← Security Cameras
F

Verkada Security Cameras

Fail
Verkada · 🇺🇸 United States · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Verkada Command
Manufacturer: Verkada

⚠️ The bottom line

150,000 security cameras hacked. Live feeds from Tesla factories. Psychiatric hospital patients. Prison cells. School classrooms. A hacker got in through a single admin account with no multi-factor authentication. Verkada sold "enterprise-grade security" cameras that were protected by a single password on an exposed server. The security cameras had no security. Verkada employees used the company's own cameras to spy on female coworkers. They shared the images in a Slack channel. The FTC fined Verkada $2.95 million. A security camera company whose employees used the cameras for sexual harassment. The product worked exactly as designed — it just wasn't designed for the people it was pointed at.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
0/4 N/A
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
2Contradictions
2Critical
0High
0Medium
2Sources
Findings by concern
Spying 3/4 HIGH 1 finding
⚠️ criticalprivacy policy vs regulatory
Verkada employees used the company's own cameras to spy on female coworkers. They shared the images in a Slack channel. The FTC fined Verkada $2.95 million. A security camera company whose employees used the cameras for sexual harassment. The product worked exactly as designed — it just wasn't designed for the people it was pointed at.

What they claim: Verkada describes strict access controls and data governance for camera footage

What we found: The FTC fined Verkada $2.95 million in 2024 for failing to implement basic security measures and for a toxic workplace culture where male employees used internal camera access to harass female colleagues. The FTC complaint described employees sharing images of female coworkers captured through office cameras in a Slack channel called "#RawDogNation."

Security 3/4 HIGH 1 finding
⚠️ criticalmarketing vs third party research
150,000 security cameras hacked. Live feeds from Tesla factories. Psychiatric hospital patients. Prison cells. School classrooms. A hacker got in through a single admin account with no multi-factor authentication. Verkada sold "enterprise-grade security" cameras that were protected by a single password on an exposed server. The security cameras had no security.

What they claim: Verkada promotes enterprise-grade cloud security cameras with end-to-end encryption

What we found: In March 2021, a hacker collective (APT-69420) breached 150,000 Verkada cameras across Tesla factories, Cloudflare offices, hospitals, psychiatric facilities, prisons, and schools. The hackers accessed live feeds and archived footage. The breach occurred through a single super admin account whose credentials were exposed in an internal Jenkins server. Verkada had no multi-factor authentication on admin accounts.

Sources