A Mysterium VPN investigation found more than 3 million internet-reachable cameras and recorders online, including 21,786 devices that were streaming live video with no authentication required. Researchers said the exposure was driven primarily by low-cost and legacy products rather than active exploitation, with RTSP representing the largest share of openly accessible video and accounting for 9,746 unauthenticated feeds. The report also noted that the researchers did not attempt default or weak passwords, indicating the number of reachable devices could be even higher.
The most heavily exposed systems were tied to budget and older platforms, including webcamXP and HiSilicon-class recorders, while major vendors such as Hikvision and Dahua were rarely exposed because of mandatory password setup policies. Japan and the United States accounted for more than a third of the open feeds, largely on residential broadband networks, raising privacy and physical security concerns as strangers could watch activity inside homes and other sensitive spaces. Recommended mitigations included setting strong passwords, disabling UPnP, limiting unnecessary RTSP exposure, updating firmware, and removing unmaintained devices from direct internet access.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
In May 2026, Mysterium VPN reported that more than three million internet-reachable cameras and recorders were exposed online, including 21,786 devices streaming live video with no authentication. The researchers said the exposure was concentrated in low-cost and legacy products, with many feeds accessible over RTSP and large concentrations in Japan and the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.