Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

Verkada Settles With FTC Over Poor Security Practices That Led to Camera Hacking

The FTC complaint alleges that Verkada’s failures allowed a hacker to access customers’ security cameras.

The Federal Trade Commission (FTC) has filed a complaint against security camera firm Verkada claiming its poor security practices have allowed a hacker to access customers’ cameras.

Based in California, Verkada offers IP-enabled security cameras and other physical security products to customers in the US and abroad, touting “best-in-class data security tools and best practices”.

According to the FTC’s complaint, Verkada failed to implement appropriate information security practices, which allowed a hacker to access cameras over the internet and view patients in psychiatric hospitals and women’s health clinics.

The complaint also alleges that the company failed not only to protect its customers’ sensitive information, such as names, email addresses, and passwords, but also to encrypt the data and to implement secure network controls.

These poor cybersecurity practices, the FTC says, led to Verkada falling victim to at least two breaches, including a March 2021 incident in which a hacktivist claimed to be able to access video footage from up to 150,000 internet-connected Verkada cameras.

Verkada, which has agreed to settle with the FTC, has clarified that only 97 of its 6,000 customers actually had their cameras accessed by the hacker.

Advertisement. Scroll to continue reading.

The FTC’s complaint also alleges that Verkada was aware of positive ratings and reviews posted by employees and a venture capital investor, which did not disclose its association with the company.

Additionally, Verkada allegedly violated the Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act) by sending a flood of commercial emails to prospective customers without allowing them to opt out, honoring opt-out requests, or providing a physical postal address in the emails.

The FTC’s proposed order (PDF), which must be approved by a federal judge, will require Verkada to implement a comprehensive information security program, will prevent it from making misrepresentations about its privacy and data security practices, and will require it to pay a $2.95 million monetary penalty for its email marketing practices.

“There was no fine imposed related to the security incident, but we have agreed to pay $2.95 million to resolve the FTC’s claims about our past email marketing practices. We do not agree with the FTC’s allegations, but we have accepted the terms of this settlement so that we can move forward with our mission and focus on protecting people and places in a privacy-sensitive way,” Verkada said.

Related: FTC Sending $5.6 Million in Refunds to Ring Customers Over Security Failures

Related: FTC Proposes Strengthening Children’s Online Privacy Rules to Address Tracking, Push Notifications

Related: Senators Push to Reform Police’s Cellphone Tracking Tools

Related: FTC Bans SpyFone From Surveillance Business for Selling Stalkerware

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.