Over 14,000 Dahua Cameras Compromised in Ukraine and Russia

Over 14,000 Dahua Cameras Compromised in Ukraine and Russia

First seen 21 Aug 2026, 16:48 UTC Ciberseguridadlatam 92% similarity 75.0

Article Content

Browse articles
ThreatCluster

Between June 17 and July 22, 2026, a threat actor exploited vulnerabilities in over 14,000 Dahua cameras, primarily in Ukraine and Russia. The attack utilized flaws from 2021 and shared SDK credentials, with 89% of the compromised devices lacking passwords. This incident highlights significant security weaknesses in the deployment of these cameras, impacting critical surveillance systems in the region. The exposure of a directory containing sensitive information facilitated the attack, underscoring the need for enhanced security measures. The incident lasted for five weeks, raising alarms about the potential for further exploitation of similar vulnerabilities in the future.

Key Points: • More than 14,000 Dahua cameras were compromised, primarily in Ukraine and Russia. • The attack exploited vulnerabilities from 2021 and used shared SDK credentials. • 89% of the affected cameras did not require a password, highlighting severe security flaws.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
Attack on Dahua cameras began
A threat actor started exploiting vulnerabilities in Dahua cameras, affecting thousands of devices.
Ciberseguridadlatam
2026-07-22
Attack on Dahua cameras ended
The exploitation of over 14,000 Dahua cameras concluded after five weeks of control by the threat actor.
Ciberseguridadlatam
2026-08-21
Incident reported
Ciberseguridadlatam published details about the compromised Dahua cameras, revealing the extent of the attack.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story