Attackers encrypted an organization's computers by hacking a surveillance camera in the Akira ransomware attack.
The attackers exploited a vulnerability in a public-facing application, gained access to an infected host, and attempted to run ransomware on the organization's file server.
Unable to deploy the ransomware on protected servers and workstations, the attackers targeted a vulnerable network video camera and installed their malware, using it as a foothold for encrypting the organization's servers.
To avoid being the next victim, it is recommended to limit access to specialized network devices, deactivate non-essential services and default accounts on smart devices, use an EDR solution, and implement monitoring and vulnerability management programs.