Money and business in the Middle East.

AI

Weak passwords and old firmware leave home cameras open to hackers

Default passwords shipped with residential security cameras are often published online, leaving feeds reachable by outsiders who never need to break anything.

· Originally published by ontime+ · Last verified: 11 Oct 2026 (Nicole Jeffrey)

Key Points

  1. Security researchers say default passwords and outdated software let strangers reach home camera feeds.
  2. A Wall Street Journal visual investigation found hacked webcams have been used to aid warfighters.
  3. Encryption, multifactor authentication and router hardening are the main defenses available to owners.

The latest:

Default passwords shipped with residential security cameras are often published online, leaving feeds reachable by outsiders who never need to break anything. A Wall Street Journal visual investigation found hacked home cameras have been exploited to assist warfighters, and cybersecurity specialists say brand choice, password discipline and router settings determine how exposed a household is.

Details:

  • The exposure: Home security cameras are increasingly popular and hackers are constantly trying to get into them, according to the Wall Street Journal. Its visual investigation documented compromised feeds being used to aid warfighters, placing consumer devices inside a security problem far larger than domestic privacy.
  • The brand factor: Paul Marrapese, a California cybersecurity specialist who has researched hacked webcams, advises avoiding cheap or unfamiliar brands. Established manufacturers prioritize security and push updates when problems surface, he said, because they have reputations to protect.
  • The cheap-device risk: With smaller internet sellers, often selling at lower prices, Marrapese said the risk is greater that known flaws are never fixed or that the devices sit easily exposed on the open web, visible to anyone scanning for them.
  • What to buy: Three features give buyers a head start, according to the guidance: end-to-end encryption, cloud storage for remote viewing, and the ability to create separate user accounts with different levels of access rather than one shared login.
  • Password hygiene: Residential camera systems often ship with default passwords or security codes that are easily found online. The recommendation is a complex, unique password stored in a password manager, with every person who has access holding their own credentials so each login traces to a specific individual.
  • Multifactor authentication: MFA adds a second layer to the login process. Even a stolen or guessed password fails without a code sent to a phone or email or generated by an authentication app such as Google Authenticator, according to the guidance.
  • Access logs: Owners are advised to review the access logs for their account or video stream periodically and look for unexpected logins, the one step that can surface a breach that has already happened rather than prevent a future one.
  • The network link: Most home camera systems connect over Wi-Fi, and protection is only as strong as the weakest link. The advice is a unique network password used nowhere else, plus automatic updates, the router’s built-in firewall and WPA3 security enabled through the internet provider’s app or website.
  • Device settings: On the camera itself, the recommended steps are turning on automatic updates or checking for them periodically, and enabling encryption wherever the device offers it. Both are typically a matter of toggling a few settings.

Between the lines:

The guidance repeatedly points away from the camera and toward everything around it: the router, the password manager, the account structure. Default credentials published online and unpatched firmware are failures that occur before any attacker acts, which is why brand choice and the manufacturer’s update record function as security decisions made at purchase.

What’s next

Owners can check whether their camera supports WPA3 on the router side and end-to-end encryption on the device, and review account access logs for logins they do not recognize.

Read on ontime+ ↗

Weak passwords and old firmware leave home cameras open to hackers · INXEN