Nest recommended the owners of its security cameras to use enhanced authentication to avoid being hacked as happened with a family living in the US.
Over the weekend, a family living in California was terrified with a hoax nuclear missile attack.
The couple explained to the local media that hackers compromised their Nest security camera and used atop their television and issued a warning of an imminent impact of missiles launched from North Korea.
After an initial fright, the family realized that they had been the victim of a hack, the attackers took control of their device and in particular of the built-in speakers in the camera, which allowed them to listen and talk with the victims.
According to Nest, the hackers used password obtained from other data breaches.
“Nest, which is owned by Google-parent Alphabet, told AFP that incidents of commandeered camera control in recent months were the result of hackers using passwords stolen from other online venues.” reported AFP.
“Nest was not breached,” confirmed Google that own the vendor.
“These recent reports are based on customers using compromised passwords – exposed through breaches on other websites.”
This isn’t an isolated incident, similar hacks made the headlines in the last months. Media reported the case of a hacker that threatened to kidnap a baby.
Experts and consumers are asking Nest to implement two-factor authentication to prevent such kind of attacks.
Nest is checking the credentials used for its users’ accounts are not included in data leaked online following the numerous data breaches.
If the credentials match the ones present is some dump available online, the company prompts to change passwords.
Last week, the popular cyber security expert Troy Hunt announced the discovery of a massive data leak he called ‘‘Collection #1’ that included 773 million records.
Someone has collected a huge trove of data through credential stuffing, the ‘Collection #1’ archive is a set of email addresses and passwords totalling 2,692,818,238 rows resulting from thousands of different sources.
According to Hunt, there are 1,160,253,228 unique combinations of email addresses and passwords, an excellent source for a hacker that is searching for valid credentials for security cameras and other devices.
Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer.
Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US.
Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines.
Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.