Hackers Compromised More Than 14,500 Cameras Made By Major Surveillance Company in Large Scale Camera Attack

Cybersecurity researchers have uncovered a large-scale hacking campaign that compromised more than 14,500 Dahua surveillance cameras and other devices. The campaign, dubbed Operation CameraSwarm by researchers at Hunt.io, was active between June 17 and July 22, 2026, and primarily affected devices located in Ukraine and Russia. Investigators discovered evidence of the operation after finding an exposed directory containing hundreds of megabytes of data, including attack tools, logs, shell histories, credentials, and records of compromised cameras.

According to Hunt.io, the attackers compromised at least 14,530 Dahua devices through several different techniques. One of the primary methods involved credential attacks against internet-accessible cameras. Researchers identified more than 12,000 unique IP addresses associated with the campaign and found evidence that attackers were scanning for vulnerable devices and attempting to gain access using stolen, guessed, or otherwise obtained credentials.

The attackers also took advantage of two older authentication-bypass vulnerabilities, identified as CVE-2021-33044 and CVE-2021-33045. These flaws affect certain Dahua cameras and related products and can allow attackers to bypass normal authentication protections. Hunt.io determined that approximately 1,923 cameras were compromised through this method. The attackers used a tool known as p2pwn to establish a persistent account on affected devices, potentially allowing continued access even after users changed their passwords.

A separate attack technique involved Dahua’s peer-to-peer, or P2P, connectivity system. Researchers identified 283 cameras that were reached through this method, including devices located behind network address translation, which normally makes directly accessing a device from the internet more difficult. The technique relied on device serial numbers and Dahua’s relay infrastructure to establish a communication path to cameras.

The investigation also uncovered evidence that the attackers were able to exploit Dahua’s password-recovery mechanisms. The campaign’s tooling reportedly used camera serial numbers to generate recovery codes, potentially allowing attackers to reset access without knowing the existing administrator password. Researchers found that a large percentage of live serial numbers tested during the investigation appeared to expose an accessible communication channel, although some of the campaign’s specific statistics have not been independently confirmed.

The two authentication-bypass vulnerabilities used in the campaign are not new. Dahua disclosed them in 2021 and released firmware updates designed to address the security issues. The vulnerabilities have also remained on the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, highlighting the fact that attackers continue to take advantage of older flaws when vulnerable devices remain exposed online.

Researchers believe the operation was conducted by a Russian-speaking threat actor based on language found in the recovered files and tools. However, Hunt.io has not attributed the campaign to a specific hacking group or government organization. Investigators also believe that some of the tools may have been designed to allow access to compromised cameras to be transferred to another party.

The discovery demonstrates the risks associated with internet-connected surveillance equipment that is not properly secured or maintained. Cameras and network video recorders can provide attackers with more than just access to video feeds; once compromised, they may also become persistent footholds inside networks or be used as part of broader attacks.

Organizations and individuals using affected Dahua devices should update their equipment with the latest vendor-provided firmware and ensure that strong, unique passwords are being used. Unnecessary accounts should be removed, and P2P functionality should be disabled when it is not required. Security teams should also consider isolating surveillance systems from other critical network resources and checking devices for unfamiliar accounts or other indications of compromise.

The CameraSwarm campaign serves as another reminder that security cameras should be treated like any other network-connected computer. Leaving them exposed to the internet, failing to apply security updates, or relying on outdated credentials can give attackers an opportunity to gain persistent access. Hunt.io’s findings also demonstrate how attackers can combine several relatively straightforward techniques to compromise thousands of devices on a global scale.