Following a combined U.S.-Israeli airstrike on February 28 that resulted in the death of Iran’s Supreme Leader, Ayatollah Ali Khamenei, numerous high-ranking Iranian officials have also been killed. The Associated Press reported, citing two undisclosed sources—one an intelligence official and the other briefed on the operation—that compromised Iranian surveillance cameras facilitated the planning of the initial assault.
The unauthorized access to surveillance cameras has emerged as a consistent element in contemporary conflicts. Examples include Hamas compromising Israeli cameras ahead of the October 7, 2023, attack, Russia utilizing hacked cameras in Ukraine, and Iran doing the same in Israel. Significantly, these aren’t advanced espionage tools; rather, they are typically ordinary cameras, akin to the millions of consumer devices globally.
Due to their affordability, widespread availability, and constant operation, cameras present exceptionally valuable targets. Vulnerable camera feeds can expose critical information, such as the residences of officials, the movement patterns of convoys, and the entry and exit times of individuals from specific buildings. Furthermore, emerging AI capabilities can transform this vast quantity of video data into actionable and searchable intelligence.
On supporting science journalism
Should you find this article engaging, please contemplate supporting our esteemed journalism through a subscription. Your purchase contributes to securing the ongoing creation of influential narratives concerning the breakthroughs and concepts that are defining our contemporary world.
The fundamental weakness lies in straightforward exposure. Matt Brown, an Internet-of-Things (IoT) security researcher and the founder of Brown Fine Security, highlights that a significant number of cameras are practically accessible to anyone with an internet connection. He states, “If there’s not good security in place, somebody can maybe log in to it and view the video feed.”
Discovering an insecure camera can occasionally be less challenging than actively hacking it. Services like Shodan and Censys function as a “Google” for the Internet of physical devices, mapping everything from webcams to infant monitors and medical gear by scanning the internet. Brown notes, “Some cameras don’t require any access. You can just browse public camera feeds.” For others that do prompt for a password, attackers can often gain entry by trying a limited set of widely used default credentials if the user hasn’t modified the factory settings.
Even when cameras are not directly exposed online, their foundational design frequently contains significant weaknesses. Paul Marrapese, a San Jose, California-based security researcher, has dedicated years to investigating this issue. In 2019, he uncovered severe vulnerabilities in millions of cameras, baby monitors, and doorbells marketed under numerous brands but produced by a limited number of Chinese manufacturers relying on common software libraries.
A common method involves peer-to-peer (P2P) connections for simplified installation: users merely plug in the device, input a unique identifier (UID), and can then monitor their premises remotely. The camera routinely communicates with central servers to update its location. Upon a user’s connection attempt, the server directs them on how to access the device.
However, this system contains exploitable flaws. Marrapese identified vulnerabilities within the firmware utilized by millions of devices. By leveraging UIDs, he was able to locate specific devices and estimate their geographical positions, as well as intercept their connections. He explained, “You didn’t even need the password. If you were able to make the connection through peer-to-peer, there was a vulnerability that you could send over that would just give you full, unrestricted root access on the camera.”
Even more concerning is the relay mechanism. In instances where direct Wi-Fi links are unsuccessful, certain manufacturers covertly configure customer cameras to function as relays for other devices. Marrapese points out, “What you may not realize is your camera may also be volunteering for the vendor’s network to help facilitate other people’s connections.” Any party monitoring this relay traffic would be able to capture passwords and video feeds. The unique identifier (UID) embedded in each device is permanent and cannot be altered, even through firmware wipes or upgrades.
For high-value targets, the challenge lies in penetrating closed systems. Brown hypothesizes that the situation in Iran involved cameras situated on a private network, inaccessible from the public internet. He explains, “By default, people from the Internet can’t just connect into devices on your home network.” Government camera networks are typically even more fortified. He adds, “But once you gain access to that private network—that’s the hard part—then it gets easier. Their security model almost assumes bad guys won’t have access and therefore don’t require passwords on the cameras.” This scenario is akin to a digital drawbridge: once breached, it reveals a castle where all inner rooms are unsecured.
To infiltrate such systems, intelligence organizations conduct laboratory testing on adversary hardware. For instance, Israel might acquire the specific camera models employed in Iran and enlist experts with capabilities similar to Brown’s to dismantle them and uncover previously unknown vulnerabilities.
Brown personally procures devices from eBay or salvages them from e-waste containers. Among his findings was an automated license plate reader—the type typically installed on highway overpasses to record passing vehicles. Through reverse-engineering, he discovered that these cameras transmitted not only video but also detailed vehicle data, including license plate numbers, makes, and models. An online search revealed over 150 such devices openly streaming to the internet. He commented, “Those are supposed to be on private networks, not where any random person sitting in their house can gain access.”
This vulnerability highlights a broader evolution: cameras are increasingly transmitting not just visual feeds but also analytical data. Brown observes, “When machine learning first rolled out, they shipped video data back to a data center, and then it was all processed on powerful computers.” Presently, due to advancements in specialized processors, this analysis is performed directly on the camera—a paradigm referred to as edge computing.
As an illustration, certain surveillance cameras are capable of sending digital facial representations alongside the video feed, enabling computer systems to identify individuals even from low-resolution images. A system designed for purposes such as identifying dissenters or ensuring compliance with mandatory hijab regulations could, if breached, grant an unauthorized party access to this identical data stream.
Should remote hacking prove ineffective, intelligence agencies possess the option to interfere with the supply chain. Brown states, “Intelligence services are known to either become the provider or intercept equipment en route and make malicious modifications.” For example, in 2024, Israeli operatives penetrated Hezbollah’s supply chain, utilizing front companies to distribute pagers and walkie-talkies equipped with explosives to members. The concept of cameras pre-loaded with back doors is a readily conceivable threat.
Marrapese asserts, “Cameras are sort of perfect. It’s not only a foothold in the network but you have microphones; you have video. You can, a lot of times, even view previous footage.” Regarding the persistent difficulty in securing them, he notes, “A lot of it really is the human element. Sometimes it’s just some stupid configuration issue. And then patching can be a nightmare.” Even when software updates are available, the logistical challenge of deploying them across millions of dispersed cameras is immense. Marrapese prompts, “Think of any IoT devices in your house. When’s the last time you went and checked if that was up to date? Probably never.”