Multi-CloudIncident TeardownsRetrospectives

Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.

In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at customers including hospitals, schools, prisons, factories and Tesla facilities.

How it happened

According to reports, the attackers found credentials for a Verkada "super admin" account exposed on an internet-accessible system. That account gave access to Verkada's internal tools and, through them, to customer cameras — including features that allowed access to the camera hardware itself. The group said its motive was to expose the scale of surveillance.

Why it mattered

  • One credential, many customers. A single highly privileged account at a SaaS vendor reached thousands of customer environments.
  • Support tooling had too much power. Internal support access extended to customers' devices without customer approval.
  • IoT and physical security converge with cloud risk. Cameras in sensitive locations were exposed through a cloud admin console.

Verkada later restricted employee access to customer systems. In 2024, the US Federal Trade Commission reached a settlement with Verkada over security failures, including the 2021 incident.

Lessons in hindsight

  • Never leave privileged credentials in accessible systems — scan for secrets in code, configuration and file shares.
  • Vendor support access should require customer approval and be time-limited.
  • Ask SaaS vendors how their staff access your data and devices.
  • Treat IoT management platforms as privileged systems.

In hindsight

The pattern — a vendor's internal admin capability reaching into many customers — reappeared repeatedly. It's why modern SaaS security reviews ask specifically about vendor employee access and why customer lockbox-style approval features have become more common.

verkada hackVerkada2021

More on this story