40,000 Exposed Security Cameras: A Wake-Up Call for Houston Business Security
Understanding the Risks of Unsecured Internet-Connected Cameras – Big Brother Is Watching, But So Is Everyone Else
Bitsight TRACE found more than 40,000 security cameras streaming to the open internet with no password at all - and Texas has one of the highest concentrations. Most owners think of it as a privacy issue. Attackers think of it as a foothold.
An exposed security camera is rarely dangerous because someone is watching. It is dangerous because it is an unmanaged computer sitting on your network with a public IP address and, too often, no password.
Bitsight TRACE, scanning the internet, found more than 40,000 exposed security cameras streaming live over HTTP and RTSP with no authentication or access control at all. About 14,000 sit in the United States, and Texas is one of the four states with the highest concentration. That gets covered as a privacy story. For a business owner in Houston, the more useful way to read it is as an IoT camera security failure - a device that was supposed to protect the building quietly became the weakest point on the network.
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. This post walks through the myths owners believe about their cameras, what the exposure really means, and how to keep a camera from becoming an attacker's front door.
What Do Businesses Get Wrong About Camera and IoT Security?
Four comfortable beliefs the Bitsight numbers quietly break.
The danger with an exposed camera is not one clever feature - it is the set of assumptions that let it sit unsecured in the first place.
Most owners do not ignore their cameras out of carelessness. They reason their way into it: a camera feels like an appliance, the router feels like a wall, and the footage feels too boring to steal. Each of those beliefs is wrong in a way attackers count on.
| ❌ The Myth | ✓ The Reality |
|---|---|
| "It's just a camera, not a real computer." | Every IP camera is a small Linux computer with a network stack. It can be scanned, logged into, and recruited into a botnet - exactly what happened to the 600,000 devices in the 2016 Mirai attack. |
| "It's behind our router, so it's safe." | Bitsight found 40,000-plus cameras reachable directly from the public internet. Port forwarding, UPnP, or a manufacturer cloud feature routinely punches a hole straight through the router to the device. |
| "No one wants footage of our lobby." | Attackers do not want the footage. They want the device - as a foothold for lateral movement, or a live view to map your building, staff schedules, and blind spots before a break-in. |
| "The login page asks for a password, so we're covered." | Bitsight showed many HTTP cameras return live screenshots through alternate API paths even when the main interface looks protected. A password prompt on one URL does not mean every URL is locked. |
How Bad Is the Exposed Camera Problem?
40,000 cameras, a heavy Texas footprint, and industries a Houston owner will recognize.
Bitsight TRACE identified over 40,000 security cameras streaming live footage to the open internet, with the United States holding roughly 14,000 of them and Texas ranking among the most affected states.
The scan covered cameras running on HTTP and RTSP, the two protocols most consumer and professional systems use. Japan followed the United States with about 7,000 exposed devices, with meaningful counts in Austria, Czechia, and South Korea. Inside the United States, California, Texas, Georgia, and New York carried the highest concentrations - which puts Houston-area businesses squarely in the affected group, not on the sidelines of someone else's problem.
Set aside residential devices on telecom networks and the business picture sharpens. The technology sector was the most exposed at 28.4%, followed by media and entertainment at 19.6%, utilities at 11.9%, business services at 10.7%, and education at 10.6%. Those are not exotic verticals. A Houston engineering firm, a Gulf-Coast utility contractor, or a Cypress logistics office runs the same kinds of cameras on the same kinds of networks.
- Corporate offices where cameras face whiteboards and screens showing confidential work - remote "shoulder surfing" without setting foot on site.
- Manufacturing floors where a live feed hands competitors a view of proprietary processes and layout.
- Server rooms and IT closets where a camera helps an attacker map physical access and security blind spots.
- Healthcare settings where exposed patient-area cameras create HIPAA exposure on top of the privacy harm.
Why Is an Exposed Camera a Network Problem, Not Just a Privacy One?
The camera is the way in - the footage is a side effect.
An internet-facing camera with weak or no authentication is a live, unmonitored device on your network, and that makes it useful to an attacker in ways that have nothing to do with what it films.
This is where the privacy framing does real harm - it makes the problem sound smaller than it is. A camera is a computer. Once an attacker controls it, they have a beachhead. The Mirai botnet made that concrete in 2016 when it pulled roughly 600,000 IoT devices, cameras included, into attacks that knocked large parts of the internet offline. That playbook did not retire. The
The U.S. Department of Homeland Security has warned that exposed cameras, particularly certain foreign-manufactured models, can be used for espionage and infrastructure mapping. On the criminal side, Bitsight noted dark-web forums trading camera IP addresses and access methods. The common thread is that the device itself is the prize. In 35 years around this work, the pattern is consistent: the breach almost never starts at the thing you were guarding. It starts at the thing you forgot was even on the network.
Not sure what's exposed on your network?
A CinchOps network security assessment finds the cameras, sensors, and forgotten devices reachable from the internet before an attacker does.
Get a Security AssessmentGetting in is not the hard part attackers worry about. Bitsight found many cameras needed only a browser, the right IP, and knowledge of common URL patterns - no exploit at all. Some HTTP cameras leak still images through alternate API endpoints even when the main login looks locked, and RTSP streams often live at predictable URLs anyone can guess. The barrier is low by design, because these devices were built for easy remote viewing, not for surviving on the public internet.
How Do You Keep a Camera From Becoming a Front Door?
Treat every camera like the networked computer it is.
Securing cameras is not about better footage - it is about network hygiene: keep the device off the open internet, off the flat office LAN, and under active management.
- Take cameras off the public internet. Do not port-forward or expose a camera directly. If you need remote viewing, reach it through a VPN or the vendor's authenticated cloud, never a raw public IP.
- Segment cameras onto their own VLAN. IoT devices belong on an isolated network segment that cannot reach your servers, workstations, or accounting data. Segmentation turns a compromised camera into a dead end instead of a pivot.
- Change every default credential and enforce real passwords. Default and blank passwords are how most of the 40,000 got exposed. Set unique, strong credentials and disable unused accounts and services on the device.
- Patch camera firmware on a schedule. Cameras run firmware that ships with vulnerabilities and rarely updates itself. Track models, apply vendor updates, and retire devices the manufacturer no longer supports.
- Monitor for the device, not just the footage. Watch for unexpected outbound connections and traffic from camera VLANs - a camera phoning home to an unfamiliar host is often the first sign it has been recruited.
None of this requires ripping out your cameras. It requires treating them as endpoints that need the same authentication, patching, segmentation, and monitoring as any other computer on the network. That shift - from "it's just a camera" to "it's a networked computer we manage" - is the whole fix.
Secure the Devices You Forgot Were Online
CinchOps hardens IoT and camera systems for Houston-area businesses with network segmentation, VPN-only remote access, firmware patching, and traffic monitoring - the controls that keep a camera from turning into an attacker's foothold. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →Owners hear "exposed camera" and picture a creep watching the lobby. That's the least of it. The camera is a computer with an IP address and no antivirus, sitting on your network. An attacker doesn't want your footage - they want a way in that nobody's watching, and a forgotten camera is exactly that.
How CinchOps Helps Secure Your Business
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, with security that treats every connected device - cameras included - as part of your attack surface.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Exposed cameras are a clean example of where managed, device-aware security pays off:
- Network security assessments. We find the cameras, sensors, and forgotten devices reachable from the internet - and close the exposure.
- IoT segmentation and access control. We put cameras on isolated VLANs behind VPN-only remote access, so a compromised device cannot reach your core systems.
- Firmware and patch management. We track device models and keep firmware current, retiring gear the vendor no longer supports.
- 24/7 monitoring and incident response. We watch for the odd outbound traffic that signals a device has been recruited, and contain it fast.
If your business in Houston or Katy runs cameras, badge readers, or any other connected gear, the question is not whether they are on your network - it is whether anyone is managing them. That is doubly true for a manufacturing plant floor or a Gulf-Coast utility operation, where a camera can look straight at proprietary work. If you are not certain what is exposed, talk to CinchOps and we will find out before someone else does.
Frequently Asked Questions
How many security cameras are exposed on the internet?
Cybersecurity firm Bitsight TRACE found more than 40,000 security cameras worldwide streaming live footage to the open internet with no authentication. About 14,000 are in the United States, with Texas among the four states holding the highest concentrations, putting Houston-area businesses directly in scope.
Why is an exposed camera a network security risk?
An IP camera is a small networked computer. Once an attacker reaches an unsecured one, it becomes a foothold - it can be pulled into a botnet like Mirai, used to map a building for a physical break-in, or used as a pivot to move laterally toward servers and deploy ransomware.
Is my camera safe because it sits behind my router?
Not necessarily. Bitsight found tens of thousands of cameras reachable directly from the public internet. Port forwarding, UPnP, and manufacturer cloud features routinely open a path through the router straight to the device, so "behind the router" does not mean unreachable.
How do attackers access exposed cameras?
Often with nothing more than a web browser, the correct IP address, and knowledge of common URL patterns - no exploit needed. Some HTTP cameras leak still images through alternate API paths even when the login page looks protected, and RTSP streams frequently sit at predictable, guessable URLs.
How do I secure my business cameras?
Take cameras off the public internet and reach them only through a VPN, put them on an isolated VLAN separate from your core systems, replace default passwords with strong unique credentials, patch firmware on a schedule, and monitor camera traffic for unexpected outbound connections that signal compromise.