Hacked Security Camera Feeds Exposed 150,000 Internal Video-Surveillance

The internet has given lots of conveniences, and one of the many conveniences is to conduct surveillance through security cameras, accessible remotely by authorized people.

But apparently, the term "authorized" is vague, since data is only put behind login credentials, and data can flow in and out of servers, sometimes unprotected.

An example of such breach, was experienced by a Silicon Valley startup Verkada, Inc.

Verkada, founded in 2016, sells security cameras that customers can access and manage through the web. The company specializes in security cameras, access control, and environmental sensors, by replacing "obsolete equipment with technology that’s smart, secure and easy to manage,” explains the company’s security cameras overview.

Those cameras are meant to be managed online, but they are supposed to be secure.

But this time, the company had its servers breached, with hackers claiming to have full access to a massive trove of around 150,000 security-camera data collected by the company, from companies that include electric carmaker Tesla, software provider Cloudflare, and also Verkada itself.

In addition, hackers were able to view video feeds from inside women’s health clinics, psychiatric hospitals and among others, also includes gyms, hospitals schools, police stations, correctional facilities and prisons.

Verkada hack, Tesla warehouse feed.
A screenshot of a Verkada camera's feed inside a Tesla warehouse.

This kind of breach can expose and breach many things that are considered private and not for public viewing.

For example, one camera feed inside Florida hospital Halifax Health showed what appeared to be eight hospital staffers tackling a man and pinning him to a bed.

Another video feed, which was shot inside a Tesla warehouse in Shanghai, showed workers working on an assembly line.

Then, there is a video from a feed taken in a police station, showing officers questioning a man in handcuffs.

Other cameras, lare placed in more discreet locations.

For example, there was a feed that shows Verkada employee who had set one of the cameras up inside his home. One of the saved clips from the camera shows the employee completing a puzzle with his family.

Another example, was from inside prisons, where the cameras are hidden inside vents, thermostats and defibrillators, as they are meant to track inmates and correctional staff using the facial-recognition technology.

In many of the videos, the hackers say they included audio. All of the videos were taken in 4K high-definition resolution.

Tesla said that, “based on our current understanding, the cameras being hacked are only installed in one of our suppliers, and the product is not being used by our Shanghai factory, or any of our Tesla stores or services centers. Our data collected from Shanghai factories and other places mentioned are stored on local servers.”

“This afternoon we were alerted that the Verkada security camera system that monitors main entry points and main thoroughfares in a handful of Cloudflare offices may have been compromised,” San Francisco-based Cloudflare said in a statement. “The cameras were located in a handful of offices that have been officially closed for several months.” The company said it disabled the cameras and disconnected them from office networks.

[block:block=87]
Verkada hack, Cloudflare office feed.
A screenshot of a Verkada camera's feed at one of Cloudflare's offices.

The data breach was said to have been carried out by an international hacker collective, and intended to show the pervasiveness of video surveillance and the ease with which systems could be broken into, said Tillie Kottmann, one of the hackers who claimed credit for breaching San Mateo, California-based Verkada.

The Swiss hacker that has previously claimed to also have hacked chipmaker Intel Corp. and carmaker Nissan Motor Co., called the hacking collective “Advanced Persistent Threat 69420” Arson Cats, a light-hearted reference to the designations cybersecurity firms give to state sponsored hacking groups and criminal cybergangs.

Describing the group as a small collective of “primarily queer hackers, not backed by any nations or capital but instead backed by the desire for fun, being gay and a better world,” on behalf of the group, Kottmann said that their reasons for hacking are “lots of curiosity, fighting for freedom of information and against intellectual property, a huge dose of anti-capitalism, a hint of anarchism - and it’s also just too much fun not to do it.”

The hack “exposes just how broadly we’re being surveilled, and how little care is put into at least securing the platforms used to do so, pursuing nothing but profit,” Kottmann said. “It’s just wild how I can just see the things we always knew are happening, but we never got to see.”

Besides having full access to live feed, Kottmann also said that the group have access to the full video archive of all Verkada customers.

This was possible because Kottmann said that the group was able to obtain “root” access on the cameras by accessing the 'Super Admin' account.

What this means, besides full access, the hackers could execute their own code, if they wanted to. That access could, in some instances, allow them to turn the cameras into botnets, creating a platform for future hacks.

Other data that the hackers had access to, include Verkada customers' usernames and email addresses, that according to the company's security update page.

Obtaining this degree of access to the camera didn’t require any additional hacking, as it was a built-in feature in Verkada, Kottmann said.

As a matter of fact, Kottmann said that the group found the username and password for the administrator account publicly exposed on the internet.

Verkada hack, jail feed.
A screenshot of a Verkada camera's feed inside a prison.

Kottmann even said that the group was able to download the entire list of Verkada customers, as well as the company’s balance sheet, which lists all of its assets and liabilities.

It should be noted that as a closely held company, Verkada does not publish its financial statements.

“If you are a company who has purchased this network of cameras and you are putting them in sensitive places, you may not have the expectation that in addition to being watched by your security team that there is some admin at the camera company who is also watching,” said Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, who was briefed on the breach by Bloomberg.

"Security cameras and facial-recognition technology are often used inside corporate offices and factories to protect proprietary information and guard against an insider threat," said the EFF’s Galperin.

“There are many legitimate reasons to have surveillance inside of a company,” Galperin added. “The most important part is to have the informed consent of your employees. Usually this is done inside the employee handbook, which no one reads.”

In response, Verkada has disabled the feeds for external viewers, and has disabled all internal administrator accounts to prevent any unauthorized access. The company said it has notified law enforcement and customers.

Verkada has also assembled both internal and external teams investigating the matter, a spokesman for the company said.

The company is also working to notify customers and set up a support line to address questions, said the person, who requested anonymity to discuss an ongoing investigation.

“We have disabled all internal administrator accounts to prevent any unauthorized access,” a Verkada spokesperson said in a statement. “Our internal security team and external security firm are investigating the scale and scope of this issue, and we have notified law enforcement.”

It was only after the news went viral that the hackers lost access to the video feeds and archives, Kottmann said.

But for two days, the hacker said, the group's access was unhindered.

Kottmann said the hacker collective doesn't set out after specific targets. Instead, it scans organizations on the internet for known vulnerabilities and then works to “just narrow down and dig in on interesting targets.”

Issues at Verkada can be traced back to October 2020, when the company fired three employees after reports surfaced that workers had used its cameras to take pictures of female colleagues inside its offices to make sexually explicit jokes about them.