Filter by Tags

Tags in the same group = OR  Β·  across groups = AND
Attack Technique
Technology Vector
Risk Profile
Industry
Target
#WhatFraudstersLike #CyberSecurity #DefaultCredentials #IoTSecurity #LetsTalkFraud

Fraudsters Like Backdoors!

"If it works out of the box, why change it?" - because that's precisely what cybercriminals rely on.

A backdoor is any hidden or unintended access path into a system - whether deliberately planted by an attacker, left open by poor design, or simply never closed after initial setup. The most common backdoor in the world? The factory-default password that was never changed.

Leaving devices in their default state is like moving into a new house and never changing the locks. Fraudsters know that factory settings are one of the easiest doors to walk through.

Hardware - the forgotten locks:

πŸ”Œ Smart cameras, routers, and IoT devices often ship with the same username and password, like "admin" and "1234." The infamous Mirai botnet began by scanning the internet for 64 known default credential combinations, infecting over 600,000 devices and generating what was then a record 1.2 Tbps DDoS attack.[ref] Variants of Mirai continue to evolve to this day.

πŸ“Ά Home routers with remote management left enabled can be hijacked to reroute traffic to fake banking or login pages. Juniper enterprise routers were exploited in late 2024 when internet-facing interfaces were left with default credentials.

🐠 The casino fish tank hack became legend - attackers stole a Las Vegas casino's high-roller database through a smart aquarium thermometer with default credentials and unpatched firmware.[ref]

🌍 Search engines for connected devices like Shodan make it trivial to find exposed cameras, sensors, and industrial controls - many still running with default credentials, letting anyone view live feeds from offices, hospitals, or city infrastructure.

Software - built for convenience, not safety:

πŸ—„οΈ Databases left wide open - Tens of thousands of MongoDB and Elasticsearch instances have been ransomed because administrators never changed default accounts or disabled unauthenticated access.

βš™οΈ Enterprise software and automation tools - Platforms like Jenkins and MOVEit have been compromised when test accounts remained post-deployment. The 2023-24 MOVEit breach impacted over 2,700 organizations worldwide, many with default configurations in place.

πŸ§‘β€πŸ’» Backup and monitoring tools - RansomHub, the most active ransomware group in 2024, gained initial access through default accounts commonly found in backup solution installations - testing thousands of common credential pairs at scale.[ref]

πŸ’Ύ RDP and cloud services - Brute-force and default-credential attacks remain among the most common initial access vectors for ransomware operations globally, accounting for approximately 26% of ransomware-related initial access in 2024.[ref]

Why fraudsters love defaults? Because they save time. No exploit needed, no complex social engineering - just log in with the credentials that came in the box.

What can we do:

For individuals:

- Change every default password immediately after installing any new device - camera, router, smart TV, or connected appliance.

- Disable remote access or "smart" features you don't actively use.

- Place IoT devices on a separate network segment, isolated from devices carrying sensitive data.

- Enable automatic firmware updates where available.

For organizations:

- Require password changes before any device or software connects to the network. Make it a gate, not a guideline.

- Scan regularly for systems using default or weak credentials - tools like Shodan's enterprise monitoring show you what attackers already see.

- Replace or isolate devices that cannot change factory credentials or receive security updates.

- Include "no default settings" as a mandatory checklist item before anything goes live - software, hardware, and cloud infrastructure.

If your camera, router, or enterprise tool still uses "admin/admin," it's not protecting you. It's helping someone else watch, steal, or encrypt your data.