Ireland's CCTV cameras vulnerable to hacking, warns global cyber firm

Analysis found Ireland had 13,350 internet cameras in operation. Of these, some 4,918 were assessed as being vulnerable to hacking.

Analysis found Ireland had 13,350 internet cameras in operation. Of these, some 4,918 were assessed as being vulnerable to hacking.

Ireland is the most vulnerable country for unsecured internet CCTV systems out of 35 European states studied — exposing organisations and the State to potential infiltration by criminals and hostile states, it has emerged.

The assessment comes after Dutch intelligence agencies issued a public warning that Russian security services were “systematically conducting” digital espionage operations via cameras that are connected to the internet.

In a joint advisory, the civilian and military intelligence agencies of the Netherlands said not only was its systems being targeted, but also EU and Nato states.

An analysis of the advisory by global cyber company Censys identified more than 87,000 internet cameras across 35 European countries, which it said had a “potentially exploited vulnerability”, that could be accessed by external hackers.

It found Ireland had 13,350 internet cameras in operation (18th highest out of the 35 countries). Of these, some 4,918 were assessed as being vulnerable to hacking.

This was the sixth highest of the 35 states in absolute numbers, which was dominated by the large-population countries, such as the UK, Italy, France, and Germany.

In terms of the proportion of its cameras that were vulnerable, Ireland was the highest, by some distance, with 37% of cameras unsecured.

This is nearly three times greater than the next highest countries, such as France and Italy, both at 13%, and compares to 6% in the UK and just 4% in the Netherlands — the country that issued the warning.

In the analysis by Censys, its principal security researcher Martijn Grooten said the Dutch warning again highlighted the vulnerability of these cameras, even when the devices themselves may not reveal “any interesting data”.

He said the potential impact went beyond a threat to cameras at military installations, which was the focus of the Dutch advisory, to include “an unpatched camera at a manufacturing plant’s loading dock, an energy utility’s substation perimeter or a bank branch’s exterior”.

Mr Gooten said: “They’re [the cameras] a live feed of physical operations, revealing shift changes, shipping schedules, security patrol timing, or which entrances go unguarded overnight.” 

He said spying did not require breaching a corporate network first and a single unpatched camera “can hand a competitor, criminal group, or state actor, months of low-cost reconnaissance on how the physical site actually runs”.

Irish cyber expert Brian Honan said the risk posed by internet cameras was not new and previous concerns were also expressed about other smart devices or internet-enabled devices, such as connected baby monitors.

Irish cyber expert Brian Honan said hackers could seek to access cameras for a range of reasons: 'They can use them to observe who is accessing the facility, identify patterns of access for individuals that they may want to target, gather information about the activity the camera is monitoring, or to turn cameras on and off to facilitate physical attacks.'
Irish cyber expert Brian Honan said hackers could seek to access cameras for a range of reasons: 'They can use them to observe who is accessing the facility, identify patterns of access for individuals that they may want to target, gather information about the activity the camera is monitoring, or to turn cameras on and off to facilitate physical attacks.'

But in relation to the Dutch advisory and the Censys analysis, he said: “This is something that Ireland could be vulnerable to, particularly if organisations are not installing internet-connected cameras securely and are not regularly maintaining them to keep their software and firmware updated to protect against any vulnerabilities.” 

“Intelligence services, and indeed criminals, will try to access internet-connected cameras using the default login credentials that manufacturers may configure into the devices, breaking into the cameras using weak or stolen login credentials, or exploiting software vulnerabilities, or weaknesses, to connect to the devices and control them.” 

He said this was illustrated when Russian security services hacked into EU border cameras, which was detailed in a study published last year by the Robert Lansing Institute, a think tank.

This study found the Russian agencies were targeting surveillance and traffic camera systems to gain intelligence on troop movements, border security, and also critical infrastructure.

In addition, it said these hacks also served to “intimidate EU states and weaken public trust in their governments’ ability to ensure national security" and could form part of a wider hybrid attack.

Mr Honan said hackers could seek to access cameras for a range of reasons: “They can use them to observe who is accessing the facility, identify patterns of access for individuals that they may want to target, gather information about the activity the camera is monitoring, or to turn cameras on and off to facilitate physical attacks.” 

He said there was a potential wider threat: “Alternatively, if the cameras are connected to an organisation's network, the attacker can use the compromised camera as a launchpad for attacks against other systems on the network.” 

Mr Honan said if cameras needed access from the internet to facilitate the likes of remote monitoring by a security team, then access to the cameras “should be restricted using multifactor authentication if it is available, and restricting access to the cameras to known and trusted internet connections”.

In response to queries about the Dutch warning and what steps Irish authorities had taken to counter the threat, the Department of Justice said the National Cyber Security Centre (NCSC) was “aware” of the advisory.

The department’s statement said: “The NCSC does not comment on operational matters or on its cyber threat intelligence capacity.” 

But the statement goes on to point out any device connected to the internet wasa “capable of being exploited” and internet-connected CCTV cameras were no exception.

“The NCSC advises users and organisations to keep such devices updated, to change default settings and credentials, and to restrict their exposure to the public internet to that required for their function.” 

The centre said it provided guidance for organisations on its website.

It added this matter would also be covered in a forthcoming EU regulation: “Under the EU Cyber Resilience Act, obligations on manufacturers to report actively exploited vulnerabilities and severe incidents take effect from September 2026, with the fuller set of product security requirements applying from 2027.” 

In a brief statement, Garda HQ said: “An Garda Síochána is aware of the potential exploitation of such devices. An Garda Síochána does not comment on matters of national or international security.”

x

More in this section

Lunchtime News

Newsletter

Get a lunch briefing straight to your inbox at noon daily. Also be the first to know with our occasional Breaking News emails.

Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited