SCADA & IoT
~/ › SCADA & IoT › article
NoName057(16) Lottery CCTV Hack: 1 New Breach Exposes Spanish State Lottery
> By Haider | Aug 04, 2026 | 5 min read
The landscape of digital security continues to face challenges from unsecured surveillance infrastructure, as demonstrated by the recent NoName057(16) Lottery CCTV Hack. In this latest incident, the hacktivist collective known as NoName057(16) claimed to have accessed the internal video surveillance system of an official state lottery box office at Loterías y Apuestas del Estado (SELAE) in Spain. Rather than targeting financial databases, the attackers compromised a security camera feed monitoring the customer service counter.
Our intelligence analysts view this incident as a practical example of the persistent vulnerabilities found in enterprise Internet of Things (IoT) deployments. When hacktivist groups pivot to exposing internal camera feeds, it emphasizes a significant operational oversight: the deployment of physical security hardware often occurs without adequate network isolation.
Table of Contents
- The Context of the State Lottery Targeting
- Technical Reality: Unsecured Surveillance Hardware
- The Operational Implications of Exposed Feeds
- Recommended Mitigation Measures for Enterprises
The Context of the NoName057(16) Lottery CCTV Hack
Historically, hacktivist groups have focused their efforts on high-profile public websites or large-scale financial institutions. However, the NoName057(16) Lottery CCTV Hack represents a targeted effort to compromise physical surveillance assets affiliated with state-run organizations. The group detailed this operation in their Telegram channel, noting their ability to monitor staff shifts and daily operations at the Spanish state lottery office.

By executing the NoName057(16) Lottery CCTV Hack, the group aims to project a narrative of pervasive access. The targeting of a state-affiliated entity like Loterías y Apuestas del Estado is consistent with their ongoing #OpSpain campaign. While the breach does not appear to involve financial transactions or core ticketing databases, the public release of internal surveillance footage is utilized to challenge the perceived security posture of Spanish state enterprises.
Technical Reality: Unsecured Surveillance Hardware
From a technical perspective, the execution of this incident highlights the significant risks associated with internet-facing administrative panels. Gaining access to these camera feeds does not typically require complex software flaws or advanced penetration tools. Instead, incidents of this nature frequently involve the use of public network scanners to identify exposed, improperly secured IP cameras.
Many enterprise surveillance systems are installed by contractors who may inadvertently leave the management interfaces accessible to the public internet. If a CCTV network video recorder (NVR) or IP camera is exposed directly online with default or weak administrator credentials, unauthorized individuals can easily gain viewing privileges. In this scenario, the attackers likely located an exposed IP address associated with the lottery office and logged into the unprotected web interface to capture screenshots.
The Operational Implications of Exposed Feeds
The NoName057(16) Lottery CCTV Hack brings notable operational and privacy concerns to the forefront. An exposed surveillance camera grants an unauthorized observer direct visibility into the daily activities of the business. Observers can monitor employee routines, customer interactions, and the physical layout of the facility, which presents a tangible security risk.
Furthermore, the psychological impact on the staff cannot be understated. Knowing that external entities are monitoring their workplace can cause significant distress. The aggregation of this visual data allows unauthorized actors to understand the operational patterns of the office. This incident serves as a crucial reminder for retail and state-run enterprises: physical security hardware must be protected by robust digital security frameworks.
Recommended Mitigation Measures for Enterprises
Securing enterprise surveillance systems requires adherence to established network hygiene standards to prevent incidents similar to the NoName057(16) Lottery CCTV Hack.
We recommend the following defensive measures, which align with global cybersecurity best practices (CISA) for enterprise IoT management:
- Do Not Expose Interfaces: Ensure that IP cameras and NVR dashboards are never connected directly to the open internet.
- Utilize VPNs: If remote monitoring is required by management or security personnel, configure a secure Virtual Private Network (VPN) for safe access.
- Change Default Passwords: Immediately update all default administrative credentials provided by the camera manufacturer to strong, unique passwords.
- Network Segmentation: Place all surveillance hardware on a dedicated, isolated Virtual Local Area Network (VLAN) separate from primary corporate devices and point-of-sale systems.
- Regular Updates: Continuously update the firmware of all security cameras and recording devices to patch publicly known vulnerabilities.
- Enable Multi-Factor Authentication (MFA): Whenever supported by the surveillance platform, require MFA to add an additional layer of security for remote access.
The unauthorized access of a state lottery office’s surveillance system illustrates a concerning trend in digital targeting. As connected devices become integral to business operations, it is vital that security standards evolve accordingly. The growing interconnectedness of enterprise hardware brings immense operational benefits, but it also broadens the potential attack surface. Cybersecurity is an essential component of physical security. By implementing basic access controls, organizations can significantly enhance their privacy and secure their facilities against unauthorized digital intrusions.
For more analyses of digital vulnerabilities and cybersecurity trends, explore our ongoing coverage of recent cyber incidents.
Mitigation & Prevention Strategies
Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:
- Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
- Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
- Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing NoName057(16) Lottery CCTV Hack: 1 New Breach Exposes Spanish State Lottery is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
SCADA & IoT
SCADA & IoT
BMS Cyberattack: Disrupt0r Hacks Quinquela Plaza SCADA
> read
SCADA & IoT