Confidential ยท Restricted Distribution

Video Surveillance Security Assessment

Executive Summary
PropertyThe Gallery
Assessment period22 - 25 July 2026
Prepared byAref Kashani

Bottom line The building's camera system records residents, guests, and deliveries throughout the lobbies, elevators, corridors, amenity areas, and parking. Unauthorized parties have gained standing administrator access to three of the building's five internet-exposed recorders, with accounts tied to an organized camera-hijacking operation (“CamhubfreeTG”). The system is reachable from the public internet, was protected only by a guessable administrator password, and is built on equipment the U.S. government has restricted on national-security grounds. Because these recorders already had attacker admin access, changing passwords and closing the internet openings is not enough: the affected units must be rebuilt from known-good firmware or replaced (not just factory reset), every credential across the system must be rotated.

Scope of this review: the assessment covered the building's surveillance network. The compromise is confined to the video recorders and cameras, which sit on a segment separated from the resident network. Residents' own networks and personal devices were outside the scope of this review and were not examined. It is recommended that the resident network be quickly validated for any suspicious activity or unexpected cross-talk across the segments.

3 / 5
Recorders already breached
77
Devices on the network
4
Cameras unpatchable (replace)
25
Attacker-created admin accounts found

1What we found

01Three recorders have already been accessed by unauthorized partiesCritical

Three of the building's five internet-exposed recorders already have administrator accounts on them that nobody at the building or its vendors created: 25 such accounts across the three. Several are attackers' “calling cards,” including one (CamhubfreeTG) that matches an organized operation known for trading footage from hijacked cameras. The account patterns indicate more than one outside party gained access over time, not a single clean break-in: two of the recorders share one intruder's account set, while the third additionally carries a distinct second cluster of accounts seen nowhere else. In practice that means there is no single point of entry to close, and no basis to assume the intruders are related or share intent.

What was visible through these three recorders: common areas on one (lobby, front desk, the gallery/event space, gate and side entries); the full parking structure across every level on another, including vehicles and potentially legible license plates; and, on the third, interior hallways plus a camera view of the building's network equipment closet. That last item is particularly sensitive: it exposes the physical network infrastructure itself, not just hallways or parking, which is a materially different kind of exposure. The two remaining internet-exposed recorders were also checked and show no sign of unauthorized access.

On timing: on each affected recorder, every unauthorized account was created after the integrator's own maintenance account, which was added when the system was set up. That places the intrusions after the 2022 installation rather than before it. The recorders do not retain activity logs far enough back to fix a precise date, so the accurate statement is that the access occurred sometime between 2022 and now.

02The system placed itself on the public internetCritical

The recorders automatically created firewall openings, using features called UPnP and P2P/cloud, and are now reachable from the public internet. This includes the automated scanners that routinely look for this type of equipment. The exposure was not necessarily set up by anyone; the devices created it themselves, and will recreate it unless the features are disabled.

03The administrator password was guessableCritical

The administrator password follows a predictable pattern: the installer's company name followed by the digit 1. The equipment's own password-strength indicator rates it as weak. The built-in lockout (five attempts, then a 30-minute pause) provides little protection in this case. It is designed to stop large-scale blind guessing, but a person who knows the installer needs only a few attempts. An admin interface that is both reachable from the internet and guessable is how the access described in Finding 01 was possible.

04Four cameras are obsolete and cannot be fixedCritical

Four cameras run 2017-era software that the manufacturer no longer updates. They carry serious flaws that allow takeover without a password, a category the U.S. Cybersecurity and Infrastructure Security Agency (CISA) lists as actively exploited. No patch is available, so these cameras should be replaced.

05U.S.-restricted foreign vendor with a cloud “phone-home” featureHigh

The equipment (Dahua) is barred from U.S. federal use and from new U.S. sales on national-security grounds, and the manufacturer is on a U.S. human-rights sanctions list. The equipment is configured with internet access, and a recorder's cloud “phone-home” feature was observed connected during the assessment. Whether the cameras themselves are permitted internet access is not confirmed, and the available signs are not encouraging; confirming it requires the router login. Deliberate data exfiltration by the vendor is not proven. For a building with high-profile residents, a reasonable approach is to block the cameras from reaching the internet, which also removes the question.

06The recorders' built-in defenses are turned offMedium

On the recorders inspected, the on-device firewall, denial-of-service protection, and video-stream encryption are all disabled. As a result, resident video travels the network unencrypted, and a recorder can be taken offline (a loss of recording) with limited effort. Only the login lockout is enabled.

2Why this matters for this building

A surveillance system is both a privacy system and a physical-security control, and this one has been compromised: unauthorized parties hold administrator access, had the ability to view live and recorded footage at will and should be assumed to have done so, and can reach any credentials stored on the system. The compromised cameras cover the building's common areas, reception and entrances rather than individual units, but someone watching those feeds can still observe residents' comings and goings, follow a specific person's movements through the building, or identify when to follow an authorized person into a secured common area. Because the access is administrative rather than a simple video feed, the same parties can also disable or black out cameras on demand, including to remove coverage during a physical entry, although less likely given most fingerprints have CISA tags from around the world (ethical hacking groups) vs local threats. Lastly, the Board may be bound to privacy and fiduciary responsibility for this footage. This is not legal advice, but because breach-notification timelines and cyber-insurance notice provisions commonly run from the date a breach is discovered rather than the date it is fixed, the Board may want to confirm with its attorney whether any resident-notification or insurer-notice obligations apply (late notice to an insurer can itself jeopardize coverage).

3What we recommend

These are incident-response actions, not hardening suggestions. The Priority 0 steps should begin promptly, in roughly this order.

Priority 0. Contain now: cut the recorders off from the internet

Remove the recorders' reachability from the public internet: close the inbound port-forwards, disable UPnP and the vendor cloud/P2P service, and block their outbound traffic. This is the single fastest step: it closes the openings attackers use and cuts any connection back to them, and it does not depend on logging into a device that is already compromised. Reception currently views the cameras over the public IP from a separate segment; preserve that by adding one controlled local route from the reception workstation to the recorders, limited to the viewing ports, so the front desk keeps its view while nothing is exposed outward.

Priority 0. Rebuild or replace the breached recorders: assume the intruders are still on them

Deleting the rogue accounts and changing passwords does not evict an attacker who already has full control of a device: it can hold hidden accounts, altered settings, or modified firmware that a simple cleanup will not remove. Each affected recorder must be fully factory-reset and reloaded from known-good firmware and rebuilt from scratch, or replaced. The three affected units are the oldest, end-of-life generation in the building and cannot be brought to a current security standard: plan to replace them rather than patch. This is where real hardware cost and lead time come in.

Priority 0. Rotate every credential across the whole system

“Change the passwords” on the affected recorders is not enough. Assume every stored credential on this network is in attacker hands and rotate all of them: every camera and recorder, the router/gateway, the analytics PC, and every email, dynamic-DNS, and cloud account tied to the system, with strong, unique, centrally-managed passwords.

Priority 0. Preserve evidence, notify the board. Consider insurer and FBI report.

Before wiping any device, preserve the evidence already captured (account lists, logs, configs). While I have collected evidence, it has not been exhaustive. Notify the board and the association's legal advisors. Breach-notification and insurer-reporting clocks may already be running, and late notice can jeopardize coverage (if applicable/required). Because the intruders are tied to an organized operation, a report to the FBI (via IC3, ic3.gov) is worth considering once the review establishes which cameras were exposed and whether any could have been used to capture audio. Until then, it's recommended to limit disclosure to those who need to know.

Priority 0. Check for other footholds, and note the audio exposure

An unidentified small computer on the surveillance network (reachable only by a remote key its owner holds) is still unaccounted for and could be a standing access point: identify and remove or bring it under control. Inspect the analytics PC and the router for signs of the same attackers, since a controlled recorder can be used to reach them. Note too that several cameras carry microphones, so this is a potential live-audio (eavesdropping) exposure in common areas, not only video: administrative access can switch on a camera's microphone even where it was disabled in the configuration, so part of the review is establishing which cameras have microphones and whether any were turned on.

Priority 0. Take the system off the internet for good

Once contained, close the exposure permanently: disable UPnP and P2P/cloud on every device, remove the router's port-forwards, and block the cameras and recorders from reaching the internet. Provide remote viewing only through a private encrypted connection (a VPN such as Tailscale). Updating firmware is not a substitute for this: new vulnerabilities against this device family are found on an ongoing basis (Dahua published one as recently as June 2026), so a fully patched recorder that stays reachable from the internet is exposed to the next one, and firmware needs an ongoing review cycle regardless. Getting the system off the internet is what actually closes the exposure.

Priority 1. Replace the four obsolete cameras

They cannot be patched. Prefer a manufacturer that is not U.S.-restricted.

Priority 2. Enable the device defenses and update firmware

Turn on the on-device firewall, denial-of-service protection, and stream encryption; apply current firmware; and disable the vendor cloud. These provide defense in depth once the system is off the internet.

What we could not yet confirm

One item could not be verified within this assessment, and it does not change the priorities above: whether the cameras specifically (as distinct from the recorders) have blocked internet egress. A host on their network reached the internet, but confirming a per-device block requires the router login. However, the initial signs are not promising: the cameras are confirmed to be reaching external internet-bound time-servers.

Target state. The breached recorders have been rebuilt or replaced and are confirmed clean; nothing in the surveillance system is reachable from the public internet; remote access is via VPN only; every credential across the system has been rotated to a strong, unique value; obsolete hardware is replaced; and the cameras cannot reach external cloud services. Reaching it requires incident response and hardware replacement, not configuration changes alone.