In short: In July 2026 cybersecurity specialists warned that more than a million surveillance and home cameras worldwide are reachable directly from the internet, and at least 87,000 of them run with known, unpatched vulnerabilities. The main causes are the UPnP protocol, which quietly opens ports on your router, and factory default passwords that were never changed. Below is why this happens and how to close access to your own camera in a few steps.
What happened?
In July 2026 European cybersecurity researchers and national authorities issued a fresh warning about the scale of exposed cameras: over a million video devices are openly accessible online, and tens of thousands answer with outdated, vulnerable firmware. This is not one dramatic hack — it is a systemic exposure problem that has been building as more homes and small businesses put cheap IP cameras on the internet without securing them.
The alarming part is how little effort a takeover takes. Anyone can use specialised search engines that index internet-connected devices, find a camera with a default login, and open its live feed — no exploit required. If you run a camera at home, the practical question is simply whether yours is one of them, and the fix starts with your router. We walk through the basics in our guide to securing your home network with a VPN.
Why do home cameras end up open on the internet?
The usual culprit is UPnP (Universal Plug and Play). It lets a device automatically ask the router to open a port for it, with no extra check. Convenient for setup — but it means the camera's video stream and admin interface can become reachable from the open internet without you ever deciding to publish them.
Two more mistakes stack on top. First, unchanged default passwords like admin/admin, which are printed in public manuals for every model. Second, no multi-factor authentication and outdated firmware, so even a known bug stays open for months. Together these turn a private camera into a public one. Tightening the device it all runs through is step one — see our secure router setup guide.
What does this mean for you and your data?
An exposed camera is not an abstract risk. A stranger can watch a live feed of your home, front door or office; harvest location metadata that reveals where the device physically is; and, on some models, run a man-in-the-middle attack to steal the administrator credentials outright. In July 2026, for example, researchers disclosed flaws in TP-Link Kasa EC70 and EC71 home cameras (CVE-2026-9770) where a hardcoded key let an attacker on the same Wi-Fi decrypt traffic and intercept the admin login.
Worse, a camera is a foothold. Once it is compromised, it sits inside your home network alongside your phone, laptop and smart devices — a launch pad for reaching everything else. That is why securing one weak IoT device is really about protecting your whole digital home.
How do I protect my camera and home network?
Change the default password to a unique one. Never keep the factory login. A password manager makes it easy to set a long, unique password for the camera and its app, and turn on multi-factor authentication where the model supports it.
Turn off UPnP and services you do not need. Disable UPnP on the router, and switch off SSH, FTP, Telnet and similar remote services on the camera unless you truly use them. This alone removes most of the exposure.
Update the firmware and isolate the device. Install the latest firmware and app updates, then place cameras and other IoT gadgets on a separate guest or VLAN network, away from your main computers and phones.
Reach your camera the safe way. Instead of opening a port to the internet, access it remotely through a VPN into your home network — the approach security agencies now recommend. Be honest about the limits: a VPN does not fix a camera left on a default password, but it lets you avoid exposing the device publicly at all, and a no-logs VPN like LiMP VPN also encrypts your traffic and hides your IP on untrusted networks. Digital safety is layered — see how on our features page, and find more privacy basics on our blog.
Sources
This report is based on coverage by SecurityLab (Positive Technologies), the Kaspersky Daily blog and Russia's Roskachestvo (July 2026).
