VERKADA▊
- OPERATION
- Cloud-managed security cameras — "security made simple," sold to schools, hospitals, jails, and factories FACT
- EVENT
- BREACHED — March 2021; intruders reached customer cameras through Verkada's own admin layer; the company confirmed the unauthorized access FACT
- SCALE
- ~150,000 cameras, per the hackers' claim as reported by Bloomberg — Tesla, Cloudflare, hospitals, a jail, an elementary school ATTRIBUTED
- VECTOR
- A "Super Admin" username and password found publicly exposed on the internet ATTRIBUTED
- DISPOSITION
- FTC order (2024): mandated security program + $2.95M penalty on the accompanying CAN-SPAM allegations ADJUDICATED
Here is the watcher — the animal that sells the ability to see inside everyone else's building — observed leaving its own master key on the public internet, where a collective of ideological hackers picked it up and looked back.
Official channel: @VerkadaHQ on X — the handle Verkada links from its own site. FACT
From the company's own incident page, on the record: “Mandiant — the external firm hired to conduct an independent review of our March 9th security incident — has concluded its investigation and confirmed that its findings are consistent with those from our own internal investigation.” And at the time, to Bloomberg: “We have disabled all internal administrator accounts to prevent any unauthorized access.” FACT
A camera company's product is trust in one direction: you watch, nobody watches you. The March 2021 breach inverted the lens. This was not a subtle intrusion — the group that claimed it announced itself, handed footage to Bloomberg, and stated its politics on the record. The failure it exposed was ordinary: an over-privileged admin account, its credentials sitting on the public internet.
The archive marks two things here: the architecture — one Super Admin layer that could see into jails, hospitals, and an elementary school — and the paper trail that followed, from the company's own remediation timeline to a federal consent order three years later. Every claim carries its receipt; the defense gets equal time.
the drama timeline
ACT I — THE LENS TURNS AROUND (MAR 2021)
The intrusion, by the intruders' own account, took no exploit at all — a username and a password, found in the open, unlocking the view into everyone's ceiling.
-
MAR 7–9 2021
Super Admin, found on the public internet
A hacker collective calling itself "APT-69420", with Swiss developer Tillie Kottmann as its public voice, gains "Super Admin"-level access to Verkada's systems using credentials found publicly exposed online, and accesses customer cameras and archived video. Kottmann tells Bloomberg the group's motives are curiosity, freedom of information, anti-capitalism — and fun.
No zero-day, no phishing kit, no patience. The moat around 150,000 lenses was one credential wide.
-
MAR 9 2021
Disclosure day — the response is fast
Bloomberg publishes; Verkada disables all internal administrator accounts the same day, opens an investigation, engages Mandiant as outside forensic firm and Perkins Coie as counsel, notifies affected customers, and begins publishing a running incident timeline on its own site.
ACT II — THE PAPERWORK ARRIVES (2021–2024)
The hacker gets an indictment; the vendor, three years later, gets a consent order. Different courts, one incident report.
-
MAR 18 2021
The DOJ indicts Kottmann — for other conduct
A federal grand jury in the Western District of Washington indicts Tillie Kottmann on conspiracy, wire fraud, and aggravated identity theft charges over alleged intrusions into dozens of companies and government agencies dating back to 2019 — conduct separate from the Verkada breach itself. Swiss authorities raid Kottmann's Lucerne apartment at U.S. request. An indictment is an accusation; Kottmann is presumed innocent unless convicted.
-
2021
Verkada publishes the post-mortem
Mandiant concludes its independent review and, per Verkada's disclosure, confirms findings consistent with the company's internal investigation; a summary letter from Mandiant and Perkins Coie is published for download on the incident page.
-
AUG 2024
The FTC order
The FTC charges that Verkada failed to use appropriate information-security practices, and that the failures let a hacker access customers' cameras — including footage of patients in psychiatric hospitals and women's health clinics. Verkada agrees to an order mandating a comprehensive security program and pays $2.95 million over alleged CAN-SPAM violations in its marketing email. A settlement resolves allegations without an admission.
The regulator's complaint reads like the hackers' press release, three years slower and with a docket number.
both sides, on the record
The product was watching; the vendor wasn't. Super Admin access to customer cameras fell to a credential found publicly on the internet — the intruders' account, unrebutted on the mechanism [1] [2].
The blast radius was the customer list. Jails, hospitals, schools, factories — people who never chose Verkada were the ones on camera [1] [2].
The FTC alleged the failure was systemic — inadequate security practices, charged in 2024 and resolved by consent order with a $2.95M penalty on the email counts [5].
The response was same-day and documented. Internal admin accounts disabled on disclosure day, customers notified, Mandiant and Perkins Coie engaged, a running public timeline and a published post-mortem — the company's own paper trail is a source on this page [3].
The independent review backed the internal one. Per Verkada, Mandiant's findings were consistent with its own investigation, and the summary letter was published rather than buried [3].
The FTC matter was settled, not proven. The order's allegations were neither admitted nor tried; the $2.95M penalty attached to marketing-email allegations, not to the breach itself. The 150,000-camera figure is the hackers' claim, not an audited count [1] [5].
YOU DECIDE
Scoped to the claims. That the breach happened, that the vector was an exposed Super Admin credential per the intruders' unrebutted account, and that the exposed feeds included a jail, hospitals, and an elementary school per the reporting — that is the record. The FTC order is adjudicated as a settlement: binding obligations, no admission.
Weigh the costly signal: a company whose entire pitch is centralized visibility built a single admin tier that could see everything — and the credential that opened it was free.
The archive does not judge. It keeps the timestamps.
evidence locker
PRIMARY & INVESTIGATIVE
Verkada — Security Update (incident timeline + Mandiant conclusion) SELF-PUBLISHED — the company's own account, first-party.
verkada.com/security-update/
SUBJECT'S OWN CHANNELS
The standard. The breach and the response are sourced to Verkada's own disclosures and to named reporting; the mechanism and the facility list are stated as the reporting states them, attributed. The FTC matter is stated as what it is — allegations resolved by consent order, with the penalty attached to the counts the FTC attached it to. The indictment of the hacker is stated as an indictment. The defense — the same-day response, the published post-mortem, the settlement's non-admission — is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.