The Hikvision Hacking Scandal

Author: John Honovich, Published on Mar 03, 2015

What was once just warnings and consumer concerns has exploded into a major problem for Hikvision.

A Chinese province's Hikvision devices have been hacked.

In this note, we examine what happened, what Hikvision says they are doing about this and what this means for the mega-manufacturer.

Update September 2015. Hikvision has suffered another major hack.

Hikvision Historical Security Problems

As background, Hikvision had already been hit with a number of security concerns / issues over the past few years. The most infamous was Wired's article on Hikvision: HACKERS TURN SECURITY CAMERA DVRS INTO WORST BITCOIN MINERS EVER. In addition, there was a buffer overflow vulnerability found later in 2014. Even more basically, since Hikvision historically did not force users to change default passwords, and since there are so many Hikvision products out there, Hikvision made itself an obvious target for even the least sophisticated hackers.

The Chinese Province Hack

Given the historical problems, what is important here is that this incident is hitting a government organization, where information security is critical.

The province is Jiangsu, on the East coast of China, with ~80 million people.

In a press release only posted on Hikvision's Chinese site (see google translation), Hikvision admits that their products were hacked inside the Jiangsu Province Internet Emergency Center. Hikvision claims that this was due to the use of weak passwords / default passwords. We cannot confirm that as we have no connection to the Jiangsu government.

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

However it happened, the fact that government video surveillance equipment was hacked is a major problem. Indeed, this is even worse given the Chinese government's recent efforts to restrict foreign products that might expose them to hacking / attacks.

Hikvision's Response

In response, Hikvision USA Outlines Updates to Surveillance Products report has been released.

It summarizes steps they have already done in the past year and discloses a new release scheduled for later this month (5.3.0).

[[Note: This firmware has been released. See our full test of it here.]]

Key changes in this upcoming release include:

  • Forcing change of the default password (an obvious step and a key risk otherwise)
  • Disabling telnet access (telnet is considered quite vulnerable)
  • Lockouts after 5 incorrect login attempts (helpful to stop brute force attempts)

The Impact

Hikvision's stock dropped 7.5% in the first day of trading post the full disclosure (trading was actually halted Monday). In percentages terms, that is not huge but at their size, it is a drop of more than $1 billion USD in value. On the second day, the stock price rose slightly, indicating that the market does not view this as a major risk.

Update: June 25, 2015: Less than 3 months later, Hikvision's stock price is up more than 50% since the hacking announcement, showing that the market does not really care about this.

Since Hikvision is partially owned by the Chinese government and has deep connections, we doubt that this will be a fatal issue for Hikvision domestically. On the other hand, it is clearly a black eye for Hikvision and something that was hotly discussed inside of China.

In North America and Europe, we think the impact will be more severe. Rival manufacturers have already been hammering Hikvision as being 'spamware'. This will simply confirm it. On the lower end of the market, where Hikvision is most commonly used, outside of China, we suspect most will not care strongly as information security tends not to be a priority compared to price. However, as Hikvision tries to expand into the mid and high end markets, we think this will cause significant resistance, making it easy for rivals to declare, "Sure, you can buy Hikvision for half the price but with Axis you won't get hacked."

Hikvision Integrators / Users / OEMs

If you are a Hikvision integrator, user or OEM, you better very carefully review your deployed products and absolutely ensure that everything is upgraded immediately. Hikvision firmware upgrades are available here.

After a hack of this magnitude, it is going to be extremely hard to explain how you allowed your equipment to be hacked. And Hikvision products deployed before a year ago (and not upgraded) have many very basic / simple vulnerabilities. It is hard for us to tell if the upgrades solve every possible risk, but it is obvious that the older versions are significantly risk prone.

Poll

21 reports cite this report:

Hikvision Backdoor Confirmed on May 08, 2017
The US Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued an advisory for...
Chinese Company Xiongmai Threatens Legal Action Against Western Accusers on Oct 24, 2016
The Chinese video surveillance manufacturer, Xiongmai, whose equipment numerous sources blame for driving massive Internet attacks over the past...
US Embassy Requires Hikvision Cameras on Aug 29, 2016
The US Embassy in Kabul Afghanistan has required only Hikvision cameras in a new US federal government bid. However: Hikvision was founded...
Hikvision Rejects Responsibility for Hacked Hikvision Cameras on May 10, 2016
After a massive number of Hikvision cameras were hacked, Hikvision has added new, and questionable legal language, declaring that Hikvision will...
ADI Refuses to Fix Their OEM'd Hikvision Security Risks [Solved] on Mar 09, 2016
More than a year after massive hacks against Hikvision was disclosed; More than 9 months after Hikvision issued improved security firmware, mega...
Network Security for IP Video Surveillance Guide 2016 on Feb 03, 2016
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...
Arecont and Bosch - Default Security Risk on Dec 14, 2015
Default passwords are a major security risk, enabling hackers around the world to access and control devices like IP cameras (using Shodan, turning...
Axis Cybersecurity Hardening Guide Examined on Nov 19, 2015
In most IT areas, 'hardening' guides are commonplace, providing best practices for improving the cybersecurity of network products (e.g., see this...
Hikvision Hires Pelco / G4S Exec on Nov 10, 2015
Hikvision gets another major industry executive. He was most recently the President of G4S Technology, and before that VP of Sales at Pelco. Now,...
Winners Losers Fall 2015 on Oct 12, 2015
There's a lot of losing right now, unfortunately. The industry is moving into year 2 of sharp camera price declines. Combined with the maturation...
Dahua Finally Has A US Distributor on Oct 08, 2015
Finally. Billion dollar Dahua is the 'smaller' of the two mega Chinese surveillance manufacturers (the other being Hikvision). Historically,...
Warning: ADI and Tri-Ed Video Products Major Security Risk on Sep 22, 2015
Recently, ADI and Tri-Ed both started OEMing Hikvision products. Reference - IPVM test on ADI W Box, IPVM test of Tri-Ed Northern Video. Both ADI...
The Hikvision Hacking Scandal Returns on Sep 22, 2015
With a vengeance. The last time, the industry mostly shook it off. This time, it is clearly much worse. In this note, we examine Hikvision's...
Anixter/Tri-Ed Northern Video Tested on Sep 18, 2015
ADI is an IP video manufacturer now (see IPVM's ADI W Box test results). And now, their top rival, Anixter's Tri-Ed arm has also entered the IP...
ADI's Disruptive W Box Tested on Jul 22, 2015
ADI moves hundreds of millions of dollars worth video surveillance equipment each year. And now, they are disrupting the channel, cutting out...
Pros and Cons - Automating Firmware Updates on Jul 01, 2015
Firmware and software updates are one of the most tedious tasks in surveillance, so why not make them easier? While other devices, like PCs,...
Hikvision Anti Hacking Firmware Tested on Jun 03, 2015
Hikvision has had historic hacking problems, with DVRs turned into Bitcoin miners, buffer overflow vulnerabilities, and finally culminating in the...
Hikvision Hires Ex-Samsung / Panasonic Exec on May 18, 2015
Hikvision's expansion continues, with the mega Chinese manufacturer now hiring one of the most well known and well tenured American sales...
Axis Cuts Prices 2015 on Mar 09, 2015
Axis has cut prices on a number of their most popular markets.  In this note, we look at feedback from Axis, comparing how this impacts...
NMAPing IP Cameras on Mar 05, 2015
The Hikvision hack has increased security concerns. Indeed, most users do not know whether they are vulnerable or not, which ports of their...
Avigilon 2014 Financials Disappoint Investors on Mar 04, 2015
Hikvision admits their equipment got hacked in a large government deployment - stock down just 7.5% Avigilon announces revenue up 42% - stock down...
Comments (47): PRO Members only. Login. or Join.

Related Reports

Axis Criticizes OEMs: "When You Buy An Axis Camera, An Axis Camera Is What You Get!" on May 19, 2017
When you buy a Honeywell camera, you likely get a Hikvision, Dahua or some other company's product. The same goes for easily 100 different...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Cisco: Hikvision Hired Us on May 15, 2017
The day after Hikvision's backdoor was confirmed by the US Department of Homeland Security, Hikvision issued a press release about a...
Dahua Founder Sells $122 Millon Dahua Stock on May 15, 2017
Just a week after his sudden resignation as CEO, Dahua's Founder sold off ~$122 million of Dahua's stock. Inside this note, we examine the stock...
Hikvision Blaming Backdoor On Others, Cannot Hide From DHS on May 11, 2017
Numerous Hikvision employees are blaming their backdoor on others but Hikvision cannot hide from the US Department of Homeland Security. Blaming...
Hikvision Backdoor Confirmed on May 08, 2017
The US Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued an advisory for...
Kedacom Targeting Hikvision, Dahua Entering US on May 03, 2017
A publicly traded company with a $1 billion dollar market cap is directly aiming for Hikvision and Dahua. Kedacom, listed on the Shanghai stock...
Hack Your Access Control With This $30 HID 125kHz Card Copier on May 01, 2017
You might have heard the stories or seen the YouTube videos of random people hacking electronic access control systems. The tools that claim to do...
US Air Force Cancels Hikvision RFQ on May 01, 2017
The US Air Force has cancelled an RFQ for Hikvision video surveillance, following IPVM notifying the Air Force that Hikvision products are made in...
Bain Sells Off Uniview on Apr 30, 2017
Bain Capital has sold off Uniview to a Chinese company. Uniview is the self-proclaimed "#3" in China video surveillance behind Hikvision and...

Most Recent Industry Reports

Axis Criticizes OEMs: "When You Buy An Axis Camera, An Axis Camera Is What You Get!" on May 19, 2017
When you buy a Honeywell camera, you likely get a Hikvision, Dahua or some other company's product. The same goes for easily 100 different...
Hackable 125kHz Access Control Migration Guide on May 19, 2017
Despite being one of the most popular credentials, 125 kHz credentials are easily copied and insecure as we showed in our test results, video...
Forget The Backdoor, "ALL HIKVISION PRODUCTS" On Sale on May 18, 2017
Less than 2 weeks after the Hikvision Backdoor was confirmed, Hikvision has launched a sale "ON ALL HIKVISION PRODUCTS". In this note, we examine...
Amazon Techs Installing IP Cameras Tested on May 18, 2017
In 2015, Amazon started offering video surveillance installation. Now, Amazon has made it a lot easier, with automatic add-on options and...
Hanwha Recorder Vulnerability Analyzed on May 18, 2017
ICS-CERT has released a vulnerability notice for Hanwha SRN-4000 recorders.  Hanwha provided additional information to IPVM about this issue,...
ShotSpotter To IPO, Facing Low Revenue and Losses on May 17, 2017
A rare event for North American security manufacturers is upcoming. ShotSpotter is planning to IPO on the NASDAQ, aiming to raise $34.5...
DMP Video Doorbell / Access Reader Examined on May 17, 2017
Consumers increasingly demand video doorbells, with "doorbells selling like hotcakes, everyone wants a doorbell", according to ADT's CEO. At ISC...
FLIR Is Giving Away $3,000 Demo Kits on May 17, 2017
Everybody likes free stuff, and FLIR is using that concept to attract dealers by giving them $3,000 worth of demo gear for attending a...
Shark Tank Startup Guard Llama Mobile Panic Tested on May 16, 2017
A Shark Tank TV show appearance has attracted big attention for Guard Llama, a security startup touting a 'panic button' paired with mobile app...
Axis Beats Avigilon Growth Rate (AVO Q1 2017) on May 16, 2017
In what is likely the first time ever, Axis beat Avigilon's revenue growth for Q1 2017. Inside this note, we examine Avigilon's Q1 2017 financial...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact