Who Else Can See Your Security Camera?
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
A security camera is the only device you deliberately install to watch your own home, which makes it the one device where a breach is genuinely unnerving rather than merely inconvenient.
The reassuring part is that the dramatic scenario people imagine — a stranger hunting for random cameras to spy through — is not usually how it goes wrong. The realistic failure modes are duller and much more preventable.
The three things that actually go wrong
Password reuse. By far the most common. Someone's email and password leak from an unrelated breach, and the same pair happens to unlock their camera account. No hacking of the camera is involved at all. The attacker simply logs in.
No two-factor authentication. Even with a leaked password, a second factor stops the login. Most camera platforms now offer it, and most users have never turned it on.
Sharing that was never revoked. Old flatmate, former partner, a house-sitter from two years ago. Access lists grow and nobody prunes them.
The settings worth changing today
- Give the camera account its own unique password. Not a variation of one you use elsewhere. If you use a password manager, this takes thirty seconds.
- Turn on two-factor authentication. This single setting defeats the most common attack entirely.
- Audit who has access. Open the sharing or family section and remove anyone who should not be there. Do this once a year.
- Update the firmware. Cameras get security patches too, and many will not install them without prompting.
- Check what is stored in the cloud, and for how long. Some plans retain footage far longer than owners expect.
Where you point it matters more than any setting
Technical controls reduce the chance of a breach. Camera placement reduces what a breach is worth.
Cameras covering entrances, driveways and shared hallways capture what you actually want captured. Cameras in bedrooms and bathrooms create a recording that is a serious problem if anything ever goes wrong — and one you will not be able to withdraw.
If you use an indoor camera for pets or an elderly relative, consider whether it needs to run continuously or only when you are away. Many support schedules or a privacy shutter, and a camera that is off cannot be watched by anyone.
Local storage versus cloud
Cameras that record to a local card or base station keep footage in your house. That removes the cloud account as an attack surface, but it also means a burglar who takes the box takes the evidence, and you lose remote viewing.
Cloud recording is more convenient and more resilient to theft, at the cost of your footage living on someone else's servers under their retention policy. Neither is wrong. Choose deliberately rather than by default, and read the retention terms before you rely on them.
A worked example: the breach that involves no hacking
A household buys a camera, creates an account with the email address they use everywhere and a password they have used on a handful of other sites, and never looks at the security settings again.
Two years later an unrelated service they signed up to once is breached, and the email-and-password pair ends up in a list that circulates freely. Nobody targets this household. An automated tool simply takes millions of leaked pairs and tries them against popular services, including camera platforms, because a meaningful share of people reuse credentials.
The pair works. The attacker logs in through the normal app, exactly like the owner would, and there is no alert because nothing abnormal happened — a correct password was entered.
Two settings break this entirely. A unique password means the leaked pair matches nothing. Two-factor authentication means the correct password alone is not enough. Neither requires understanding how cameras work, and both take under a minute. This is why the advice above is so unglamorous: the realistic attack is credential reuse, so the realistic defence is not reusing credentials.
Questions worth asking before you buy
Camera security is decided largely at purchase, because you cannot add most of this later.
- Does it support two-factor authentication? If not, walk away. This is the single most important feature and it is not universal.
- How long will it receive firmware updates? Some manufacturers publish a support window; many do not. A camera that stops receiving patches is a permanent, unmonitored computer on your network.
- Can it work without the cloud? A camera that still records locally when the manufacturer's service is unavailable keeps working when the company changes its plans or disappears.
- What happens to your footage if you stop paying? Some plans delete recordings promptly when a subscription lapses, which is a nasty discovery to make after an incident.
- Where is the company based and what does its privacy policy actually say about employee access to footage and requests from authorities?
- Is there a physical shutter or a hardware off switch? For indoor cameras this is the one control that cannot be defeated by a software problem.
The subscription trap nobody reads
Most consumer cameras are sold cheap and monetised through recording plans, and the terms deserve reading before you rely on the device.
The pattern to watch for is a plan that covers a limited number of cameras, so that adding a second doubles the ongoing cost, and a retention period measured in days rather than weeks. If you were away for a fortnight, footage from the start of the trip may already be gone by the time you get home and look.
This is also where local storage earns its place. A camera writing to a card or base station keeps everything for as long as the storage lasts, with no monthly fee and no retention policy to be changed by a company you have no relationship with beyond a credit card.
The counter-argument worth taking seriously
There is a case against indoor cameras that is not about hacking at all.
Even perfectly secured, an indoor camera creates a continuous record of your household's private life, held by you and usually by a company. That record can be requested in a dispute, seen by anyone with access to the account, and misused by someone who lives in the house. Domestic abuse cases involving household technology are a real and documented problem, and a camera is the most direct version of it.
So the honest framing is not "cameras are risky, secure them properly". It is that an indoor camera is a considered trade — real value for monitoring a pet, an elderly relative or an empty house, against a permanent recording of a private space. Outdoor and entrance cameras carry far less of that cost for most of the same benefit, which is why placement is treated here as a security control rather than an afterthought.
Where this fits
Cameras are the most sensitive item on the least-maintained part of your network, which is why they belong on the guest network described in the router security checklist. The password advice depends on a password manager to be practical, and the second factor is covered in the two-factor authentication guide. If you are wondering whether your details are already in a leaked credential list, checking after a data breach is the place to start.
The one-minute version
Unique password, two-factor on, access list pruned, firmware current, and cameras pointed at doors rather than beds. That is the overwhelming majority of the risk handled — and the first two items handle most of it on their own. The password manager and authenticator apps those first two items depend on are compared in our shortlist of security tools.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
They Did Not Steal Your Phone. They Stole Your Number.
A SIM swap moves your phone number to someone else, and every code sent to it goes with it. How the attack works, the warning sign, and why SMS is the weakest second factor.
antivirus
Your Files Are Encrypted and There Is a Countdown. Now What?
Ransomware is the one incident where the first hour genuinely decides the outcome. What to do immediately, what not to touch, and the honest answer on paying.
guides
Avast One Review 2026: Best Free Antivirus, With Caveats
An honest Avast One review for 2026: who the free and paid tiers suit, the 2019 Jumpshot scandal in context, and how it compares to Bitdefender.
