Cybersecurity researchers have uncovered 'Operation CameraSwarm,' a massive campaign that compromised over 14,530 Dahua devices using advanced authentication bypass techniques.
- Over 14,530 Dahua devices were compromised during 'Operation CameraSwarm.'
- Attackers utilized credential attacks, auth bypasses, and P2P relay techniques.
- The breach was identified via a massive 407 MB exposed directory.
In a major blow to IoT security, cybersecurity researchers at Hunt.io have disclosed a sophisticated campaign that successfully compromised more than 14,530 Dahua devices. The campaign, codenamed 'Operation CameraSwarm,' took place between June 17 and July 22, 2026, highlighting critical vulnerabilities in widely used surveillance hardware.
The investigation began after the discovery of a 407 MB exposed working directory containing 2,616 files. This massive data leak provided the roadmap used by attackers to infiltrate systems. The breach was not a single-method attack; instead, it involved a multi-pronged approach including credential-based attacks, two distinct authentication-bypass flaws, and the use of peer-to-peer (P2P) relay techniques to mask their activity.
Why This Matters
BozokMedia analysis shows that the compromise of surveillance infrastructure represents a high-tier threat to both privacy and network integrity. When an edge device like a security camera is breached, it serves as a gateway for attackers to perform cross-domain privilege escalation, potentially allowing them to move laterally through an entire corporate or home network.
Identity exposure serves as the ultimate unlock for active attack paths, turning a single device breach into a full-scale network compromise.
Historical Background: The vulnerability of IoT devices has been a recurring theme in cybersecurity. As companies like Dahua dominate the global surveillance market, the scale of impact from a single flaw can reach tens of thousands of endpoints, making these devices prime targets for botnet recruitment and espionage.
Security experts urge all users of Dahua and similar IoT hardware to immediately audit their network configurations, update firmware to the latest versions, and move away from default credentials to mitigate the risk of similar exploitation.
Frequently Asked Questions
1. How did the hackers gain access?
They used a combination of stolen credentials, authentication bypass vulnerabilities, and P2P relaying.
2. What should I do if I own a Dahua device?
Ensure your firmware is up to date and change all default passwords immediately.