Researchers at Hunt.io disclosed a large-scale compromise of Dahua surveillance devices spanning June 17 through July 22, 2026. The attack, dubbed Operation CameraSwarm, affected 14,530+ devices through a combination of credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer relay technique.

The researchers reconstructed the campaign from a 407 MB exposed working directory containing 2,616 files. The P2P component proved particularly significant, allowing attackers to establish persistence and lateral movement across compromised devices without direct internet access.

Dahua devices form a substantial share of global surveillance infrastructure. The use of credential attacks indicates attackers leveraged weak or default passwords alongside zero-day or known-but-unpatched authentication flaws. The dual-vulnerability approach suggests attackers exploited both firmware weaknesses and architectural gaps in how Dahua handles credential validation.

The P2P relay tactic expands the attack surface beyond traditional network boundaries. Once a single device falls, attackers can use it as a pivot point to compromise others on the same network segment or even across geographically dispersed installations if they share P2P connectivity.

Organizations running Dahua camera systems should treat this campaign as a direct operational threat. Immediate actions include rotating all default credentials, isolating camera systems on separate network segments, disabling P2P features if not operationally necessary, and applying any available firmware patches. Dahua's public response and patch timeline remain unclear from available reporting.

The 2,616 exposed files suggest attackers maintained detailed operational logs, indicating a sophisticated group with infrastructure to manage large-scale compromise campaigns. The reconstructed working directory provides threat intelligence teams concrete artifacts to hunt for similar activity within their networks.

This incident demonstrates that surveillance hardware represents a critical but often overlooked attack vector. Many organizations deploy cameras with minimal security hardening