Dahua Security Cameras Exposed to Mass Hacking Due to Lax Password Policies and Flaws in Authentication Protocols
A staggering 14,500+ Dahua surveillance cameras have been compromised by hackers using a combination of credential attacks, authentication bypasses, and peer-to-peer (P2P) exploits. The vulnerability lies in the lax password policies implemented by Dahua’s customers, which allowed attackers to gain unauthorized access to the devices.
The widespread hacking campaign was only recently discovered, but it is believed to have begun several months ago. Dahua security cameras are widely used for commercial and residential applications, and their popularity has made them a prime target for hackers seeking to exploit vulnerabilities in IoT devices. The compromised devices are located across various countries, including the United States, China, and other parts of Asia.
At its core, this hacking campaign is an example of how identity exposure can lead to active attack paths. When users choose weak passwords or fail to implement robust authentication protocols, they inadvertently create opportunities for hackers to gain access to connected devices. In this case, attackers used a combination of credential attacks – where they guessed or brute-forced the login credentials – and authentication bypasses – where they exploited flaws in Dahua’s software that allowed them to skip the login process altogether.
Once inside, the hackers leveraged P2P exploits to move laterally across the network, essentially creating a pathway for further exploitation. This is particularly concerning, as it suggests that the attackers may have gained access to sensitive data stored on these devices or used them as a springboard for more targeted attacks on other systems within an organization.
The Dahua hacking campaign serves as a stark reminder of the importance of robust password policies and authentication protocols in IoT device security. As the number of connected devices continues to grow, so too does the attack surface, making it essential for users to prioritize security best practices when configuring their devices. This includes implementing strong passwords, enabling two-factor authentication (2FA), and regularly updating software and firmware.
In light of this incident, we urge Dahua customers – as well as those using similar surveillance cameras from other manufacturers – to review their password policies and ensure they are adequately protecting their devices against unauthorized access.
Source: The Hacker News — 2026-08-19