2021 Verkada — support/Jenkins path; super-admin replay; camera & access-control data exposure
Data compromised
Live video/imagery for affected tenants; access-control and Wi-Fi credentials for some customers; Command user directory (names, emails); sales-order listings
Technical writeup
Verkada disclosed unauthorized access to its platform beginning March 8–9, 2021, via a compromised internet-facing Jenkins-style customer-support environment and abuse of highly privileged support accounts. The company’s incident report attributed activity to a known hacktivist and stated attackers accessed live video or image data for 97 customer accounts (plus related access-control and Wi-Fi credential material for a narrower subset) and exfiltrated Command user lists (names/emails) and sales-order metadata. Later FTC and trade coverage framed the episode as failures to secure video and personal data—se CAN-SPAM settlement commentary in 2024.
Root cause
Exposed admin/support infrastructure and credential replay enabling customer session emulation
References
- https://www.verkada.com/security-update/report/
- https://www.bleepingcomputer.com/news/security/hackers-breach-verkada-surveillance-company-access-150-000-cameras-in-hospitals-jails-and-more/
- https://www.ftc.gov/news-events/news/press-releases/2024/08/ftc-takes-action-against-security-camera-firm-verkada-over-charges-it-failed-secure-videos-other