SCADA & IoT
~/ › SCADA & IoT › article
Dark Web Alert: Disrupt0r Breaches Dozens of Indonesian CCTVs
> By Haider | Aug 08, 2026 | 3 min read
?? THREAT INTELLIGENCE ADVISORY:
A threat actor known as Disrupt0r has successfully breached and exposed multiple private CCTV networks across Indonesia. The compromised feeds broadcast live footage of offices, commercial warehouses, and public parking lots directly into underground channels.
In a chilling reminder of the fragility of Internet of Things (IoT) security, Disrupt0r breaches dozens of Indonesian CCTVs, turning private surveillance networks into public spectacle. As businesses increasingly rely on digital cameras for physical security, this incident highlights a severe disconnect between deploying hardware and securing the network layer it relies on.
Inside the “Disrupt0r” Operations
According to screenshots intercepted by CyberAsia threat analysts, the actor Disrupt0r has been actively sharing multiplexed video feeds on Telegram and dark web forums. The captured panels show up to 36 simultaneous channels streaming live, unauthenticated footage from locations tagged as “Indonesia Cctv”.
Historically, threat actors targeting CCTVs do not employ sophisticated zero-day exploits. Instead, they rely on mass-scanning tools (like Shodan) to identify exposed Digital Video Recorders (DVRs) and IP cameras that are either using default factory credentials or are vulnerable to known, unpatched exploits (e.g., outdated firmware). Once authenticated, the actor can view, record, and sometimes pivot into the broader corporate network.
Compromised Video Feeds
To demonstrate the scale of the intrusion, CyberAsia has reviewed several panels accessed by the actor. Due to the sensitive nature of the footage, we are displaying these panels in a compacted view to highlight the breadth of the access without overly exposing individual identities.
The streams display a disturbing variety of environments: workers in offices, vehicles in private garages, and nighttime security patrols. The fact that the threat actor possesses administrative-level multiplexed views suggests they have compromised the central Network Video Recorders (NVR) rather than just individual edge cameras.
Defender Takeaways: Securing the IoT Perimeter
For organizations and homeowners in Indonesia (and globally), this incident is a direct warning to audit physical security systems. To prevent becoming a target for actors like Disrupt0r, defenders must implement the following controls:
- Eliminate Default Credentials: Immediately change default passwords (e.g., admin/admin, admin/12345) on all NVRs, DVRs, and IP cameras to strong, unique passphrases.
- Isolate IoT Traffic: Place all CCTV hardware on a segregated VLAN that does not have direct inbound or outbound access to the public internet.
- Use VPNs for Remote Access: Never port-forward a CCTV interface directly to the web (e.g., exposing port 80, 554, or 8000). Require users to connect via a secure corporate VPN to view feeds remotely.
- Patch Firmware: Regularly update camera firmware to close known RCE (Remote Code Execution) vulnerabilities frequently abused by botnets.
The exposure of these cameras by Disrupt0r is a stark privacy violation. CyberAsia will continue to monitor the threat actor’s activities. Read more about protecting your infrastructure in our CyberAsia Threat Intelligence Hub.
The information provided in this article is for educational and threat intelligence purposes only. CyberAsia does not condone, promote, or encourage any illegal activities, including data breaches or unauthorized access to systems. The claims made by threat actors are reported strictly for awareness and defensive mitigation.
Get CyberAsia threat intelligence updates by email. Unsubscribe anytime. Privacy Policy.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Dark Web Alert: Disrupt0r Breaches Dozens of Indonesian CCTVs is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
SCADA & IoT
SCADA & IoT
BMS Cyberattack: Disrupt0r Hacks Quinquela Plaza SCADA
> read
SCADA & IoT