Threat Intelligence

Over 14,500 Dahua Cameras Hacked in Global Attack Campaign

The Hacker News · 19 Aug 2026
Key Takeaway Change default passwords and keep firmware updated on all internet-connected cameras and security devices to avoid becoming an easy target for mass exploitation campaigns.

Cybersecurity researchers at Hunt.io have revealed details of a campaign that compromised over 14,530 Dahua devices between June and July 2026. Dubbed 'Operation CameraSwarm', the attackers used a combination of credential-based attacks, two known authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique to gain access to internet-connected cameras and recorders.

The scale and methods of the operation were reconstructed after researchers found a 407 MB exposed working directory containing 2,616 files, apparently used by the attackers to organise their campaign. This suggests a systematic, large-scale effort to identify and exploit vulnerable devices rather than a single isolated incident.

Dahua devices are widely used in security and surveillance systems, including by small and medium businesses for CCTV and access control. Devices left with default or weak passwords, or running outdated firmware with known vulnerabilities, are especially at risk of being swept up in campaigns like this one, which can allow attackers to spy on premises, pivot into networks, or add devices to botnets.

IoT Security Surveillance Cameras Dahua Credential Attacks Vulnerability

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.