Cybercriminals are actively trading access credentials for over 100,000 Chinese surveillance cameras on dark web marketplaces, exploiting an unpatched vulnerability that vendors disclosed nearly a year ago. The cameras remain compromised across thousands of organizations globally, with threat actors demanding payment for authenticated access that grants full control over video feeds and system settings.

The vulnerability affects cameras manufactured by major Chinese vendors and has circulated since early 2024. Organizations failed to deploy patches within the first 11 months of disclosure, creating an extended window for exploitation. Threat actors now harvest credentials from unpatched devices and resell them to other criminals, launching a secondary market for compromised surveillance infrastructure.

This represents a multi-layered organizational failure. Vendors published patches months ago. System administrators did not apply them. Security teams did not inventory their video systems. The result is a predictable supply chain where a known technical flaw converts into operational access sold for profit.

The risk surfaces at multiple levels. Immediate concerns include direct surveillance of physical facilities. Attackers gain real-time video feeds from office buildings, manufacturing plants, retail locations, and data centers. They observe employee movements, identify security routines, and photograph sensitive areas. Video footage also serves as raw intelligence for subsequent break-ins, theft, or social engineering campaigns.

Second-order risks involve lateral network movement. Compromised cameras often sit on corporate networks with inadequate segmentation. Attackers pivot from video systems to access workstations, servers, and databases. A camera breach becomes a foothold for ransomware deployment or data exfiltration. Supply chain attacks also emerge when retailers, logistics firms, or manufacturers face coordinated camera compromises before physical theft or espionage operations.

Organizations operating Chinese surveillance equipment face particular pressure. Many large retailers, hospitals, and international logistics firms deployed these cameras for cost reasons. Industrial facilities in the U.S., Europe, and Asia installed tens of thousands of units. The vendor ecosystem spans Hikvision, Dahua, Uniview, and smaller manufacturers. All share common architecture patterns that ease exploitation once one brand suffers a breach.

The dark web pricing structures indicate mature criminal infrastructure. Access bundles sell from hundreds to thousands of dollars per camera, depending on facility type and credential quality. Bulk deals offer discounts for organizations seeking dozens of simultaneous compromises. This commodification accelerates proliferation across criminal networks previously unconnected.

Mitigation requires immediate action. Organizations must inventory all video surveillance systems and identify those running vulnerable firmware versions. Network segmentation becomes essential. Surveillance cameras should operate on isolated VLANs with restricted outbound access. Credential rotation and multi-factor authentication deployment limit lateral movement from compromised devices.

Vendors bear responsibility for enforcing patch deployment through firmware auto-update mechanisms. Organizations must abandon legacy patch-on-demand models for life-safety systems like surveillance. The 11-month gap between disclosure and widespread exploitation reflects institutional tolerance for known risks.

This situation extends beyond single organizations. Surveillance networks underpin physical security for critical infrastructure. Hospitals, power facilities, and financial institutions rely on camera feeds. Compromised feeds undermine situational awareness during emergencies. The erosion of surveillance integrity affects both theft prevention and incident response capabilities.