Three former employees say that 100+ employees at Verkada could view the camera feeds of its thousands of customers via widely used super admin accounts
- Former employee said issue was raised with Verkada executives — Hackers gained access to 150,000 customer camera feeds
Context & Ripple Effects
The allegation follows the reported breach exposing feeds and archives from 150,000 Verkada cameras, turning the security incident from an external intrusion into a question about how broadly privileged internal access was distributed. Earlier reporting had also described employees allegedly using company cameras to monitor coworkers, giving the access-control claims a workplace-governance dimension.
The later employee accounts of neglected data protection and misleading customers reinforce the same arc: Verkada’s handling of privileged access, rather than a single breach alone, becomes central to customer trust.
First-order effects
- Verkada customers must treat the alleged super-admin practice as a potential exposure of their live and archived footage to more than 100 company employees, not solely to hackers.
- Verkada faces immediate pressure to explain who held super-admin access, what viewing was logged, and whether customers were told how employee access worked.
Second-order effects
- Customers, including organizations operating sensitive sites, are likely to scrutinize Verkada’s access controls and contractual representations more closely when renewing or expanding deployments.
- The breach and internal-access allegations together raise the value of surveillance vendors that can demonstrate narrower privileges and auditable employee access, shifting procurement attention from camera features toward governance controls.
Third-order effects
- If privileged internal access remains a recurring failure mode in cloud-managed surveillance, enterprise buyers will increasingly treat operator-access design as a core security requirement rather than an internal vendor policy.
- The pattern points toward a more demanding market for verifiable least-privilege controls in physical-security platforms, because a single vendor console can concentrate access to many customers’ cameras.
The trend: Cloud-managed surveillance is making privileged vendor access, auditability, and customer control as consequential as the security of the cameras themselves.