Hikvision Europe Warns Of "A Wave of Cyberattacks"

Author: John Honovich, Published on Sep 28, 2017

Hikvision Europe has issued a "Hikvision Security Advisory" press release and emailed an e-newsletter with the advisory at the very top:

Hikvision Europe also urged users to upgrade their IP camera firmware to remove the Hikvision backdoor.

Wave Certainly

They are certainly correct to refer to it as a 'wave of cyberattacks' as the hacks on video surveillance products this month have been far more broad and severe than ever before.

Dahua Mostly Hit

Ironically, this wave has overwhelmingly hit Dahua recorders (see Hackers Globally Attacking Dahua Recorders), not Hikvision devices, as Dahua has numerous cybersecurity vulnerabilities (e.g., Dahua's backdoor) of their own, including issues with their recorders that are more commonly made publicly accessible than IP cameras.

Hikvision IP Cameras Certainly At Risk

At the same time, Hikvision IP cameras (and their numerous OEMs who we have verified), face risk as well. In September 2017, full disclosure was made to the Hikvision backdoor, showing how easy it was for hackers to attack vulnerable Hikvision IP cameras.

Right Thing To Do

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

To that end, Hikvision Europe is certainly doing the right thing to make it clear to their customers and partners that this is a real risk and real attacks are occurring. Moreover, Hikvision Europe deserves respect for prominently sending out notice, rather than obscuring it.

Hikvision Better Response Than Dahua

Hikvision Europe's response to the Dahua driven wave of cyber attacks has been better than Dahua's own. Dahua's only public communication to date was a press release that buried the hacks in spin about launching latest cybersecurity initiatives. This is a positive for Hikvision but only reinforces how poor Dahua's response has been.

Hikvision USA Failing So Far

Unlike Hikvision Europe that addressed the issue head on and professionally communicated the risks publicly, Hikvision USA is ignoring the risks and failing to warn their customers of this wave and the recent disclosure of Hikvision's backdoor. Instead, Hikvision USA blogged arguing that they only had 8 CVE cyber vulnerabilities and bemoaning an 'online blogger'. [Update: now, Hikvision USA Misleads Dealers On Backdoor]

Communicating Risks Clearly Is Critical

Manufacturers not only have a responsibility to clearly and prominently communicate risks but they also will benefit by rebuilding trust by being more forthright.

1 report cite this report:

Surveillance Systems Remote Access Usage Statistics on Oct 11, 2017
Remote access is a major benefit and risk for video surveillance. It is a benefit because it allows users to manage security or review...
Comments (11) : PRO Members only. Login. or Join.

Most Recent Industry Reports

The IP Camera Lock-In Trend: Meraki and Verkada on Jan 18, 2019
Open systems and interoperability have not only been big buzzwords over the past decade, but they have also become core features of video...
NYPD Refutes False SCMP Hikvision Story on Jan 18, 2019
The NYPD has refuted the SCMP Hikvision story, the Voice of America has reported. On January 11, 2018, the SCMP alleged that the NYPD was using...
Mobile Surveillance Trailers Guide on Jan 17, 2019
Putting cameras in a place for temporary surveillance where power and communications are not readily available can be complicated and expensive....
Exacq Favorability Results 2019 on Jan 17, 2019
Exacq favorability amongst integrators has declined sharply, in new IPVM statistics, compared to 2017 IPVM statistics for Exacq. Now, over 5 since...
Testing Bandwidth Vs. Low Light on Jan 16, 2019
Nighttime bandwidth spikes are a major concern in video surveillance. Many calculate bandwidth as a single 24/7 number, but bit rates vary...
Access Control Records Maintenance Guide on Jan 16, 2019
Weeding out old entries, turning off unused credentials, and updating who carries which credentials is as important as to maintaining security as...
UK Fines Security Firms For Illegal Direct Marketing on Jan 16, 2019
Two UK security firms have paid over $200,000 in fines for illegally making hundreds of thousands of calls to people registered on a government...
Access Control Cabling Tutorial on Jan 15, 2019
Access Control is only as reliable as its cables. While this aspect lacks the sexiness of other components, it remains a vital part of every...
Avigilon Favorability Results 2019 on Jan 15, 2019
Since IPVM's 2017 Avigilon favorability results, the company was acquired by Motorola and has shifted from being an aggressive startup to a more...
Gorilla Technology AI Provider, Raises $15 Million, Profiled on Jan 15, 2019
Gorilla Technology is a Taiwanese video analytics manufacturer that recently announced a $15 million investment from SBI Group, saying this...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact