To: Tom and Rebecca Re: the camera system — what I found
Hi Tom & Rebecca,
First, sorry this took so long to finally send. I was traveling and couldn't finish the summary until now. Thanks for your patience.
Here's the short version: I found a confirmed cybersecurity breach of the building's video surveillance system. I stumbled onto it while setting up the IntuVision cameras.
The essentials:
It's a real breach. Unauthorized outside parties have administrator control of three of the five internet-connected recorders, each with accounts they created themselves. The pattern looks like more than one party got in over time, not a single event.
How they got in. Those three were reachable straight from the public internet, running older firmware, with a guessable admin password — enough to log in with full rights. I can't tell you after the fact what was actually viewed or copied, but the unauthorized access itself is confirmed. The newer recorder and the main NVR both checked out clean.
What's in scope. This is contained to the surveillance system, which sits on its own segment, separate from the resident network. I only looked at the camera network, not the resident networks. The affected recorders cover reception and the lobby, the parking decks, the elevator lobbies, and a view into the main equipment room.
When. The equipment doesn't keep enough history to pinpoint an exact date, but the access seems to have occurred after the IntuVision 2022 installation, so the window is 2022 to today.
What to do right now. Disconnecting the affected recorders from the internet is cheap, reversible, and worth doing promptly. It stops any ongoing access immediately, and the cameras keep recording locally. Tom and I are already scheduled to meet with Bluesky Monday afternoon.
But that's not the whole fix. Since these units were under outside administrative control, closing it out properly means rebuilding or replacing them and rotating credentials across the whole system — and that carries real hardware cost, labor, and lead time. Better to plan and fund it now than kick it down the road.
A couple of open questions for us. Whether we treat this as an emergency is the Board's call, once you've seen which cameras are affected. One thing to nail down: whether any affected camera carries audio, since admin access can switch on a microphone even if it was turned off.
The Executive Summary attached walks through what I found, why it matters for our building, and what should happen next. The full Technical Security Audit and device-by-device remediation plan contain the supporting evidence and the network routing details. However, because that material spells out exactly how the system was reached, I'm keeping it on a share-on-request basis for the building's camera and network vendors rather than sending it via email. Happy to provide it and walk anyone through it.
A potential silver lining is the prior decision: isolating the camera network a few years ago protected the resident network, which may have severely limited the damage. However, it would be prudent to quickly check the resident network for security, as I did not scan it. Consider changing any easily guessable passwords on any configuration layers or controllers on that network too.
I did this work on my own time and at no charge, as a resident: about ten hours total. Given what it turned up, my honest recommendation is that the Board bring in an independent security review by someone not tied to our current camera or network vendors, so the findings and the fix get checked from outside the setup that let this happen in the first place. I'm glad to help scope that review and to talk anyone through what to look for.