by far the company’s most dominant verticals. Lesser verticals for them are manufacturing, financial and retail.The Verkada website pledges to take privacy seriously

Verkada’s line of hybrid cloud security cameras combines edge-based processing with the capabilities of cloud computing. Cameras analyse events in real-time, while simultaneously leveraging computer vision technology for insights that bring speed and efficiency to incidents and investigations. Command, Verakda’s centralised web-based platform, provides users with access to footage they need. Motion detection, people analytics, and vehicle analytics enable searches across an organisation to find relevant footage.

The Verkada website pledges to take privacy seriously: “We are passionate about developing products that enhance the security and privacy of organisations and individuals. We believe that well-built, user-friendly systems make it easier to manage and secure physical environments in ways that respect the privacy of individuals while simultaneously keeping them safe.”

Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Download PDF version Download PDF version

Author profile

Larry Anderson Editor, SecurityInformed.com & SourceSecurity.com

An experienced journalist and long-time presence in the US security industry, Larry is SourceSecurity.com's eyes and ears in the fast-changing security marketplace, attending industry and corporate events, interviewing security leaders and contributing original editorial content to the site. He leads SourceSecurity.com's team of dedicated editorial and content professionals, guiding the "editorial roadmap" to ensure the site provides the most relevant content for security professionals.

In case you missed it

Physical security and the cloud: why one can’t work without the other
Physical security and the cloud: why one can’t work without the other

Human beings have a long-standing relationship with privacy and security. For centuries, we’ve locked our doors, held close our most precious possessions, and been wary of the threats posed by thieves. As time has gone on, our relationship with security has become more complicated as we’ve now got much more to be protective of. As technological advancements in security have got smarter and stronger, so have those looking to compromise it. Cybersecurity Cybersecurity, however, is still incredibly new to humans when we look at the long relationship that we have with security in general. As much as we understand the basics, such as keeping our passwords secure and storing data in safe places, our understanding of cybersecurity as a whole is complicated and so is our understanding of the threats that it protects against. However, the relationship between physical security and cybersecurity is often interlinked. Business leaders may find themselves weighing up the different risks to the physical security of their business. As a result, they implement CCTV into the office space, and alarms are placed on doors to help repel intruders. Importance of cybersecurity But what happens when the data that is collected from such security devices is also at risk of being stolen, and you don’t have to break through the front door of an office to get it? The answer is that your physical security can lose its power to keep your business safe if your cybersecurity is weak. As a result, cybersecurity is incredibly important to empower your physical security. We’ve seen the risks posed by cybersecurity hacks in recent news. Video security company Verkada recently suffered a security breach as malicious attackers obtained access to the contents of many of its live camera feeds, and a recent report by the UK government says two in five UK firms experienced cyberattacks in 2020. Cloud computing – The solution Cloud stores information in data centres located anywhere in the world, and is maintained by a third party Cloud computing offers a solution. The cloud stores your information in data centres located anywhere in the world and is maintained by a third party, such as Claranet. As the data sits on hosted servers, it’s easily accessible while not being at risk of being stolen through your physical device. Here’s why cloud computing can help to ensure that your physical security and the data it holds aren’t compromised. Cloud anxiety It’s completely normal to speculate whether your data is safe when it’s stored within a cloud infrastructure. As we are effectively outsourcing our security by storing our important files on servers we have no control over - and, in some cases, limited understanding of - it’s natural to worry about how vulnerable this is to cyber-attacks. The reality is, the data that you save on the cloud is likely to be a lot safer than that which you store on your device. Cyber hackers can try and trick you into clicking on links that deploy malware or pose as a help desk trying to fix your machine. As a result, they can access your device and if this is where you’re storing important security data, then it is vulnerable. Cloud service providers Cloud service providers offer security that is a lot stronger than the software in the personal computer Cloud service providers offer security that is a lot stronger than the software that is likely in place on your personal computer. Hyperscalers such as Microsoft and Amazon Web Service (AWS) are able to hire countless more security experts than any individual company - save the corporate behemoth - could afford. These major platform owners have culpability for thousands of customers on their cloud and are constantly working to enhance the security of their platforms. The security provided by cloud service providers such as Claranet is an extension of these capabilities. Cloud resistance Cloud servers are located in remote locations that workers don’t have access to. They are also encrypted, which is the process of converting information or data into code to prevent unauthorised access. Additionally, cloud infrastructure providers like ourselves look to regularly update your security to protect against viruses and malware, leaving you free to get on with your work without any niggling worries about your data being at risk from hackers. Data centres Cloud providers provide sophisticated security measures and solutions in the form of firewalls and AI Additionally, cloud providers are also able to provide sophisticated security measures and solutions in the form of firewalls and artificial intelligence, as well as data redundancy, where the same piece of data is held within several separate data centres. This is effectively super-strong backup and recovery, meaning that if a server goes down, you can access your files from a backup server. Empowering physical security with cybersecurity By storing the data gathered by your physical security in the cloud, you're not just significantly reducing the risk of cyber-attacks, but also protecting it from physical threats such as damage in the event of a fire or flood. Rather than viewing your physical and cybersecurity as two different entities, treat them as part of one system: if one is compromised, the other is also at risk. They should work in tandem to keep your whole organisation secure.

Video surveillance is getting smarter and more connected
Video surveillance is getting smarter and more connected

The global pandemic has triggered considerable innovation and change in the video surveillance sector. Last year, organisations around the globe embraced video surveillance technologies to manage social distancing, monitor occupancy levels in internal and external settings, and enhance their return-to-work processes. Forced to reimagine nearly every facet of their operations for a new post-COVID reality, companies were quick to seize on the possibilities offered by today’s next-generation video surveillance systems. Whether that was utilising motion sensing technologies to automatically close doors or switch on lighting in near-deserted office facilities. Or checking if people were wearing masks and adhering to distancing rules. Or keeping a watchful eye on streets and public spaces during mandated curfew hours. Beyond surveillance and monitoring use cases, organisations also took advantage of a raft of new Artificial Intelligence (AI) applications to undertake a range of tasks. Everything from automating their building management and optimising warehouse operations, to increasing manufacturing output and undertaking predictive maintenance. Behind the scenes, three key trends all contributed to the growing ubiquity of video surveillance observed in a variety of government, healthcare, corporate, retail, and industry settings. Video surveillance takes to the Cloud Last year the shift to digital working led organisations to rapidly embrace cloud-enabled services, including cloud-hosted Video Surveillance As A Service (VSaaS) solutions that provide tremendous economies of scale and flexibility. Alongside significant cost savings, these solutions make it easier for organisations to enhance their disaster recovery and manage their video surveillance estate in new and highly effective ways. Surveillance cameras with audio recording were used more than 200% by customers between 2016 and 2020For example, in addition to enabling remote access and maintenance, today’s cloud-powered systems eliminate any need to invest in local storage technologies that all too often fail to keep pace with an organisation’s growing data storage requirements. Indeed, data from our worldwide customer base survey reveals how in 2020 an impressive 63% of organisations had abandoned using any on-premises storage option and were instead only storing all their video surveillance recordings and data in the Cloud. A deeper review of the global stats shows that the average cloud recording retention period for this stored data was 28.2 days, with organisations in Asia topping the global average at 38 days – 33% higher than was observed in any other region. Improvements in bandwidth and scalability engendered by the Cloud have also helped boost the growing utilisation of audio recordings in addition to visual image capture. Indeed, our research found the number of surveillance cameras with an audio recording facility used by customers jumped more than 200% between 2016 and 2020. Making sense of Big Data The enhanced ease of connectivity and scalable bandwidth made possible by the Cloud is stimulating more companies to connect a lot more video surveillance cameras to their networks. The top motivation for doing so is to generate live metrics and data that can be utilised to deliver enhanced business insights and operational intelligence. In recent years, a rich choice of video analytics solutions have been developed for a variety of industry verticals. The range of functionalities on offer is impressive and covers a variety of applications. Everything from making it easy to classify and track objects and behaviour patterns in real-time, to undertaking anomaly detection, or generating predictions based on past and present events/activities. Data collected via today’s cloud connected cameras can now also be used to feed deep learning training and AI analytics, utilising the unparalleled virtualised processing capacity of the Cloud to convert Big Data into usable information quickly. By integrating this information with data from other enterprise data capture systems, organisations are now able to gain a 360-degree view of their operations – in almost real-time. IT is now in the driving seat No longer the sole preserve of on-site security staff, the wider application and business use of video surveillance means that IT is increasingly taking the lead role where the management and control of these systems are concerned. IT is asked to integrate video surveillance into key enterprise platforms to generate the data that business leaders need Aside from the fact that IT has a vested interest in addressing the cybersecurity implications that come with attaching a growing range of IoT devices to the enterprise network, they’re also increasingly being asked to integrate video surveillance into key enterprise platforms to generate the data that business leaders need. As organisations expand their integration of video with other business applications, such as point of sale, access control, process control and manufacturing systems, this trend is only set to accelerate. Looking to the future Right now, the video surveillance industry is at a key tipping point, as video systems become increasingly strategic for enabling the enterprise to boost productivity, stay compliant, and fulfil its obligations to protect employees and customers. As the technology’s contribution to enhanced data-driven decision-making and problem solving continues to increase, expect the adoption of IP connected video cameras to burgeon as organisations look to capture more data from their day-to-day business operations.

How has Brexit affected the security industry?
How has Brexit affected the security industry?

When the United Kingdom voted to leave the European Union, a world of uncertainty unfolded for those doing business in the UK and the EU. The referendum was passed in July 2016. Including subsequent delays, the separation was completed after four years in January 2020, with a transition period ending December 2020. Even with the deadlines past, there are still pockets of uncertainty stemming from the separation. We asked this week’s Expert Panel Roundtable: How has Brexit affected the security industry?