Quick Summary
AllegedExecutive Summary
Everest added VIVOTEK to its dark web portal on September 1, 2026, as identified by SOCRadar Dark Web Monitoring. VIVOTEK, a publicly traded Taiwanese manufacturer, specializes in IP surveillance cameras, network video recorders, and video management software. Its products are deployed across enterprise, government, and critical infrastructure sectors globally. The potential impact of this breach extends beyond typical corporate data theft; VIVOTEK’s products are security infrastructure themselves, meaning a compromise of their corporate systems could have implications for the integrity of camera and device management credentials at customer sites. In the 60 days preceding this listing, Everest claimed 30 other victims, primarily in the Technology, Professional Services, and Other industries. The group has a geographic concentration in the United States, India, and the United Arab Emirates. Notable victims in the technology and networking infrastructure space listed around the same time as VIVOTEK include Italtel Peru, Rise UP, Kingston Technology, and Rx Networks. The concurrent listing of two security and networking infrastructure firms on the same day may suggest a coordinated campaign or the use of shared access infrastructure by the threat actor.
Technical Analysis
A stealer-log query for vivotek[.]com revealed 23 records spanning from January 2025 to September 1, 2026, with the most recent entry timestamped on the listing date. These records were categorized as follows: 2 employee credentials, 5 customer credentials, 1 third-party credential, and 15 with an unclear profile. The observed endpoints included confluence.vivotek[.]com (internal Confluence knowledge management), w4.vivotek[.]com, and ezconnect.vivotek[.]com (cloud device management portal for IP camera administration). Additionally, credentials for launchpad.37signals.com, a Basecamp project management SaaS, were also found. The EZConnect portal is VIVOTEK’s cloud-based service used by customers for registering and remotely managing their IP cameras and NVR devices. The discovery of valid customer credentials for this portal, especially when logged on the same day as the ransomware listing, raises concerns. Such credentials could potentially grant an adversary visibility into or control over surveillance infrastructure at numerous third-party customer sites. Combined with the exposure of internal knowledge content via Confluence credentials, the stealer-log data suggests broad and current credential exposure that could facilitate further compromise. Organizations utilizing VIVOTEK’s cloud management services should consider this information as a strong indicator of potential risk. It is recommended to audit EZConnect session activity for any anomalous access patterns and to proactively rotate all device management credentials as a precautionary measure. Continued monitoring of dark web stealer logs and vigilant credential hygiene practices are advisable.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.