Dash Cam Hack: How Criminals Can Seize Control in Seconds
Dashcams have become an essential accessory in vehicles across many countries, serving as impartial witnesses in the event of accidents and roadside disputes. Yet, new research presented at Security Analyst Summit 2025 by a team of Singaporean…
Dashcams have become an essential accessory in vehicles across many countries, serving as impartial witnesses in the event of accidents and roadside disputes. Yet, new research presented at Security Analyst Summit 2025 by a team of Singaporean cybersecurity researchers has uncovered a disturbing reality: dashcams, even offline ones, are increasingly being exploited as convenient surveillance and attack platforms. This revelation upends the prevailing perception of dashcams as harmless tools and highlights their potential to be turned into instruments for mass espionage. Most dashcams, despite lacking SIM cards or cellular connectivity, are equipped with Wi-Fi functionality. This feature allows for quick pairing with a driver’s smartphone to download video footage or adjust settings. However, it also presents an unexpected vulnerability. Many dashcam models enable connections using default or hardcoded credentials readily found in user manuals or mobile apps. The result is a scenario where a malicious actor, in close proximity, can connect to the dashcam network, bypass authentication, and siphon high-resolution video, audio, GPS data, and even records of interior conversations. Such access transforms a humble dashcam into a surveillance tool capable of mapping a driver’s routes, cataloging visited locations, overhearing discussions, and recording passengers’ identities. These vulnerabilities enable both targeted and large-scale surveillance efforts, substantially raising the stakes for privacy and security. No Technical Wizardry Required The Singaporean researchers began by investigating a leading Thinkware model but quickly extended their analysis to around two dozen devices spanning 15 brands. Alarming patterns emerged: initial connections typically leveraged the dashcam’s self-issued Wi-Fi network, almost always protected only by a default SSID and password. Attackers can thus rapidly connect and gain access to Linux-based systems running lightweight web and file servers. Three main attack vectors stand out: Direct File Access: Malicious parties can request raw video files directly from the dashcam’s server, bypassing any password checks. MAC Address Spoofing: Many devices trust connections from registered smartphones via unique Wi-Fi MAC addresses. Attackers can capture and spoof these values, securing access. Replay Attacks: By eavesdropping on legitimate exchanges between dashcam and smartphone, adversaries can replay these authentication sequences, effectively impersonating the owner. To compound matters, the foundational hardware and software of dashcams across brands are often sourced from the same suppliers. Combined with uniform or hardcoded credentials, a single malware tool can automate attacks on a massive scale, targeting significant swaths of dashcams in any busy city. Reconnaissance missions can occur at gas stations or drive-throughs, or alarmingly on the move, as infected dashcams themselves attempt to compromise nearby units in traffic, creating a self-spreading surveillance worm. Weaponization and Data Exploitation The researchers demonstrated a full-blown attack chain: harvested dashcam data could be relayed to an attacker via built-in LTE modules or be forwarded through compromised devices to a collection point. Using cloud synchronization features or exploiting insecure vendor servers, attackers can aggregate GPS metadata, recognize street signs, transcribe private conversations, and even link vehicle activity to precise individuals. De-anonymization becomes trivial when license plates or user identifiers are exposed. While responsibility for securing these devices lies primarily with manufacturers implementing secure-by-design principles, drivers have some countermeasures at their disposal: Opt for models without wireless connectivity or disable Wi-Fi and Bluetooth features entirely Regularly update device firmware and accompanying mobile applications Change default network names and passwords, and enable Wi-Fi auto-shutoff or hidden SSID features if possible Consider turning off audio recording and parking modes to minimize the attack surface As companies like Flock and Nexar move to create enormous, interconnected networks of dashcams and license plate readers, the threat of systemic compromise grows. Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Based on reporting by GBHackers.
Most dashcams, despite lacking SIM cards or cellular connectivity, are equipped with Wi-Fi functionality.
