Article

    Cyber News / Article / How to protect yourself from webcam spying: five simple steps | Kaspersky official blog

    How to protect yourself from webcam spying: five simple steps | Kaspersky official blog
    To
    Tom Fosters-23 days ago

    How to protect yourself from webcam spying: five simple steps | Kaspersky official blog

    We revisit the key rules for setting up IP cameras and related devices so that you don’t end up starring in a reality show — whether at home, in a hotel, or in rented accommodation.

    Tom Fosters

    August 19, 2026

    These days, it can feel like there’s a camera watching us from every corner: a video doorbell by the front door, a laptop webcam in the home office, an IP baby monitor in the children’s room, a smart TV with a camera and microphone in the bedroom, a robot vacuum with a navigation camera roaming around the house… Even a smart cat feeder could be spying on you! And any one of these cameras can easily become a useful tool for extortionists, blackmailers, or simply curious malicious actors.

    You don’t have to look far for examples. South Korea, late 2025:not one device, but 120,000 IP cameras were hacked. The criminals sold intimate footage and recordings of people’s everyday lives by subscription in private chats.

    In this article, we look at exactly where the threat comes from, and outline five rules that can greatly reduce your chances of becoming the star of a voyeur’s show.

    Unfortunately,reportsof miniature cameras being discovered in hotel rooms and rental apartments have become almost routine. Technically, these belong to a separate category of devices — “spy cameras” disguised as power outlets, smoke detectors, or alarm clocks. We’ll explain a little later how to detect them.

    Criminals don’t just publish footage from spy cameras — they even livestream it. Access to intimate videos, naturally, isn’t free. In some regions, criminals have built an entire infrastructure around spy cameras: some people install the cameras, others process the footage, while still others sell access through the dark web or messaging apps. Victims typically discover that there was a hidden camera in their hotel room purelyby accident, after coming across videos of themselves on porn sites.

    Another popular attack vector ishacking dashcamsthat can connect to the internet. These devices are tempting targets for attackers: their security is often weak, while the footage clearly shows license plates, road signs, and addresses on buildings. The recordings also contain detailed metadata, including exact dates, GPS coordinates, and more.

    This can allow criminals to identify a victim’s regular routes, determine where their car is parked, or even eavesdrop on conversations with passengers. There can be enough information for full-scale surveillance, car theft, or even blackmail if the camera records conversations and video inside the car.

    Not all stolen camera footage is the result of attacks by professional cybercriminals looking to profit from it. Sometimes, stalkers hack webcams to spy on specific people — often someone they know. For example, in 2025 a case came to light in which a man had beenspyingon his colleagues for years through their home IP cameras. All of the victims were women, who had no idea they were being watched.

    In another case, a manmonitoredhis ex-wife and daughter through an intercom system and IP cameras. He made no attempt to hide the fact that he was spying on his own family, and even sent his daughter screenshots from the webcam. As a result, she eventually had to move away.

    This is probably the main reason IP cameras get hacked. Most users never change the factory-default passwords on their routers, smart devices, or the apps connected to them. Such passwords are essentially public knowledge. They often use simple combinations such as “admin/admin” or “root/1234”, which are known worldwide and can be guessed in a matter of seconds — no sophisticated algorithm is required. This is exactly what recently allowed attackers tohack 120,000 camerasin South Korea.

    Even when manufacturers give assurances that camera data is stored only locally, in practice this is often far from the truth. For example, in 2022 researchers discovered that one popular range of video camerassent snapshots to the manufacturer’s server every time a person appeared in the frame. And that wasn’t all: remote access to all cameras’ recordings was available through URLs generated in a predictable way — making them relatively easy to generate or guess.

    At the same time, the company claimed that its cameras used end-to-end encryption, stored recordings exclusively on the device, and didn’t transmit data to external servers. Incidentally, the supposedly “secure encryption” was implemented using a fixed key that was identical for every user. And the key itself could easily be found in the source code published by the manufacturer.

    In short, if a device has a lens and Wi-Fi, be prepared for the possibility that sooner or later a serious security flaw will be discovered in it.

    To access a camera, an attacker often only needs to know its IP address and try a handful of common passwords. There are search engines that index not websites, but devices and their open ports: webcams, routers, industrial controllers, medical equipment — you name it.

    If an IP camera requires no username and password, or is “protected” by the default “admin/admin” credentials, it may easily be discovered and added to the database of an OSINT service. Journalists and researchers have used such services to find publicly accessible cameras in children’s rooms, offices, hospital operating rooms, banks, and shops.

    What can you do at home or in a small office without a dedicated security team? These five simple recommendations can help.

    When choosing an IP camera model, make sure you check whether cameras from that manufacturer have been hacked before — for example, by searching for “IP camera hackmanufacturer name“. Then visit the Support section of the manufacturer’s website and check the date of the most recent firmware update both for the model you are considering and older models.

    If you find that firmware has not been updated for more than six months, or that updates are released irregularly, you may want to choose a different model. Most cameras run specialized embedded versions of Linux, and more than 2,300 vulnerabilities were recorded in the Linux kernel in the first six months of 2026 alone. If a manufacturer fails to update its firmware regularly, sooner or later a security hole is almost certain to appear in its cameras.

    Consider models from major manufacturers if you don’t want to end up with a whole collection of vulnerabilities and virtually no chance of them ever being patched. Cheap cameras from obscure companies with limited functionality and weak protection can ultimately cost you dearly.

    The fewer third-party cloud storage services involved in your surveillance system, the better. When choosing a camera, look for a microSD card slot, or support for a home network-attached storage device (NAS), so you can store all recordings locally.

    Ideally, the camera should be able to operate entirely within your local network without transmitting data to the cloud or the manufacturer’s servers — with viewing available over the LAN or through asecure connectionto your home or office.

    When buying other smart home appliances, consider whether you really need a built-in camera in, say,a smart TV, smart speaker,robot vacuum, orautomatic pet feeder. Each and every one of these devices expands the potential attack surface.

    After buying an IP camera, go through its settings — usually available in the manufacturer’s app or through the camera’s web interface — and disable anything you don’t need.

    Factory-default passwords have been known to attackers for years. If you haven’t changed the username and password for your router or IP camera, an attacker may be able to gain access in a matter of seconds.

    We recommend segmenting your home Wi-Fi into separate subnets. You’ve probably encountered this arrangement in cafés, which often have one Wi-Fi network for staff and another for guests.

    All IP cameras and other smart home gadgets should ideally be moved to a separate Wi-Fi network and completely isolated from laptops, phones, and other work devices. Better still, IP cameras should be isolated from all other devices by creating a dedicated Wi-Fi network specifically for them.

    Most modern routers allow you to create at least two Wi-Fi networks — a primary network and a guest network — while more advanced models can support more. That way, even if your camera is hacked, the attacker won’t be able to reach your other devices or access sensitive files.

    For detailed setup instructions, consult your router’s manual or the support section of the manufacturer’s website. For more advice on protecting your smart home, see our postHow to secure your smart home.

    Our final set of recommendations is not about configuring the camera itself, but about good security hygiene.

    Make a habit of checking the client list on your router. If you see an unknown device with a strange name or MAC address, investigate what it is and why it’s connected to your home network.Our security solutionincludes a dedicatedSmart Home Monitor component. This feature can alert you when a new device connects to your home wired or wireless network, provide simple recommendations for improving home network security, and identify weak router passwords and insecure encryption.

    When traveling, we recommend checking hotel rooms and rental properties for hidden recording devices:

    For more practical methods of finding spy cameras, see our articleFour ways to find spy cameras.

    What else you should know about surveillance and cameras:

    Steam forums are the latest battleground for ClickFix attacks. We break down how attackers disguise themselves as helpful commenters to trick gamers into installing a crypto miner on their PCs.

    Steam forums are the latest battleground for ClickFix attacks. We break down how attackers disguise themselves as helpful commenters to trick gamers into installing a crypto miner on their PCs.

    Alanna Titterington

    August 17, 2026

    We explain how to use AI the right way for schoolwork, how to fact-check chatbot responses, and how to protect your personal data.

    We explain how to use AI the right way for schoolwork, how to fact-check chatbot responses, and how to protect your personal data.

    Kaspersky Team

    September 2, 2026

    We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.

    We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.

    Stan Kaminsky

    August 28, 2026

    Handing it to a store manager or cashier, posting about it in your neighborhood chat, or just keeping it – these are common actions if a bank card is found on the street, but they’re also the wrong ones. Here’s what you should actually do.

    Handing it to a store manager or cashier, posting about it in your neighborhood chat, or just keeping it – these are common actions if a bank card is found on the street, but they’re also the wrong ones. Here’s what you should actually do.

    Kaspersky Team

    August 27, 2026

    Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?

    Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?

    Stan Kaminsky

    August 11, 2026

    Original source