Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Dahua Devices Compromised in Large-Scale Credential-Based Attack, Exposing Thousands of Users to Potential Risk

A staggering 14,500+ Dahua security cameras and recorders have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) protocols. The breach is particularly concerning due to the widespread nature of the affected devices, which are used in various industries, including education, healthcare, government institutions, and commercial establishments.

The attackers exploited vulnerabilities in Dahua’s software to gain unauthorized access to the devices. According to reports, credential attacks, where hackers use stolen or weak passwords, were a primary means of entry. This was often accompanied by authentication bypasses, which allowed the attackers to sidestep traditional login mechanisms. In some cases, P2P protocols – designed for remote monitoring and control – were also leveraged to facilitate lateral movement within the compromised networks.

The affected devices are equipped with Dahua’s proprietary software, which is known to have several security flaws. While Dahua has issued patches and security updates in the past, it appears that many users have failed to apply these fixes or may be running outdated firmware versions. This lack of vigilance has created an environment ripe for exploitation.

The compromised devices are now being used as a launching pad for further attacks on the targeted networks. Hackers can potentially use the affected cameras and recorders to gain access to sensitive areas, eavesdrop on conversations, or even disrupt critical operations. The widespread nature of this breach highlights the need for improved cybersecurity measures in industries that rely heavily on connected devices.

It’s also worth noting that the attack methods employed by the hackers – credential attacks, authentication bypasses, and P2P exploitation – are not particularly sophisticated but rather effective due to their low-hanging fruit nature. This serves as a reminder that even seemingly simple security vulnerabilities can have devastating consequences when left unaddressed.

As the cybersecurity landscape continues to evolve, it’s essential for users of Dahua devices and other connected systems to prioritize regular firmware updates, strong password management, and network segmentation. By doing so, they can minimize their exposure to potential risks and ensure that their security posture remains robust in the face of ever-present threats.


Source: The Hacker News — 2026-08-19