VERKADA

OPERATION
Cloud-managed security cameras — "security made simple," sold to schools, hospitals, jails, and factories FACT
EVENT
BREACHED — March 2021; intruders reached customer cameras through Verkada's own admin layer; the company confirmed the unauthorized access FACT
SCALE
~150,000 cameras, per the hackers' claim as reported by Bloomberg — Tesla, Cloudflare, hospitals, a jail, an elementary school ATTRIBUTED
VECTOR
A "Super Admin" username and password found publicly exposed on the internet ATTRIBUTED
DISPOSITION
FTC order (2024): mandated security program + $2.95M penalty on the accompanying CAN-SPAM allegations ADJUDICATED

Here is the watcher — the animal that sells the ability to see inside everyone else's building — observed leaving its own master key on the public internet, where a collective of ideological hackers picked it up and looked back.

Official channel: @VerkadaHQ on X — the handle Verkada links from its own site. FACT

From the company's own incident page, on the record: Mandiant — the external firm hired to conduct an independent review of our March 9th security incident — has concluded its investigation and confirmed that its findings are consistent with those from our own internal investigation.” And at the time, to Bloomberg: “We have disabled all internal administrator accounts to prevent any unauthorized access.” FACT

A camera company's product is trust in one direction: you watch, nobody watches you. The March 2021 breach inverted the lens. This was not a subtle intrusion — the group that claimed it announced itself, handed footage to Bloomberg, and stated its politics on the record. The failure it exposed was ordinary: an over-privileged admin account, its credentials sitting on the public internet.

The archive marks two things here: the architecture — one Super Admin layer that could see into jails, hospitals, and an elementary school — and the paper trail that followed, from the company's own remediation timeline to a federal consent order three years later. Every claim carries its receipt; the defense gets equal time.

the drama timeline

ACT I — THE LENS TURNS AROUND (MAR 2021)

The intrusion, by the intruders' own account, took no exploit at all — a username and a password, found in the open, unlocking the view into everyone's ceiling.

  1. MAR 7–9 2021

    Super Admin, found on the public internet

    A hacker collective calling itself "APT-69420", with Swiss developer Tillie Kottmann as its public voice, gains "Super Admin"-level access to Verkada's systems using credentials found publicly exposed online, and accesses customer cameras and archived video. Kottmann tells Bloomberg the group's motives are curiosity, freedom of information, anti-capitalism — and fun.

    No zero-day, no phishing kit, no patience. The moat around 150,000 lenses was one credential wide.

  2. MAR 9 2021

    Disclosure day — the response is fast

    Bloomberg publishes; Verkada disables all internal administrator accounts the same day, opens an investigation, engages Mandiant as outside forensic firm and Perkins Coie as counsel, notifies affected customers, and begins publishing a running incident timeline on its own site.

ACT II — THE PAPERWORK ARRIVES (2021–2024)

The hacker gets an indictment; the vendor, three years later, gets a consent order. Different courts, one incident report.

  1. MAR 18 2021

    The DOJ indicts Kottmann — for other conduct

    A federal grand jury in the Western District of Washington indicts Tillie Kottmann on conspiracy, wire fraud, and aggravated identity theft charges over alleged intrusions into dozens of companies and government agencies dating back to 2019 — conduct separate from the Verkada breach itself. Swiss authorities raid Kottmann's Lucerne apartment at U.S. request. An indictment is an accusation; Kottmann is presumed innocent unless convicted.

  2. 2021

    Verkada publishes the post-mortem

    Mandiant concludes its independent review and, per Verkada's disclosure, confirms findings consistent with the company's internal investigation; a summary letter from Mandiant and Perkins Coie is published for download on the incident page.

  3. AUG 2024

    The FTC order

    The FTC charges that Verkada failed to use appropriate information-security practices, and that the failures let a hacker access customers' cameras — including footage of patients in psychiatric hospitals and women's health clinics. Verkada agrees to an order mandating a comprehensive security program and pays $2.95 million over alleged CAN-SPAM violations in its marketing email. A settlement resolves allegations without an admission.

    The regulator's complaint reads like the hackers' press release, three years slower and with a docket number.

both sides, on the record

The product was watching; the vendor wasn't. Super Admin access to customer cameras fell to a credential found publicly on the internet — the intruders' account, unrebutted on the mechanism [1] [2].

The blast radius was the customer list. Jails, hospitals, schools, factories — people who never chose Verkada were the ones on camera [1] [2].

The FTC alleged the failure was systemic — inadequate security practices, charged in 2024 and resolved by consent order with a $2.95M penalty on the email counts [5].

The response was same-day and documented. Internal admin accounts disabled on disclosure day, customers notified, Mandiant and Perkins Coie engaged, a running public timeline and a published post-mortem — the company's own paper trail is a source on this page [3].

The independent review backed the internal one. Per Verkada, Mandiant's findings were consistent with its own investigation, and the summary letter was published rather than buried [3].

The FTC matter was settled, not proven. The order's allegations were neither admitted nor tried; the $2.95M penalty attached to marketing-email allegations, not to the breach itself. The 150,000-camera figure is the hackers' claim, not an audited count [1] [5].

YOU DECIDE

Scoped to the claims. That the breach happened, that the vector was an exposed Super Admin credential per the intruders' unrebutted account, and that the exposed feeds included a jail, hospitals, and an elementary school per the reporting — that is the record. The FTC order is adjudicated as a settlement: binding obligations, no admission.

Weigh the costly signal: a company whose entire pitch is centralized visibility built a single admin tier that could see everything — and the credential that opened it was free.

The archive does not judge. It keeps the timestamps.

evidence locker

PRIMARY & INVESTIGATIVE

  1. Bloomberg — "Hackers Expose Tesla, Jails in Breach of 150,000 Security Cams" (Mar 9, 2021) ATTRIBUTED — the breaking report; the hackers' claims and motives. (Bloomberg blocks bots; the page is live.) bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams
  2. The Verge — "Security startup Verkada hack exposes 150,000 security cameras..." (Mar 9, 2021) ATTRIBUTED — the Super Admin mechanism, the facility list, and Verkada's same-day statement. theverge.com/2021/3/9/22322122/verkada-hack-150000-security-cameras-tesla-factory-cloudflare-jails-hospitals
  3. Verkada — Security Update (incident timeline + Mandiant conclusion) SELF-PUBLISHED — the company's own account, first-party. verkada.com/security-update/
  4. U.S. DOJ, W.D. Wash. — "Swiss hacker indicted for computer intrusion and identity theft" (Mar 2021) FACT-OF-FILING — the Kottmann indictment; an accusation, not a conviction. (justice.gov bot-challenges scripts; the page is live.) justice.gov/usao-wdwa/pr/swiss-hacker-indicted-computer-intrusion-and-identity-theft
  5. FTC — "FTC Takes Action Against Security Camera Firm Verkada..." (Aug 2024) ADJUDICATED — the consent order, the mandated security program, and the $2.95M CAN-SPAM penalty. ftc.gov/news-events/news/press-releases/2024/08/ftc-takes-action-against-security-camera-firm-verkada-over-charges-it-failed-secure-videos-other

SUBJECT'S OWN CHANNELS

  1. @VerkadaHQ on X SELF-PUBLISHED — the official handle, linked from verkada.com. twitter.com/VerkadaHQ
The standard. The breach and the response are sourced to Verkada's own disclosures and to named reporting; the mechanism and the facility list are stated as the reporting states them, attributed. The FTC matter is stated as what it is — allegations resolved by consent order, with the penalty attached to the counts the FTC attached it to. The indictment of the hacker is stated as an indictment. The defense — the same-day response, the published post-mortem, the settlement's non-admission — is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.