Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Hunt.io cybersecurity experts have revealed information about a campaign that they claim used credential assaults, two authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay mechanism to hack over 14,530 Dahua devices between June 17 and July 22, 2026.
A 407 MB exposed working directory with 2,616 files spread across 234 subdirectories—including tooling, logs, shell history, and campaign records—was used to reconstruct the activity, codenamed Operation CameraSwarm. According to the researchers, confirmed compromises were concentrated in Russia and Ukraine.
According to the researchers, 283 cameras were accessed via the P2P route, while 1,923 cameras were set up with a persistent account during the operation.
While ITRES Labs advises deactivating P2P when it is not ...

